Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits: 33a542d1 by Thorsten Alteholz at 2021-01-23T00:51:39+01:00 add xmlbeans - - - - - 1b320853 by Thorsten Alteholz at 2021-01-23T00:59:24+01:00 mark CVE-2020-27827 as no-dsa for openvswitch in Stretch - - - - - c0a091b7 by Thorsten Alteholz at 2021-01-23T01:03:33+01:00 nark CVE-2015-8011 as no-dsa for openvswitch in Stretch - - - - - 6f9d65ea by Thorsten Alteholz at 2021-01-23T01:04:54+01:00 xen is EOL in Stretch - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -758,6 +758,7 @@ CVE-2019-25014 CVE-2021-XXXX [Xen: IRQ vector leak on x86] - xen <unfixed> [buster] - xen <postponed> (Fix along in future update) + [stretch] - xen <end-of-life> (DSA 4602-1) NOTE: https://xenbits.xen.org/xsa/advisory-360.html CVE-2021-3189 RESERVED @@ -23823,6 +23824,7 @@ CVE-2020-27827 [lldp: avoid memory leak from bad packets] [buster] - lldpd <no-dsa> (Minor issue) [stretch] - lldpd <no-dsa> (Minor issue) - openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-4 (bug #980132) + [stretch] - openvswitch <no-dsa> (Minor issue) NOTE: https://github.com/openvswitch/ovs/pull/337 NOTE: https://github.com/lldpd/lldpd/commit/a8d3c90feca548fc0656d95b5d278713db86ff61 NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000269.html @@ -288580,6 +288582,7 @@ CVE-2015-8011 (Buffer overflow in the lldp_decode function in daemon/protocols/l [wheezy] - lldpd <not-affected> (Vulnerable code not present) [squeeze] - lldpd <not-affected> (Vulnerable code not present) - openvswitch 2.15.0~git20210104.def6eb1ea+dfsg1-1 + [stretch] - openvswitch <no-dsa> (Minor issue) NOTE: https://github.com/lldpd/lldpd/commit/dd4f16e7e816f2165fba76e3d162cd8d2978dcb2 NOTE: https://www.openwall.com/lists/oss-security/2015/10/16/2 NOTE: https://mail.openvswitch.org/pipermail/ovs-announce/2021-January/000268.html ===================================== data/dla-needed.txt ===================================== @@ -156,3 +156,5 @@ xcftools NOTE: 20200523: Proposed fix https://github.com/j-jorge/xcftools/pull/15 (gladk) NOTE: 20200605: Patch https://salsa.debian.org/lts-team/packages/xcftools/-/blob/fix/test-CVE-2019-5087/debian/patches/CVE-2019-5087.patch (gladk) -- +xmlbeans +-- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/63a4a42f5df8fc3030ad1422c54ef7cee6932367...6f9d65ead4a541a2b075150ec45382eb576e6db7 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits