From 14f929ca57708a679eaf87f8ee0c5c3de388c263 Mon Sep 17 00:00:00 2001 From: Sylvain Beucler Date: Fri, 4 Nov 2022 15:04:32 +0100 Subject: Reserve DLA-3178-1 for ffmpeg --- data/DLA/list | 2 ++ data/dla-needed.txt | 3 --- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/data/DLA/list b/data/DLA/list index a5dfc1ca6c..f36853747b 100644 --- a/data/DLA/list +++ b/data/DLA/list @@ -1,3 +1,5 @@ +[04 Nov 2022] DLA-3178-1 ffmpeg - security update + [buster] - ffmpeg 7:4.1.10-0+deb10u1 [04 Nov 2022] DLA-3177-1 python-django - security update {CVE-2021-45115 CVE-2021-45116 CVE-2022-28346} [buster] - python-django 1:1.11.29-1+deb10u3 diff --git a/data/dla-needed.txt b/data/dla-needed.txt index 1383783783..7cd3691530 100644 --- a/data/dla-needed.txt +++ b/data/dla-needed.txt @@ -47,9 +47,6 @@ exiv2 (Dominik George) NOTE: 20220819: Programming language: C++. NOTE: 20220819: https://github.com/Exiv2/exiv2/commit/109d5df7abd329f141b500c92a00178d35a6bef3#diff-bd28aafd4c87975a3a236af74c2200db447587fa0bb4f43ba9beb98738c77b2aL292 does not directly apply, but a very quick glance suggests the earlier code may be equally vulnerable. (Chris Lamb) -- -ffmpeg (Sylvain Beucler) - NOTE: Should be updated to 4.1.10 --- firmware-nonfree NOTE: 20220906: Consider to check the severity of the issues again and judge whether a correction is worth it. -- -- cgit v1.2.3