summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMarkus Koschany <apo@debian.org>2021-04-01 20:10:33 +0200
committerMarkus Koschany <apo@debian.org>2021-04-01 20:10:33 +0200
commit3c6d95a849de2c373648d237be2f544b4ecde726 (patch)
treea4ac0d5f160b5922a49e6c02da0bf3059cdc7c3e
parente232c5c38a64bc849e696c20d22a8c9791c0266e (diff)
Reserve DLA-2614-1 for busybox
-rw-r--r--data/DLA/list3
-rw-r--r--data/dla-needed.txt4
2 files changed, 3 insertions, 4 deletions
diff --git a/data/DLA/list b/data/DLA/list
index 727acd13b9..a4509fcda0 100644
--- a/data/DLA/list
+++ b/data/DLA/list
@@ -1,3 +1,6 @@
+[01 Apr 2021] DLA-2614-1 busybox - security update
+ {CVE-2021-28831}
+ [stretch] - busybox 1:1.22.0-19+deb9u2
[31 Mar 2021] DLA-2613-1 underscore - security update
{CVE-2021-23358}
[stretch] - underscore 1.8.3~dfsg-1+deb9u1
diff --git a/data/dla-needed.txt b/data/dla-needed.txt
index d2d68e8e7d..e76bcbbaec 100644
--- a/data/dla-needed.txt
+++ b/data/dla-needed.txt
@@ -17,10 +17,6 @@ ansible (Markus Koschany)
NOTE: 20210322: As discussed with the maintainer I will update Buster first and
NOTE: 20210322: after that LTS. Will ask for a maintainer review later this week.
--
-busybox
- NOTE: 20210319: Version in LTS is missing BAD_HUFT check in the patch, so perhaps
- NOTE: 20210319: we are missing other vulnerabilities in this file. (lamby)
---
ceph
NOTE: 20200707: Vulnerable to at least CVE-2018-14662. (lamby)
NOTE: 20200707: Some discussion regarding removal <https://lists.debian.org/debian-lts/2020/04/msg00019.html> (lamby)

© 2014-2024 Faster IT GmbH | imprint | privacy policy