Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c40a35a2 by Chris Lamb at 2021-03-20T10:33:26+00:00
Triage CVE-2021-28834 in ruby-kramdown for stretch LTS.

- - - - -
3aea448f by Chris Lamb at 2021-03-20T10:34:20+00:00
data/dla-needed.txt: Triage ruby-carrierwave for stretch LTS (CVE-2021-21288).

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -242,6 +242,7 @@ CVE-2021-28835
        RESERVED
 CVE-2021-28834 (Kramdown before 2.3.1 does not restrict Rouge formatters to 
the Rouge: ...)
        - ruby-kramdown <unfixed> (bug #985569)
+       [buster] - ruby-kramdown <not-affected> (Vulnerable code added later)
        NOTE: https://github.com/gettalong/kramdown/pull/708
        NOTE: Fixed by: 
https://github.com/gettalong/kramdown/commit/d6a1cbcb2caa2f8a70927f176070d126b2422760
 CVE-2021-28833


=====================================
data/dla-needed.txt
=====================================
@@ -105,6 +105,10 @@ ruby-actionpack-page-caching
 --
 ruby-activerecord-session-store
 --
+ruby-carrierwave
+  NOTE: 20210320: Will be difficult to backport as code in LTS version appears
+  NOTE: 20210320: to use primitive Kernel.open to load URIs. (lamby)
+--
 ruby-doorkeeper
   NOTE: 20200831: it's a breaking change, I'd rather not want to issue a DLA 
for this. (utkarsh)
   NOTE: 20200831: in case it's really DLA worthy, I'd be very careful with 
this update. (utkarsh)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0d369987a95b5155cef768b3f7dcb979758f2364...3aea448fef0b78331cbc842897ef8e6f9126cafd

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0d369987a95b5155cef768b3f7dcb979758f2364...3aea448fef0b78331cbc842897ef8e6f9126cafd
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to