From cdb8a2c7102c7e107dc22f42d98c298a926f4855 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sun, 2 Aug 2020 20:42:35 +0200 Subject: Mark CVE-2020-14344/libx11 as no-dsa Notably the original patchset causes regressions[1], reported upstream[2]. [1]: [2]: --- data/CVE/list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list b/data/CVE/list index 59d4e97204..73bf3c94a4 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -4668,6 +4668,7 @@ CVE-2020-14345 CVE-2020-14344 [Heap corruption in the X input method client in libX11] RESERVED - libx11 2:1.6.10-1 + [buster] - libx11 (Minor issue) NOTE: https://lists.x.org/archives/xorg-announce/2020-July/003050.html NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/0e6561efcfaa0ae7b5c74eac7e064b76d687544e NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/388b303c62aa35a245f1704211a023440ad2c488 -- cgit v1.2.3