From dc490bc43734ca33e9c2a2d5774bac03e1337966 Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Tue, 16 Nov 2021 23:23:10 +0100 Subject: Reserve DLA-2819-1 for ntfs-3g --- data/CVE/2021.list | 2 +- data/DLA/list | 3 +++ data/dla-needed.txt | 3 --- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index 4f86b50055..eb338dc7c1 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -4875,7 +4875,7 @@ CVE-2021-41655 CVE-2021-41654 RESERVED CVE-2021-41653 (The PING function on the TP-Link TL-WR840N EU v5 router with firmware ...) - NOT-FOR-US: TP-Link + NOT-FOR-US: TP-Link CVE-2021-41652 RESERVED CVE-2021-41651 (A blind SQL injection vulnerability exists in the Raymart DG / Ahmed H ...) diff --git a/data/DLA/list b/data/DLA/list index 0f8f95fd7b..edb90bb0d8 100644 --- a/data/DLA/list +++ b/data/DLA/list @@ -1,3 +1,6 @@ +[16 Nov 2021] DLA-2819-1 ntfs-3g - security update + {CVE-2021-33285 CVE-2021-33286 CVE-2021-33287 CVE-2021-33289 CVE-2021-35266 CVE-2021-35267 CVE-2021-35268 CVE-2021-35269 CVE-2021-39251 CVE-2021-39252 CVE-2021-39253 CVE-2021-39254 CVE-2021-39255 CVE-2021-39256 CVE-2021-39257 CVE-2021-39258 CVE-2021-39259 CVE-2021-39260 CVE-2021-39261 CVE-2021-39262 CVE-2021-39263} + [stretch] - ntfs-3g 1:2016.2.22AR.1+dfsg-1+deb9u2 [13 Nov 2021] DLA-2818-1 ffmpeg - security update {CVE-2020-20445 CVE-2020-20446 CVE-2020-20451 CVE-2020-20453 CVE-2020-22037 CVE-2020-22041 CVE-2020-22044 CVE-2020-22046 CVE-2020-22048 CVE-2020-22049 CVE-2020-22054 CVE-2021-38171 CVE-2021-38291} [stretch] - ffmpeg 7:3.2.16-1+deb9u1 diff --git a/data/dla-needed.txt b/data/dla-needed.txt index e6881a13ba..d3851f131f 100644 --- a/data/dla-needed.txt +++ b/data/dla-needed.txt @@ -70,9 +70,6 @@ linux-4.19 (Ben Hutchings) -- mbedtls (Emilio) -- -ntfs-3g (Markus Koschany) - NOTE: 20211101: too many CVEs (gladk) --- nvidia-graphics-drivers NOTE: package is in non-free but also in packages-to-support NOTE: only CVE‑2021‑1076 seems to be fixed in the R390 branch used in Stretch, no fix available for CVE-2021-1077 -- cgit v1.2.3