Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker
Commits: 67573539 by Roberto C. Sánchez at 2019-11-18T02:30:55Z CVE-2019-12779/libqb: jessie end-of-life - - - - - b55d19b5 by Roberto C. Sánchez at 2019-11-18T02:31:37Z LTS/libqb: remove from dla-needed.txt as it is now EOL - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -21647,6 +21647,7 @@ CVE-2019-5439 (A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash w NOTE: http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security CVE-2019-12779 (libqb before 1.0.5 allows local users to overwrite arbitrary files via ...) - libqb 1.0.4-1 (unimportant; bug #927159) + [jessie] - libqb <end-of-life> (https://salsa.debian.org/debian/debian-security-support/commit/ba638006d397eda2cc094761ed7a7bfdca9e534b) NOTE: https://github.com/ClusterLabs/libqb/issues/338 NOTE: https://github.com/ClusterLabs/libqb/commit/6a4067c1d1764d93d255eccecfd8bf9f43cb0b4d NOTE: Regression fix: https://github.com/ClusterLabs/libqb/pull/349 ===================================== data/dla-needed.txt ===================================== @@ -71,13 +71,6 @@ libmatio (Adrian Bunk) NOTE: 20190428: older changes seem to also be required for them NOTE: 20191111: work is ongoing -- -libqb (Roberto C. Sánchez) - NOTE: 20190616: Upstream patch does not apply at all, but it appears that - NOTE: 20190616: package is still vulnerable in ipc_posix_mq.c etc. or - NOTE: 20190616: wherever it uses c->pid w/NAME_MAX. (lamby) - NOTE: 20190619: See https://lists.debian.org/debian-lts/2019/06/msg00015.html - NOTE: 20191111: Made an attempt at backporting relevant commits; requested review by upstream. (roberto) --- libvpx (Dylan Aïssi) -- linux (Ben Hutchings) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d989a77d1fe360ab0be6183b331fc3384f19db7d...b55d19b5bbb358f7ff4b090e0a1640e40f371af6 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits