Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits: 4ae084e4 by Utkarsh Gupta at 2021-04-25T12:59:25+05:30 Strip no-dsa tags for opendmarc for stretch which'll receieve an update - - - - - d4da7d4d by Utkarsh Gupta at 2021-04-25T13:16:11+05:30 Reserve DLA-2639-1 for opendmarc - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -74313,7 +74313,6 @@ CVE-2020-12461 (PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has CVE-2020-12460 (OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper nul ...) - opendmarc 1.4.0~beta1+dfsg-3 (bug #966464) [buster] - opendmarc <no-dsa> (Minor issue) - [stretch] - opendmarc <no-dsa> (Minor issue) NOTE: https://github.com/trusteddomainproject/OpenDMARC/issues/64 NOTE: https://github.com/trusteddomainproject/OpenDMARC/commit/50d28af25d8735504b6103537228ce7f76ad765f CVE-2020-12459 (In certain Red Hat packages for Grafana 6.x through 6.3.6, the configu ...) ===================================== data/DLA/list ===================================== @@ -1,3 +1,6 @@ +[25 Apr 2021] DLA-2639-1 opendmarc - security update + {CVE-2020-12460} + [stretch] - opendmarc 1.3.2-2+deb9u3 [25 Apr 2021] DLA-2638-1 jackson-databind - security update {CVE-2020-24616 CVE-2020-24750 CVE-2020-35490 CVE-2020-35491 CVE-2020-35728 CVE-2020-36179 CVE-2020-36180 CVE-2020-36181 CVE-2020-36182 CVE-2020-36183 CVE-2020-36184 CVE-2020-36185 CVE-2020-36186 CVE-2020-36187 CVE-2020-36188 CVE-2020-36189 CVE-2021-20190} [stretch] - jackson-databind 2.8.6-1+deb9u9 ===================================== data/dla-needed.txt ===================================== @@ -85,11 +85,6 @@ nvidia-graphics-drivers NOTE: package is in non-free but also in packages-to-support NOTE: only CVE‑2021‑1076 seems to be fixed in the R390 branch used in Stretch, no fix available for CVE-2021-1077 -- -opendmarc (Utkarsh) - NOTE: 20200719: no patches for remaining CVEs available, everything else is already done in Stretch (thorsten) - NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto) - NOTE: 20210104: wait for other CVEs (abhijith) --- openexr -- ring (Thorsten Alteholz) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa663333458a736a7fd8d4c592f29e24b4cbe2dd...d4da7d4da4aa9f6017df68d94d20c2ec3f54ca2e You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits