[Git][security-tracker-team/security-tracker][master] Reserve DLA-3676-1 for libde265

Anton Gladky (@gladk) gladk at debian.org
Thu Nov 30 16:39:43 GMT 2023



Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker


Commits:
808dc32e by Anton Gladky at 2023-11-30T17:39:19+01:00
Reserve DLA-3676-1 for libde265

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -41871,14 +41871,12 @@ CVE-2023-27103 (Libde265 v1.0.11 was discovered to contain a heap buffer overflo
 	- libde265 1.0.12-1 (bug #1033257)
 	[bookworm] - libde265 <no-dsa> (Minor issue)
 	[bullseye] - libde265 <no-dsa> (Minor issue)
-	[buster] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/issues/394
 	NOTE: https://github.com/strukturag/libde265/commit/d6bf73e765b7a23627bfd7a8645c143fd9097995 (v1.0.12)
 CVE-2023-27102 (Libde265 v1.0.11 was discovered to contain a segmentation violation vi ...)
 	- libde265 1.0.12-1 (bug #1033257)
 	[bookworm] - libde265 <no-dsa> (Minor issue)
 	[bullseye] - libde265 <no-dsa> (Minor issue)
-	[buster] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/issues/393
 	NOTE: https://github.com/strukturag/libde265/commit/0b1752abff97cb542941d317a0d18aa50cb199b1 (v1.0.12)
 CVE-2023-27101


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[30 Nov 2023] DLA-3676-1 libde265 - security update
+	{CVE-2023-27102 CVE-2023-27103 CVE-2023-43887 CVE-2023-47471}
+	[buster] - libde265 1.0.11-0+deb10u5
 [30 Nov 2023] DLA-3675-1 zbar - security update
 	{CVE-2023-40889 CVE-2023-40890}
 	[buster] - zbar 0.22-1+deb10u1


=====================================
data/dla-needed.txt
=====================================
@@ -89,10 +89,6 @@ keystone
 knot-resolver
   NOTE: 20231029: Added by Front-Desk (gladk)
 --
-libde265 (gladk)
-  NOTE: 20231119: Added by Front-Desk (apo)
-  NOTE: 20231119: Fix along with postponed issues.
---
 libreswan
   NOTE: 20230817: Added by Front-Desk (ta)
   NOTE: 20230909: Prepared a patch for CVE-2023-38712 and pushed it to



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/808dc32e5e7fbd049a8faf0570941fe689e19210

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/808dc32e5e7fbd049a8faf0570941fe689e19210
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231130/de59c4ba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list