Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d289b03d by Sylvain Beucler at 2021-03-18T22:42:14+01:00
CVE-2021-27921,CVE-2021-27922,CVE-2021-27923/pillow: stretch triage

- - - - -
aaa040ac by Sylvain Beucler at 2021-03-18T22:42:15+01:00
CVE-2018-16428/glib2.0: fixed through stretch o-p-u (but typo in changelog)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2066,18 +2066,22 @@ CVE-2021-27924
 CVE-2021-27923 (Pillow before 8.1.1 allows attackers to cause a denial of 
service (mem ...)
        - pillow 8.1.2-1
        [buster] - pillow <ignored> (Minor issue)
+       [stretch] - pillow <ignored> (Minor issue, risk of regression, 
_decompression_bomb_check only warned, see CVE-2019-16865)
        NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
        NOTE: 
https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
 CVE-2021-27922 (Pillow before 8.1.1 allows attackers to cause a denial of 
service (mem ...)
        - pillow 8.1.2-1
        [buster] - pillow <ignored> (Minor issue)
+       [stretch] - pillow <ignored> (Minor issue, risk of regression, 
_decompression_bomb_check only warned, see CVE-2019-16865)
        NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
        NOTE: 
https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
 CVE-2021-27921 (Pillow before 8.1.1 allows attackers to cause a denial of 
service (mem ...)
        - pillow 8.1.2-1
        [buster] - pillow <ignored> (Minor issue)
+       [stretch] - pillow <not-affected> (Vulnerable code introduced later)
        NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html
        NOTE: 
https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973
+       NOTE: Introduced in 
https://github.com/python-pillow/Pillow/commit/adaa70357662a11cd4b7c0beddaad4e92164c5d9
 (5.1.0)
 CVE-2021-27920
        RESERVED
 CVE-2021-27919 (archive/zip in Go 1.16.x before 1.16.1 allows attackers to 
cause a den ...)
@@ -165996,7 +166000,7 @@ CVE-2018-16429 (GNOME GLib 2.56.1 has an 
out-of-bounds read vulnerability in g_m
 CVE-2018-16428 (In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in 
gmarkup.c  ...)
        {DLA-1866-1}
        - glib2.0 2.58.0-1 (low)
-       [stretch] - glib2.0 <no-dsa> (Minor issue)
+       [stretch] - glib2.0 2.50.3-2+deb9u1
        NOTE: 
https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9
        NOTE: https://gitlab.gnome.org/GNOME/glib/issues/1364
 CVE-2018-16427 (Various out of bounds reads when handling responses in OpenSC 
before 0 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to