Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
fe8443a5 by Salvatore Bonaccorso at 2023-05-19T21:32:46+02:00
Add additional tracking for src:pupnp for issues

They were open for src:pupnp-1.8 but fixed with the renamed source
package to experimental. Track exceptionally already as expected that
once it moves to unstable all fixes still are contained.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -157068,6 +157068,7 @@ CVE-2021-29463 (Exiv2 is a command-line utility and 
C++ library for reading, wri
        NOTE: 
https://github.com/Exiv2/exiv2/security/advisories/GHSA-5p8g-9xf3-gfrr
        NOTE: 
https://github.com/Exiv2/exiv2/commit/783b3a6ff15ed6f82a8f8e6c8a6f3b84a9b04d4b
 CVE-2021-29462 (The Portable SDK for UPnP Devices is an SDK for development of 
UPnP de ...)
+       - pupnp <not-affected> (Fixed before initial upload to Debian after 
source package rename)
        - pupnp-1.8 <unfixed> (bug #987326)
        [bookworm] - pupnp-1.8 <no-dsa> (Minor issue)
        [bullseye] - pupnp-1.8 <no-dsa> (Minor issue)
@@ -159925,6 +159926,7 @@ CVE-2021-28304
 CVE-2021-28303
        RESERVED
 CVE-2021-28302 (A stack overflow in pupnp before version 1.14.5 can cause the 
denial o ...)
+       - pupnp <not-affected> (Fixed before initial upload to Debian after 
source package rename)
        - pupnp-1.8 <unfixed> (bug #986833)
        [bookworm] - pupnp-1.8 <no-dsa> (Minor issue)
        [bullseye] - pupnp-1.8 <no-dsa> (Minor issue)
@@ -225666,6 +225668,7 @@ CVE-2020-13849 (The MQTT protocol 3.1.1 requires a 
server to set a timeout value
        NOT-FOR-US: MQTT protocol flaw
 CVE-2020-13848 (Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows 
remote attac ...)
        {DLA-2585-1 DLA-2238-1}
+       - pupnp <not-affected> (Fixed before initial upload to Debian after 
source package rename)
        - pupnp-1.8 <unfixed> (bug #962282)
        [bookworm] - pupnp-1.8 <no-dsa> (Minor issue)
        [bullseye] - pupnp-1.8 <no-dsa> (Minor issue)
@@ -228675,6 +228678,7 @@ CVE-2020-12695 (The Open Connectivity Foundation UPnP 
specification before 2020-
        - gupnp 1.2.3-1
        [buster] - gupnp 1.0.5-0+deb10u1
        - minidlna 1.2.1+dfsg-3 (bug #976594)
+       - pupnp <not-affected> (Fixed before initial upload to Debian after 
source package rename)
        - pupnp-1.8 <unfixed> (bug #983206)
        [bookworm] - pupnp-1.8 <no-dsa> (Minor issue)
        [bullseye] - pupnp-1.8 <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe8443a5ca836e2f6718b2ed1933bd45e9430e97

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe8443a5ca836e2f6718b2ed1933bd45e9430e97
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to