[Git][security-tracker-team/security-tracker][master] Reserve DLA-3970-1 for twisted
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Thu Nov 28 12:03:02 GMT 2024
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cd35c2a5 by Sylvain Beucler at 2024-11-28T13:02:48+01:00
Reserve DLA-3970-1 for twisted
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -102975,7 +102975,6 @@ CVE-2023-46232 (era-compiler-vyper is the EraVM Vyper compiler for zkSync Era, a
CVE-2023-46137 (Twisted is an event-based framework for internet applications. Prior t ...)
{DSA-5797-1}
- twisted 23.10.0-1 (bug #1054913)
- [bullseye] - twisted <no-dsa> (Minor issue)
[buster] - twisted <no-dsa> (Minor issue)
NOTE: https://github.com/twisted/twisted/security/advisories/GHSA-xc8x-vp79-p3wm
NOTE: https://github.com/twisted/twisted/commit/1e6e9d23cac59689760558dcb6634285e694b04c (twisted-23.10.0rc1)
@@ -184257,7 +184256,6 @@ CVE-2022-39349 (The Tasks.org Android app is an open-source app for to-do lists
CVE-2022-39348 (Twisted is an event-based framework for internet applications. Started ...)
{DLA-3212-1}
- twisted 22.4.0-4 (bug #1023359)
- [bullseye] - twisted <no-dsa> (Minor issue)
NOTE: https://github.com/twisted/twisted/security/advisories/GHSA-vg46-2rrj-3647
NOTE: Introduced by: https://github.com/twisted/twisted/commit/f49041bb67792506d85aeda9cf6157e92f8048f4
NOTE: Fixed by: https://github.com/twisted/twisted/commit/f2f5e81c03f14e253e85fe457e646130780db40b (twisted-22.10.0rc1)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[28 Nov 2024] DLA-3970-1 twisted - security update
+ {CVE-2022-39348 CVE-2023-46137 CVE-2024-41671 CVE-2024-41810}
+ [bullseye] - twisted 20.3.0-7+deb11u2
[28 Nov 2024] DLA-3969-1 thunderbird - security update
{CVE-2024-11692 CVE-2024-11694 CVE-2024-11695 CVE-2024-11696 CVE-2024-11697 CVE-2024-11699}
[bullseye] - thunderbird 1:128.5.0esr-1~deb11u1
=====================================
data/dla-needed.txt
=====================================
@@ -214,10 +214,6 @@ trafficserver
tryton-server
NOTE: 20240923: Added by Front-Desk (lamby)
--
-twisted (Sylvain Beucler)
- NOTE: 20240807: Added by oldstable Security Team (jmm)
- NOTE: 20240815: A bookworm DSA is planned (Beuc/front-desk)
---
twitter-bootstrap3
NOTE: 20241110: Added by Front-Desk (apo)
NOTE: 20241119: Supportability discussion https://lists.debian.org/debian-lts/2024/11/msg00030.html (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cd35c2a5bfc010da03c0567d2525b826003f02f4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cd35c2a5bfc010da03c0567d2525b826003f02f4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241128/9e53e448/attachment.htm>
More information about the debian-security-tracker-commits
mailing list