[Git][security-tracker-team/security-tracker][master] Reserve DSA-5558-1 for netty

Markus Koschany (@apo) apo at debian.org
Sat Nov 18 15:58:35 GMT 2023



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fb8c6f97 by Markus Koschany at 2023-11-18T16:58:07+01:00
Reserve DSA-5558-1 for netty

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -22182,8 +22182,6 @@ CVE-2023-34553 (An issue was discovered in WAFU Keyless Smart Lock v1.0 allows a
 	NOT-FOR-US: WAFU Keyless Smart Lock
 CVE-2023-34462 (Netty is an asynchronous event-driven network application framework fo ...)
 	- netty 1:4.1.48-8 (bug #1038947)
-	[bookworm] - netty <postponed> (Minor issue, fix along in future update)
-	[bullseye] - netty <postponed> (Minor issue, fix along in future update)
 	[buster] - netty <not-affected> (SslClientHelloHandler introduced in v4.1.46)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-6mjq-h674-j845
 	NOTE: https://github.com/netty/netty/commit/535da17e45201ae4278c0479e6162bb4127d4c32 (netty-4.1.94.Final)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,7 @@
+[18 Nov 2023] DSA-5558-1 netty - security update
+	{CVE-2023-34462 CVE-2023-44487}
+	[bullseye] - netty 1:4.1.48-4+deb11u2
+	[bookworm] - netty 1:4.1.48-7+deb12u1
 [17 Nov 2023] DSA-5557-1 webkit2gtk - security update
 	{CVE-2023-41983 CVE-2023-42852}
 	[bullseye] - webkit2gtk 2.42.2-1~deb11u1


=====================================
data/dsa-needed.txt
=====================================
@@ -42,8 +42,6 @@ linux (carnil)
 nbconvert/oldstable
   Guilhem Moulin proposed an update ready for review
 --
-netty (apo)
---
 nghttp2
 --
 nodejs



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fb8c6f97071556ac2984b4ebea230efb8c2225e7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fb8c6f97071556ac2984b4ebea230efb8c2225e7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231118/500088b2/attachment.htm>


More information about the debian-security-tracker-commits mailing list