Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3b86e6c8 by Salvatore Bonaccorso at 2018-05-18T20:30:51+02:00
Drop some no-dsa/postponed items for qemu/stretch as proposed by aintainer

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -14667,7 +14667,6 @@ CVE-2018-5773 (An issue was discovered in markdown2 
(aka python-markdown2) throu
        NOT-FOR-US: python-markdown2 (not our markdown, different code base)
 CVE-2017-18043 (Integer overflow in the macro ROUND_UP (n, d) in Quick 
Emulator (Qemu) ...)
        - qemu 1:2.10.0+dfsg-2
-       [stretch] - qemu <postponed> (Can be fixed along in a future DSA)
        [jessie] - qemu <postponed> (Can be fixed along in a future DSA)
        [wheezy] - qemu <not-affected> (vulnerable code not present)
        - qemu-kvm <removed>
@@ -15029,7 +15028,6 @@ CVE-2018-5684 (In Libav through 12.2, there is an 
invalid memcpy call in the ...
        NOTE: https://bugzilla.libav.org/show_bug.cgi?id=1110
 CVE-2018-5683 (The vga_draw_text function in Qemu allows local OS guest 
privileged ...)
        - qemu 1:2.12~rc3+dfsg-1 (bug #887392)
-       [stretch] - qemu <postponed> (Minor issue, can be fixed along in future 
DSA)
        [jessie] - qemu <postponed> (Minor issue, can be fixed along in future 
DSA)
        [wheezy] - qemu <postponed> (Minor issue, can be fixed along in next 
DLA)
        - qemu-kvm <removed>
@@ -27462,7 +27460,6 @@ CVE-2017-17382 (Citrix NetScaler Application Delivery 
Controller (ADC) and NetSc
        NOTE: https://robotattack.org/
 CVE-2017-17381 (The Virtio Vring implementation in QEMU allows local OS guest 
users to ...)
        - qemu 1:2.11+dfsg-1 (bug #883625)
-       [stretch] - qemu <postponed> (Can be fixed along in later update)
        [jessie] - qemu <not-affected> (Vulnerable code not present)
        [wheezy] - qemu <postponed> (Can be fixed along in later update)
        - qemu-kvm <removed>
@@ -31698,7 +31695,6 @@ CVE-2017-16846 (Zoho ManageEngine Applications Manager 
13 allows SQL injection v
        NOT-FOR-US: Zoho ManageEngine Applications Manager
 CVE-2017-16845 (hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' 
values ...)
        - qemu 1:2.12~rc3+dfsg-1 (bug #882136)
-       [stretch] - qemu <no-dsa> (Minor issue)
        [jessie] - qemu <no-dsa> (Minor issue)
        [wheezy] - qemu <postponed> (Can be fixed along in a future update)
        - qemu-kvm <removed>
@@ -36181,7 +36177,6 @@ CVE-2017-15590 (An issue was discovered in Xen through 
4.9.x allowing x86 guest 
        NOTE: https://xenbits.xen.org/xsa/advisory-237.html
 CVE-2017-15289 (The mode4and5 write functions in hw/display/cirrus_vga.c in 
Qemu allow ...)
        - qemu 1:2.11+dfsg-1 (bug #880832)
-       [stretch] - qemu <no-dsa> (Minor issue)
        [jessie] - qemu <no-dsa> (Minor issue)
        [wheezy] - qemu <postponed> (Can be fixed along in a future update)
        - qemu-kvm <removed>
@@ -36259,7 +36254,6 @@ CVE-2017-15269 (The PSFTPd 10.0.4 Build 729 server does 
not prevent FTP bounce s
        NOT-FOR-US: PSFTPd
 CVE-2017-15268 (Qemu through 2.10.0 allows remote attackers to cause a memory 
leak by ...)
        - qemu 1:2.11+dfsg-1 (bug #880836)
-       [stretch] - qemu <no-dsa> (Minor issue)
        [jessie] - qemu <not-affected> (I/O channels driver websockets 
introduced later)
        [wheezy] - qemu <not-affected> (I/O channels driver websockets 
introduced later)
        - qemu-kvm <not-affected> (I/O channels driver websockets introduced 
later)
@@ -36735,7 +36729,6 @@ CVE-2017-15120 [Crafted CNAME answer can cause a denial 
of service]
 CVE-2017-15119 [DoS via large option request]
        RESERVED
        - qemu 1:2.11+dfsg-1 (bug #883399)
-       [stretch] - qemu <postponed> (Can be fixed along in later update)
        [jessie] - qemu <not-affected> (Vulnerable code not present)
        [wheezy] - qemu <not-affected> (Vulnerable code not present)
        - qemu-kvm <removed>
@@ -37076,7 +37069,6 @@ CVE-2017-15039 (Cross-site scripting (XSS) exists in 
Zurmo 3.2.1.57987acc3018 vi
 CVE-2017-15038 (Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c 
in QEMU ...)
        {DLA-1129-1 DLA-1128-1}
        - qemu 1:2.10.0+dfsg-2 (bug #877890)
-       [stretch] - qemu <no-dsa> (Minor issue)
        [jessie] - qemu <no-dsa> (Minor issue)
        - qemu-kvm <removed>
        NOTE: 
https://lists.gnu.org/archive/html/qemu-devel/2017-10/msg00729.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/3b86e6c81f097dc90e46bc7cfda47a8574868d1c

---
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/3b86e6c81f097dc90e46bc7cfda47a8574868d1c
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to