Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits: d289b03d by Sylvain Beucler at 2021-03-18T22:42:14+01:00 CVE-2021-27921,CVE-2021-27922,CVE-2021-27923/pillow: stretch triage - - - - - aaa040ac by Sylvain Beucler at 2021-03-18T22:42:15+01:00 CVE-2018-16428/glib2.0: fixed through stretch o-p-u (but typo in changelog) - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -2066,18 +2066,22 @@ CVE-2021-27924 CVE-2021-27923 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...) - pillow 8.1.2-1 [buster] - pillow <ignored> (Minor issue) + [stretch] - pillow <ignored> (Minor issue, risk of regression, _decompression_bomb_check only warned, see CVE-2019-16865) NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973 CVE-2021-27922 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...) - pillow 8.1.2-1 [buster] - pillow <ignored> (Minor issue) + [stretch] - pillow <ignored> (Minor issue, risk of regression, _decompression_bomb_check only warned, see CVE-2019-16865) NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973 CVE-2021-27921 (Pillow before 8.1.1 allows attackers to cause a denial of service (mem ...) - pillow 8.1.2-1 [buster] - pillow <ignored> (Minor issue) + [stretch] - pillow <not-affected> (Vulnerable code introduced later) NOTE: https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html NOTE: https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973 + NOTE: Introduced in https://github.com/python-pillow/Pillow/commit/adaa70357662a11cd4b7c0beddaad4e92164c5d9 (5.1.0) CVE-2021-27920 RESERVED CVE-2021-27919 (archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a den ...) @@ -165996,7 +166000,7 @@ CVE-2018-16429 (GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_m CVE-2018-16428 (In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c ...) {DLA-1866-1} - glib2.0 2.58.0-1 (low) - [stretch] - glib2.0 <no-dsa> (Minor issue) + [stretch] - glib2.0 2.50.3-2+deb9u1 NOTE: https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9 NOTE: https://gitlab.gnome.org/GNOME/glib/issues/1364 CVE-2018-16427 (Various out of bounds reads when handling responses in OpenSC before 0 ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/651d8b67e8b8c5a0d52c39457840a6fdfb945260...aaa040ac94a53b8be5c9c2f7366ec50f878cb6e4 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits