[Git][security-tracker-team/security-tracker][master] Reserve DLA-3763-1 for curl
Bastien Roucariès (@rouca)
rouca at debian.org
Sun Mar 17 09:23:21 GMT 2024
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5f003d9d by Bastien Roucariès at 2024-03-17T09:22:54+00:00
Reserve DLA-3763-1 for curl
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -64149,7 +64149,6 @@ CVE-2023-27535 (An authentication bypass vulnerability exists in libcurl <8.0.0
CVE-2023-27534 (A path traversal vulnerability exists in curl <8.0.0 SFTP implementati ...)
- curl 7.88.1-7
[bullseye] - curl 7.74.0-1.3+deb11u8
- [buster] - curl <no-dsa> (Minor issue)
NOTE: https://curl.se/docs/CVE-2023-27534.html
NOTE: Introduced by: https://github.com/curl/curl/commit/ba6f20a2442ab1ebfe947cff19a552f92114a29a (curl-7_18_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/4e2b52b5f7a3bf50a0f1494155717b02cc1df6d6 (curl-8_0_0)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Mar 2024] DLA-3763-1 curl - security update
+ {CVE-2023-27534}
+ [buster] - curl 7.64.0-4+deb10u9
[15 Mar 2024] DLA-3762-1 unadf - security update
{CVE-2016-1243 CVE-2016-1244}
[buster] - unadf 0.7.11a-4+deb11u1~deb10u1
=====================================
data/dla-needed.txt
=====================================
@@ -59,12 +59,6 @@ composer (rouca)
NOTE: 20240315: DSA 5632-1 is out (Beuc/front-desk)
NOTE: 20240316: Ask clarification about some fixes on DSA 5632-1 without CVE
--
-curl (rouca)
- NOTE: 20231229: Added by Front-Desk (lamby)
- NOTE: 20231229: CVE-2023-27534 fixed in bullseye via DSA or point release. (lamby)
- NOTE: 20240129: https://salsa.debian.org/debian/curl/-/merge_requests/21 (rouca)
- NOTE: 20240312: test fix (rouca)
---
dnsmasq (dleidert)
NOTE: 20240303: Added by Front-Desk (apo)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f003d9d3fbf160ffc6753ddaa616a492a6e8445
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f003d9d3fbf160ffc6753ddaa616a492a6e8445
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240317/4c78f87b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list