Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits: 66eb9963 by Thorsten Alteholz at 2022-01-22T00:58:18+01:00 mark CVE-2021-41043 as no-dsa for Stretch - - - - - 6d0eae4f by Thorsten Alteholz at 2022-01-22T01:00:44+01:00 mark CVE-2021-40874 as no-dsa for Stretch - - - - - 498703fe by Thorsten Alteholz at 2022-01-22T01:17:05+01:00 add ipython - - - - - abe96cde by Thorsten Alteholz at 2022-01-22T01:21:41+01:00 add ujson - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -22212,6 +22212,7 @@ CVE-2021-41043 (Use after free in tcpslice triggers AddressSanitizer, no other c - tcpslice <unfixed> (bug #1003190) [bullseye] - tcpslice <no-dsa> (Minor issue) [buster] - tcpslice <no-dsa> (Minor issue) + [stretch] - tcpslice <no-dsa> (Minor issue) NOTE: https://github.com/the-tcpdump-group/tcpslice/issues/11 NOTE: https://github.com/the-tcpdump-group/tcpslice/commit/030859fce9c77417de657b9bb29c0f78c2d68f4a (tcpslice-1.5) CVE-2021-41042 @@ -22582,6 +22583,7 @@ CVE-2021-40874 [RESTServer pwdConfirm always returns true with Combination + Ker - lemonldap-ng <unfixed> [bullseye] - lemonldap-ng <no-dsa> (Minor issue) [buster] - lemonldap-ng <no-dsa> (Minor issue) + [stretch] - lemonldap-ng <no-dsa> (Minor issue) NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2612 NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/66946e8f754812b375768c2124937137c856fe0c CVE-2021-40873 (An issue was discovered in Softing Industrial Automation OPC UA C++ SD ...) ===================================== data/dla-needed.txt ===================================== @@ -58,6 +58,8 @@ gpac (Roberto C. Sánchez) guacamole-client NOTE: 20220114: package unmaintained AFAICS and only present in stretch (Beuc) -- +ipython +-- libarchive (Thorsten Alteholz) NOTE: 20220102: testing package NOTE: 20220116: waiting for upload in higher releases @@ -109,6 +111,9 @@ samba (Utkarsh Gupta) NOTE: 20211212: Fix is too large, coordination with ELTS-upload NOTE: 20220110: fix applied, but will need a second opinion. (utkarsh) -- +ujson + NOTE: 20220121: please reheck, at least the mentioned function is available in Stretch +-- vim (Emilio) -- zabbix View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96456572dabf2fb0910608d0c82fa0785155a3c5...abe96cde0646362e316a689589fef811c0213023 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits