From 930d09ff0fbdec24203280bbdf1e5d1ccac744a8 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Fri, 31 Jul 2020 17:12:42 +0200 Subject: Track fixes for fwupd in 10.5 --- data/CVE/list | 2 +- data/next-point-update.txt | 2 -- 2 files changed, 1 insertion(+), 3 deletions(-) (limited to 'data') diff --git a/data/CVE/list b/data/CVE/list index 07df1d3965..8af26837f7 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -15053,7 +15053,7 @@ CVE-2020-10759 [Possible bypass in signature verification] RESERVED {DLA-2274-1} - fwupd 1.3.10-1 (bug #962517) - [buster] - fwupd (Will be fixed via point release) + [buster] - fwupd 1.2.13-1 - libjcat 0.1.3-1 NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1844316 NOTE: https://github.com/justinsteven/advisories/blob/master/2020_fwupd_dangling_s3_bucket_and_CVE-2020-10759_signature_verification_bypass.md diff --git a/data/next-point-update.txt b/data/next-point-update.txt index f2c3ef4092..ff063756a5 100644 --- a/data/next-point-update.txt +++ b/data/next-point-update.txt @@ -1,5 +1,3 @@ -CVE-2020-10759 - [buster] - fwupd 1.2.13-1 CVE-2020-7040 [buster] - storebackup 3.2.1-2~deb10u1 CVE-2020-9548 -- cgit v1.2.3