Markus Koschany pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d6fe26eb by Markus Koschany at 2023-01-11T23:42:28+01:00
Reserve DLA-3268-1 for netty
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -90449,7 +90449,6 @@ CVE-2021-43798 (Grafana is an open-source platform for
monitoring and observabil
- grafana <removed>
CVE-2021-43797 (Netty is an asynchronous event-driven network application
framework fo ...)
- netty 1:4.1.48-6 (bug #1001437)
- [buster] - netty <no-dsa> (Minor issue)
[stretch] - netty <no-dsa> (Minor issue)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-wx5j-54mm-rqqq
NOTE:
https://github.com/netty/netty/commit/07aa6b5938a8b6ed7a6586e066400e2643897323
(netty-4.1.71.Final)
@@ -110930,13 +110929,11 @@ CVE-2021-37138
RESERVED
CVE-2021-37137 (The Snappy frame decoder function doesn't restrict the chunk
length wh ...)
- netty 1:4.1.48-6 (bug #1014769)
- [buster] - netty <no-dsa> (Minor issue)
[stretch] - netty <no-dsa> (Minor issue)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-9vjp-v76f-g363
NOTE: Fixed by:
https://github.com/netty/netty/commit/6da4956b31023ae967451e1d94ff51a746a9194f
(netty-4.1.68.Final)
CVE-2021-37136 (The Bzip2 decompression decoder function doesn't allow setting
size re ...)
- netty 1:4.1.48-6 (bug #1014769)
- [buster] - netty <no-dsa> (Minor issue)
[stretch] - netty <no-dsa> (Minor issue)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv
NOTE: Fixed by:
https://github.com/netty/netty/commit/41d3d61a61608f2223bb364955ab2045dd5e4020
(netty-4.1.68.Final)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[11 Jan 2023] DLA-3268-1 netty - security update
+ {CVE-2021-37136 CVE-2021-37137 CVE-2021-43797 CVE-2022-41881
CVE-2022-41915}
+ [buster] - netty 1:4.1.33-1+deb10u3
[11 Jan 2023] DLA-3267-1 libxstream-java - security update
{CVE-2022-41966}
[buster] - libxstream-java 1.4.11.1-1+deb10u4
=====================================
data/dla-needed.txt
=====================================
@@ -170,11 +170,6 @@ netatalk
NOTE: 20221212: VCS: https://salsa.debian.org/lts-team/packages/netatalk
NOTE: 20221212: Work is ongoing. CVE-2022-0194 is probably too intrusive.
(gladk)
--
-netty (Markus Koschany)
- NOTE: 20221225: Programming language: Java.
- NOTE: 20221225: VCS: https://salsa.debian.org/lts-team/packages/netty.git
- NOTE: 20221225: Testsuite:
https://lts-team.pages.debian.net/wiki/TestSuites/netty.html
---
nextcloud-desktop
NOTE: 20221128: Programming language: C++.
NOTE: 20221128: VCS: https://salsa.debian.org/owncloud-team/nextcloud-desktop
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fe26ebdd7da582c7dd1db2135dde2457204c8a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6fe26ebdd7da582c7dd1db2135dde2457204c8a
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits