summaryrefslogtreecommitdiffstats
path: root/data/dsa-needed.txt
blob: ff02a455ab59f6dd9711c082438e09e6cbd7fc86 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
A DSA is needed for the following source packages in old/stable. The specific
CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from
https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE
when working on an update.

Some packages are not tracked here:
- Linux kernel (tracking in kernel-sec repo)
- Embargoed issues continue to be tracked in separate file.

To pick an issue, simply add your uid behind it.

If needed, specify the release by adding a slash after the name of the source package.

--
asterisk/oldstable
--
cacti
--
cifs-utils (carnil)
--
curl
--
epiphany-browser
--
freecad (aron)
--
libpgjava (apo)
--
linux (carnil)
  Wait until more issues have piled up, though try to regulary rebase for point
  releases to more recent v4.19.y versions.
--
ndpi/oldstable
--
nodejs (jmm)
--
puma/oldstable
--
rpki-client/stable
  new 7.6 release required libretls, which isn't in Bullseye
--
rsyslog (carnil)
  Assessment ongoing with maintainer to see if warranted
--
salt
--
slurm-llnl/oldstable
--
slurm-wlm/stable
--
smarty3 (apo)
--
sox
--
spi (seb)
  2022-05-25: maintainer proposed debdiffs
--
thunderbird (jmm)
--
trafficserver (jmm)
  wait until status for CVE-2021-38161 is clarified (upstream patch got reverted)
  Maintainer prepared debdiffs for review for a set of CVEs
--
unzip
  unclear information, initial report indicates writable memory corruption, but
  some identified patch is just for a NULL deref, needs more clarification
--
waitress (jmm)
--
wordpress
--
webkit2gtk
--
wpewebkit
--

© 2014-2024 Faster IT GmbH | imprint | privacy policy