[Git][security-tracker-team/security-tracker][master] update note

Thorsten Alteholz (@alteholz) alteholz at debian.org
Mon May 5 18:50:17 BST 2025



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5dea0835 by Thorsten Alteholz at 2025-05-05T19:50:01+02:00
update note

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -198,10 +198,11 @@ libstring-compare-constanttime-perl (guilhem)
   NOTE: 20250430: with it. At least not until we have either decided to revert the patch landing in trixie or accept
   NOTE: 20250430: it. Context in https://github.com/hoytech/String-Compare-ConstantTime/pull/21
 --
-libxmltok
+libxmltok (Thorsten Alteholz)
   NOTE: 20250421: Added by Front-Desk (ta)
   NOTE: 20250421: Also review all other expat CVEs. (bunk)
   NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
+  NOTE: 20250505: WIP there are lots of CVEs to review (ta)
 --
 linux (Ben Hutchings)
   NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5dea083550443275d7bc56d54a04d02b86386dad

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5dea083550443275d7bc56d54a04d02b86386dad
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250505/34335825/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list