Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4ae084e4 by Utkarsh Gupta at 2021-04-25T12:59:25+05:30
Strip no-dsa tags for opendmarc for stretch which'll receieve an update

- - - - -
d4da7d4d by Utkarsh Gupta at 2021-04-25T13:16:11+05:30
Reserve DLA-2639-1 for opendmarc

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -74313,7 +74313,6 @@ CVE-2020-12461 (PHP-Fusion 9.03.50 allows SQL Injection 
because maincore.php has
 CVE-2020-12460 (OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has 
improper nul ...)
        - opendmarc 1.4.0~beta1+dfsg-3 (bug #966464)
        [buster] - opendmarc <no-dsa> (Minor issue)
-       [stretch] - opendmarc <no-dsa> (Minor issue)
        NOTE: https://github.com/trusteddomainproject/OpenDMARC/issues/64
        NOTE: 
https://github.com/trusteddomainproject/OpenDMARC/commit/50d28af25d8735504b6103537228ce7f76ad765f
 CVE-2020-12459 (In certain Red Hat packages for Grafana 6.x through 6.3.6, the 
configu ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Apr 2021] DLA-2639-1 opendmarc - security update
+       {CVE-2020-12460}
+       [stretch] - opendmarc 1.3.2-2+deb9u3
 [25 Apr 2021] DLA-2638-1 jackson-databind - security update
        {CVE-2020-24616 CVE-2020-24750 CVE-2020-35490 CVE-2020-35491 
CVE-2020-35728 CVE-2020-36179 CVE-2020-36180 CVE-2020-36181 CVE-2020-36182 
CVE-2020-36183 CVE-2020-36184 CVE-2020-36185 CVE-2020-36186 CVE-2020-36187 
CVE-2020-36188 CVE-2020-36189 CVE-2021-20190}
        [stretch] - jackson-databind 2.8.6-1+deb9u9


=====================================
data/dla-needed.txt
=====================================
@@ -85,11 +85,6 @@ nvidia-graphics-drivers
   NOTE: package is in non-free but also in packages-to-support
   NOTE: only CVE‑2021‑1076 seems to be fixed in the R390 branch used in 
Stretch, no fix available for CVE-2021-1077
 --
-opendmarc (Utkarsh)
-  NOTE: 20200719: no patches for remaining CVEs available, everything else is 
already done in Stretch (thorsten)
-  NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto)
-  NOTE: 20210104: wait for other CVEs (abhijith)
---
 openexr
 --
 ring (Thorsten Alteholz)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to