summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMarkus Koschany <apo@debian.org>2021-04-01 20:10:33 +0200
committerMarkus Koschany <apo@debian.org>2021-04-01 20:10:33 +0200
commit002d58a19c2d0ff3d2c2dfdde1d8c267b88a8355 (patch)
treea0b8626e8e348ab2fa023d21342a972e1d44a6e5
parent9104f1a604cd01e5e2f32092d564dffba5664609 (diff)
Reserve DLA-2614-1 for busybox
-rw-r--r--data/DLA/list3
-rw-r--r--data/dla-needed.txt4
2 files changed, 3 insertions, 4 deletions
diff --git a/data/DLA/list b/data/DLA/list
index 727acd13b9..a4509fcda0 100644
--- a/data/DLA/list
+++ b/data/DLA/list
@@ -1,3 +1,6 @@
+[01 Apr 2021] DLA-2614-1 busybox - security update
+ {CVE-2021-28831}
+ [stretch] - busybox 1:1.22.0-19+deb9u2
[31 Mar 2021] DLA-2613-1 underscore - security update
{CVE-2021-23358}
[stretch] - underscore 1.8.3~dfsg-1+deb9u1
diff --git a/data/dla-needed.txt b/data/dla-needed.txt
index d2d68e8e7d..e76bcbbaec 100644
--- a/data/dla-needed.txt
+++ b/data/dla-needed.txt
@@ -17,10 +17,6 @@ ansible (Markus Koschany)
NOTE: 20210322: As discussed with the maintainer I will update Buster first and
NOTE: 20210322: after that LTS. Will ask for a maintainer review later this week.
--
-busybox
- NOTE: 20210319: Version in LTS is missing BAD_HUFT check in the patch, so perhaps
- NOTE: 20210319: we are missing other vulnerabilities in this file. (lamby)
---
ceph
NOTE: 20200707: Vulnerable to at least CVE-2018-14662. (lamby)
NOTE: 20200707: Some discussion regarding removal <https://lists.debian.org/debian-lts/2020/04/msg00019.html> (lamby)

© 2014-2024 Faster IT GmbH | imprint | privacy policy