[Git][security-tracker-team/security-tracker][master] dla: drop h2o, DSA not tracked anymore

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Tue Sep 3 08:31:21 BST 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f6cccf4d by Sylvain Beucler at 2024-09-03T09:30:48+02:00
dla: drop h2o, DSA not tracked anymore

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -71512,6 +71512,7 @@ CVE-2023-43364 (main.py in Searchor before 2.4.2 uses eval on CLI input, which m
 CVE-2023-41337 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In ...)
 	- h2o <unfixed> (bug #1059413)
 	[bookworm] - h2o <no-dsa> (Minor issue)
+	[bullseye] - h2o <postponed> (Minor issue, session hijack in specific conditions, workarounds exist)
 	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-5v5r-rghf-rm6q
 	NOTE: Fixed by: https://github.com/h2o/h2o/commit/35760540337a47e5150da0f4a66a609fad2ef0ab
 CVE-2023-38694 (Umbraco is an ASP.NET content management system (CMS). Starting in ver ...)
@@ -82688,6 +82689,7 @@ CVE-2023-44487 (The HTTP/2 protocol allows a denial of service (server resource
 	[buster] - grpc <no-dsa> (Minor issue)
 	- h2o 2.2.5+dfsg2-8 (bug #1054232)
 	[bookworm] - h2o <no-dsa> (Minor issue)
+	[bullseye] - h2o <postponed> (Minor issue, DoS)
 	- haproxy 1.8.13-1
 	- nginx 1.24.0-2 (unimportant; bug #1053770)
 	- nghttp2 1.57.0-1 (bug #1053769)


=====================================
data/dla-needed.txt
=====================================
@@ -123,11 +123,6 @@ gpac
   NOTE: 20240815: Considered for EOL
   NOTE: 20240815: https://lists.debian.org/debian-lts/2024/08/msg00004.html (Beuc/front-desk)
 --
-h2o
-  NOTE: 20231107: Added by oldstable Security Team (jmm)
-  NOTE: 20240815: A bookworm DSA is planned
-  NOTE: 20240815: coordinate bullseye DLA with secteam (Beuc/front-desk)
---
 libvirt (Thorsten Alteholz)
   NOTE: 20240826: Added by Front-Desk (ta)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6cccf4d1108c19dfb68c5b57f38292b75918862

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6cccf4d1108c19dfb68c5b57f38292b75918862
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240903/098bbd20/attachment.htm>


More information about the debian-security-tracker-commits mailing list