[Git][security-tracker-team/security-tracker][master] 2 commits: dla: update ceph note

Sylvain Beucler (@beuc) beuc at debian.org
Mon Mar 6 11:22:45 GMT 2023



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2557527e by Sylvain Beucler at 2023-03-06T12:21:12+01:00
dla: update ceph note

- - - - -
886f307f by Sylvain Beucler at 2023-03-06T12:22:01+01:00
dla: wireless-regdb was added following tobi's request

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -23,8 +23,9 @@ ceph
   NOTE: 20221031: To be checked further. Not clear whether the vulnerability can be exploited in a Debian system.
   NOTE: 20221031: What should be checked is whether any user with ceph permission can do the actions described in the exploit. (ola/front-desk)
   NOTE: 20221130: CVE-2022-3650: The patch is kind of trivial Python stuff backporting work.
-  NOTE: 20221130: Can someone take care of it in Buster? I'm currently building the Bullseye backport of the fix...
-  NOTE: 20221130: https://lists.debian.org/debian-lts/2022/11/msg00025.html  (zigo/maintainer)
+  NOTE: 20221130:   Can someone take care of it in Buster? I'm currently building the Bullseye backport of the fix...
+  NOTE: 20221130:   https://lists.debian.org/debian-lts/2022/11/msg00025.html  (zigo/maintainer)
+  NOTE: 20230102:   [buster] - ceph <not-affected> (ceph-crash service added in Ceph 14) (stefanor)
   NOTE: 20230111: VCS: https://salsa.debian.org/lts-team/packages/ceph.git
 --
 consul
@@ -327,7 +328,7 @@ trafficserver
    NOTE: 20230209: could find informatin for CVE-2022-31779, might be the same fix as CVE-2022-31778 (marked as to be ignored), but no proof on that…
    NOTE: 20230209: not sure, maybe the safest way would be to update to 8.1.6. </tobi>
 --
-wireless-regdb
+wireless-regdb (tobi)
   NOTE: 20230306: Programming language: database.
   NOTE: 20230306: VCS: https://salsa.debian.org/kernel-team/wireless-regdb
   NOTE: 20230306: Maintainer notes: To be updated regularly; used by linux-image.



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/46a8ccf40468edae1ea38a510c3e0da267b3546d...886f307f6f9b2717d409080842d61a47ee79ce59

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/46a8ccf40468edae1ea38a510c3e0da267b3546d...886f307f6f9b2717d409080842d61a47ee79ce59
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230306/be0e0332/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list