[Git][security-tracker-team/security-tracker][master] Reserve DLA-3288-1 for curl
Roberto C. Sánchez (@roberto)
roberto at debian.org
Sat Jan 28 21:08:22 GMT 2023
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker
Commits:
317c1f24 by Roberto C. Sánchez at 2023-01-28T16:07:54-05:00
Reserve DLA-3288-1 for curl
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[28 Jan 2023] DLA-3288-1 curl - security update
+ {CVE-2022-27774 CVE-2022-32221 CVE-2022-35252 CVE-2022-43552}
+ [buster] - curl 7.64.0-4+deb10u4
[28 Jan 2023] DLA-3287-1 lemonldap-ng - security update
{CVE-2020-16093 CVE-2022-37186}
[buster] - lemonldap-ng 2.0.2+ds-7+deb10u8
=====================================
data/dla-needed.txt
=====================================
@@ -44,15 +44,6 @@ consul
NOTE: 20221031: Programming language: Go.
NOTE: 20221031: Concluded that the package should be fixed by the CVE description. Source code not analyzed in detail.
--
-curl (Roberto C. Sánchez)
- NOTE: 20220901: Programming language: C.
- NOTE: 20220904: VCS: https://salsa.debian.org/lts-team/packages/curl.git
- NOTE: 20220904: Special attention: high popcon!.
- NOTE: 20221209: Testsuite: https://lts-team.pages.debian.net/wiki/TestSuites/curl.html
- NOTE: 20230103: Sorted out issue with broken CVE fix in stable, working with secteam to land the fix (roberto)
- NOTE: 20230103: Packages ready for bullseye and buster, syncing ELTS releases (roberto)
- NOTE: 20230126: Builds for all releases are ready, working on final coordination (roberto)
---
dojo (guilhem)
NOTE: 20230105: Programming language: JavaScript.
NOTE: 20230105: Follow fixes from bullseye 11.6 (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/317c1f24f651b23e936a3793b7b8f45db8e05377
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/317c1f24f651b23e936a3793b7b8f45db8e05377
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230128/7af10098/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list