Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker
Commits: 4e874c58 by Anton Gladky at 2022-01-10T22:11:39+01:00 Reserve DLA-2876-1 for vim - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -19742,7 +19742,6 @@ CVE-2021-3796 (vim is vulnerable to Use After Free ...) - vim 2:8.2.3455-1 (bug #994497) [bullseye] - vim 2:8.2.2434-3+deb11u1 [buster] - vim <no-dsa> (Minor issue) - [stretch] - vim <no-dsa> (Minor issue) NOTE: https://huntr.dev/bounties/ab60b7f3-6fb1-4ac2-a4fa-4d592e08008d/ NOTE: https://github.com/vim/vim/commit/35a9a00afcb20897d462a766793ff45534810dc3 (v8.2.3428) NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1 @@ -20197,7 +20196,6 @@ CVE-2021-3778 (vim is vulnerable to Heap-based Buffer Overflow ...) - vim 2:8.2.3455-1 (bug #994498) [bullseye] - vim 2:8.2.2434-3+deb11u1 [buster] - vim <no-dsa> (Minor issue) - [stretch] - vim <no-dsa> (Minor issue) NOTE: https://huntr.dev/bounties/d9c17308-2c99-4f9f-a706-f7f72c24c273 NOTE: https://github.com/vim/vim/commit/65b605665997fad54ef39a93199e305af2fe4d7f (v8.2.3409) NOTE: https://www.openwall.com/lists/oss-security/2021/10/01/1 @@ -116744,7 +116742,6 @@ CVE-2019-20808 (In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI V CVE-2019-20807 (In Vim before 8.1.0881, users can circumvent the rvim restricted mode ...) - vim 2:8.1.2136-1 [buster] - vim <no-dsa> (Minor issue) - [stretch] - vim <no-dsa> (Minor issue) [jessie] - vim <no-dsa> (Minor issue) NOTE: https://github.com/vim/vim/commit/8c62a08faf89663e5633dc5036cd8695c80f1075 CVE-2020-13644 (An issue was discovered in the Accordion plugin before 2.2.9 for WordP ...) @@ -263627,7 +263624,6 @@ CVE-2017-17088 (The Enterprise version of SyncBreeze 10.2.12 and earlier is affe CVE-2017-17087 (fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp f ...) {DLA-1871-1} - vim 2:8.0.1401-1 - [stretch] - vim <no-dsa> (Minor issue) [wheezy] - vim <no-dsa> (Minor issue) NOTE: https://github.com/vim/vim/commit/5a73e0ca54c77e067c3b12ea6f35e3e8681e8cf8 (8.0.1263) CVE-2017-17086 (Indeo Otter through 1.7.4 mishandles a "</script>" substring in ...) ===================================== data/DLA/list ===================================== @@ -1,3 +1,6 @@ +[10 Jan 2022] DLA-2876-1 vim - security update + {CVE-2017-17087 CVE-2019-20807 CVE-2021-3778 CVE-2021-3796} + [stretch] - vim 2:8.0.0197-4+deb9u4 [10 Jan 2022] DLA-2875-1 clamav - security update [stretch] - clamav 0.103.4+dfsg-0+deb9u1 [04 Jan 2022] DLA-2874-1 thunderbird - security update ===================================== data/dla-needed.txt ===================================== @@ -114,13 +114,6 @@ sphinxsearch (Thorsten Alteholz) thunderbird (Emilio) NOTE: 20220104: ftbfs on armhf (pochu) -- -vim (Anton) - NOTE: 20211203: adding here as it's in the ela-needed as well - NOTE: 20211203: so worth fixing in stretch, too. Co-ordinate w/ - NOTE: 20211203: Emilio since he's working on it for jessie. (utkarsh) - NOTE: 20211220: WIP (Anton) - NOTE: 20220103: Upload is planed this week (Anton) --- wordpress (Utkarsh) NOTE: 20220108: Issues may not warrant a DLA. See comment for commit 3ae7f35d1 re. previous release. (lamby) -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e874c583c7ed5259ebbe3e1dda3976d9ed83aea You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits