Anton Gladky pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4e874c58 by Anton Gladky at 2022-01-10T22:11:39+01:00
Reserve DLA-2876-1 for vim

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19742,7 +19742,6 @@ CVE-2021-3796 (vim is vulnerable to Use After Free ...)
        - vim 2:8.2.3455-1 (bug #994497)
        [bullseye] - vim 2:8.2.2434-3+deb11u1
        [buster] - vim <no-dsa> (Minor issue)
-       [stretch] - vim <no-dsa> (Minor issue)
        NOTE: https://huntr.dev/bounties/ab60b7f3-6fb1-4ac2-a4fa-4d592e08008d/
        NOTE: 
https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3 
(v8.2.3428)
        NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1
@@ -20197,7 +20196,6 @@ CVE-2021-3778 (vim is vulnerable to Heap-based Buffer 
Overflow ...)
        - vim 2:8.2.3455-1 (bug #994498)
        [bullseye] - vim 2:8.2.2434-3+deb11u1
        [buster] - vim <no-dsa> (Minor issue)
-       [stretch] - vim <no-dsa> (Minor issue)
        NOTE: https://huntr.dev/bounties/d9c17308-2c99-4f9f-a706-f7f72c24c273
        NOTE: 
https://github.com/vim/vim/commit/65b605665997fad54ef39a93199e305af2fe4d7f 
(v8.2.3409)
        NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1
@@ -116744,7 +116742,6 @@ CVE-2019-20808 (In QEMU 4.1.0, an out-of-bounds read 
flaw was found in the ATI V
 CVE-2019-20807 (In Vim before 8.1.0881, users can circumvent the rvim 
restricted mode  ...)
        - vim 2:8.1.2136-1
        [buster] - vim <no-dsa> (Minor issue)
-       [stretch] - vim <no-dsa> (Minor issue)
        [jessie] - vim <no-dsa> (Minor issue)
        NOTE: 
https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075
 CVE-2020-13644 (An issue was discovered in the Accordion plugin before 2.2.9 
for WordP ...)
@@ -263627,7 +263624,6 @@ CVE-2017-17088 (The Enterprise version of SyncBreeze 
10.2.12 and earlier is affe
 CVE-2017-17087 (fileio.c in Vim prior to 8.0.1263 sets the group ownership of 
a .swp f ...)
        {DLA-1871-1}
        - vim 2:8.0.1401-1
-       [stretch] - vim <no-dsa> (Minor issue)
        [wheezy] - vim <no-dsa> (Minor issue)
        NOTE: 
https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8 
(8.0.1263)
 CVE-2017-17086 (Indeo Otter through 1.7.4 mishandles a "&lt;/script&gt;" 
substring in  ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[10 Jan 2022] DLA-2876-1 vim - security update
+       {CVE-2017-17087 CVE-2019-20807 CVE-2021-3778 CVE-2021-3796}
+       [stretch] - vim 2:8.0.0197-4+deb9u4
 [10 Jan 2022] DLA-2875-1 clamav - security update
        [stretch] - clamav 0.103.4+dfsg-0+deb9u1
 [04 Jan 2022] DLA-2874-1 thunderbird - security update


=====================================
data/dla-needed.txt
=====================================
@@ -114,13 +114,6 @@ sphinxsearch (Thorsten Alteholz)
 thunderbird (Emilio)
   NOTE: 20220104: ftbfs on armhf (pochu)
 --
-vim (Anton)
-  NOTE: 20211203: adding here as it's in the ela-needed as well
-  NOTE: 20211203: so worth fixing in stretch, too. Co-ordinate w/
-  NOTE: 20211203: Emilio since he's working on it for jessie. (utkarsh)
-  NOTE: 20211220: WIP (Anton)
-  NOTE: 20220103: Upload is planed this week (Anton)
---
 wordpress (Utkarsh)
   NOTE: 20220108: Issues may not warrant a DLA. See comment for commit 
3ae7f35d1 re. previous release. (lamby)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to