blob: 0ae62fd7a8a1c11a1fd7cc4b7cf55bcdf482fea8 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
|
A DSA is needed for the following source packages in old/stable. The specific
CVE IDs do not need to be listed, they can be gathered in an up-to-date manner from
https://security-tracker.debian.org/tracker/source-package/SOURCEPACKAGE
when working on an update.
Some packages are not tracked here:
- Linux kernel (tracking in kernel-sec repo)
- Embargoed issues continue to be tracked in separate file.
To pick an issue, simply add your uid behind it.
If needed, specify the release by adding a slash after the name of the source package.
--
389-ds-base (fw)
--
asterisk/stable
berni working on updates
--
bouncycastle/stable
Markus Koschany proposed an update for stretch
--
chromium-browser
--
dokuwiki/oldstable
anarcat proposed an update for CVE-2017-18123, needs review and ack
--
enigmail
--
ffmpeg/stable
Wait for next 3.2.x release
--
glusterfs
--
graphicsmagick
--
imagemagick (jmm)
--
intel-microcode
or possibly via spu, depends on timing of release and other factors
--
knot-resolver
--
libav/oldstable
We can ship the next libav 11.x point release when available
--
libgcrypt20 (carnil)
--
libidn
santiago proposed debdiffs for jessie and stretch
--
linux
Wait until more issues have piled up
--
mariadb-10.0/oldstable
--
mariadb-10.1/stable
--
mercurial
2018-06-07: jessie update proposed by anarcat in https://lists.debian.org/87y3fr75kk.fsf@angela.anarc.at
--
mosquitto (seb)
2018-02-27: Roger Light provided a debdiff targetting stretch, needs review
--
openjpeg2 (luciano)
--
passenger/stable
--
php5/oldstable
--
php7.0/stable
--
php-horde-image
--
phpmyadmin/oldstable
https://mentors.debian.net/debian/pool/main/p/phpmyadmin/phpmyadmin_4.2.12-2+deb8u3.dsc, abhijith
--
ruby2.1/oldstable
Santiago will prepare an update
work-in-progress: https://salsa.debian.org/ruby-team/ruby/tree/jessie-security-wip
--
ruby2.3/stable
Santiago will prepare an update
work-in-progress: https://salsa.debian.org/ruby-team/ruby/tree/stretch-security-wip
--
sssd/stable
Maintainer prepared an update and proposed debdiff, acked for upload, but update needs further testing before release.
--
strongswan (corsac)
--
thunderbird
--
tomcat7/oldstable
--
tomcat8 (seb)
2018-04-11: Emmanuel Bourg submitted a debdiff
--
zendframework/oldstable
--
|