[Git][security-tracker-team/security-tracker][master] Reserve DLA-3763-1 for curl

Bastien Roucariès (@rouca) rouca at debian.org
Sun Mar 17 09:23:21 GMT 2024



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f003d9d by Bastien Roucariès at 2024-03-17T09:22:54+00:00
Reserve DLA-3763-1 for curl

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -64149,7 +64149,6 @@ CVE-2023-27535 (An authentication bypass vulnerability exists in libcurl <8.0.0
 CVE-2023-27534 (A path traversal vulnerability exists in curl <8.0.0 SFTP implementati ...)
 	- curl 7.88.1-7
 	[bullseye] - curl 7.74.0-1.3+deb11u8
-	[buster] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2023-27534.html
 	NOTE: Introduced by: https://github.com/curl/curl/commit/ba6f20a2442ab1ebfe947cff19a552f92114a29a (curl-7_18_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/4e2b52b5f7a3bf50a0f1494155717b02cc1df6d6 (curl-8_0_0)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Mar 2024] DLA-3763-1 curl - security update
+	{CVE-2023-27534}
+	[buster] - curl 7.64.0-4+deb10u9
 [15 Mar 2024] DLA-3762-1 unadf - security update
 	{CVE-2016-1243 CVE-2016-1244}
 	[buster] - unadf 0.7.11a-4+deb11u1~deb10u1


=====================================
data/dla-needed.txt
=====================================
@@ -59,12 +59,6 @@ composer (rouca)
   NOTE: 20240315: DSA 5632-1 is out (Beuc/front-desk)
   NOTE: 20240316: Ask clarification about some fixes on DSA 5632-1 without CVE
 --
-curl (rouca)
-  NOTE: 20231229: Added by Front-Desk (lamby)
-  NOTE: 20231229: CVE-2023-27534 fixed in bullseye via DSA or point release. (lamby)
-  NOTE: 20240129: https://salsa.debian.org/debian/curl/-/merge_requests/21 (rouca)
-  NOTE: 20240312: test fix (rouca)
---
 dnsmasq (dleidert)
   NOTE: 20240303: Added by Front-Desk (apo)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f003d9d3fbf160ffc6753ddaa616a492a6e8445

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f003d9d3fbf160ffc6753ddaa616a492a6e8445
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240317/4c78f87b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list