From 72a9a60f99c0f24a11b64261d7d541d8146c4ea2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Roberto=20C=2E=20S=C3=A1nchez?= Date: Sat, 9 Oct 2021 17:16:29 -0400 Subject: LTS: update CVE-2020-23226/cacti and drop cacti from dla-needed.txt --- data/CVE/list | 2 +- data/dla-needed.txt | 4 ---- 2 files changed, 1 insertion(+), 5 deletions(-) (limited to 'data') diff --git a/data/CVE/list b/data/CVE/list index b33f152cc4..a0b0951605 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -76835,7 +76835,7 @@ CVE-2020-23227 CVE-2020-23226 (Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1. ...) - cacti 1.2.13+ds1-1 [buster] - cacti (Minor issues) - [stretch] - cacti (Minor issues) + [stretch] - cacti (Minor issues; also requires semi-intrusive change to be backported) NOTE: https://github.com/Cacti/cacti/issues/3549 NOTE: https://github.com/Cacti/cacti/commit/8d5fbc48debddc91a66b5aed877060566c6b6232 (1.2.13) NOTE: https://github.com/Cacti/cacti/commit/74c011ba8635902713c530ded90bc0a045ca461d (1.2.13) diff --git a/data/dla-needed.txt b/data/dla-needed.txt index 3dc1e01239..2d67c793e1 100644 --- a/data/dla-needed.txt +++ b/data/dla-needed.txt @@ -23,10 +23,6 @@ ansible (Lee Garrett) NOTE: 20210411: after that LTS. (apo) NOTE: 20210426: https://people.debian.org/~apo/lts/ansible/ -- -cacti (Roberto C. Sánchez) - NOTE: 20210829: not really sure whether affected, please recheck - NOTE: 20210914: still assessing whether or not affected (roberto) --- debian-archive-keyring (Utkarsh) NOTE: https://lists.debian.org/debian-lts/2021/08/msg00037.html NOTE: 20210920: Raphael answered. will backport today. (utkarsh) -- cgit v1.2.3