[Git][security-tracker-team/security-tracker][master] Reserve DLA-4050-1 for bind9

Paride Legovini (@paride) paride at debian.org
Tue Feb 11 14:09:56 GMT 2025



Paride Legovini pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b8624d4c by Paride Legovini at 2025-02-11T15:09:45+01:00
Reserve DLA-4050-1 for bind9

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[11 Feb 2025] DLA-4050-1 bind9 - security update
+	{CVE-2024-11187}
+	[bullseye] - bind9 1:9.16.50-1~deb11u3
 [11 Feb 2025] DLA-4049-1 rust-openssl - security update
 	{CVE-2025-24898}
 	[bullseye] - rust-openssl 0.10.29-1+deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -34,13 +34,6 @@ ansible (lee)
   NOTE: 20241120: Waiting for release by Lee testsuite is ok (rouca)
   NOTE: 20241123: Made a partial release. only CVE-2024-11079 needed but more upstream backport work needed (rouca)
 --
-bind9 (paride)
-  NOTE: 20250130: Added by Front-Desk (pochu)
-  NOTE: 20250206: CVE-2024-12705 is a DoS affecting the bind9 DNS-over-HTTPS resolver. (paride)
-  NOTE: 20250206: Per upstream changelog-history.rst, DNS-over-HTTPS first got implemented in 9.17.10. (paride)
-  NOTE: 20250206: Therefore, CVE-2024-12705 does not affect Bullseye or earlier releases. (paride)
-  NOTE: 20250210: I have a Bullseye branch ready, but I want to attempt expanding autopkgtest to cover modified code. (paride)
---
 ceph
   NOTE: 20241205: Added by Front-Desk (santiago)
   NOTE: 20241205: maintainer is preparing an update: https://lists.debian.org/debian-lts/2024/12/msg00008.html (santiago/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8624d4c52865835d7a833f2a240943f42dddfa9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8624d4c52865835d7a833f2a240943f42dddfa9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250211/2ce8df00/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list