summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorUtkarsh Gupta <utkarsh@debian.org>2021-12-29 18:09:01 +0530
committerUtkarsh Gupta <utkarsh@debian.org>2021-12-29 18:09:01 +0530
commitcd4dce6ee8493dfe0e255c0f116c38a1a8da5c39 (patch)
tree8a3b772996e75a8f0b0c254f09e16a1f6fb36b43
parentf384884620babe54a3c509fc9e6b678e2f24b7be (diff)
Reserve DLA-2864-1 for ruby-haml
-rw-r--r--data/CVE/list.20171
-rw-r--r--data/DLA/list3
-rw-r--r--data/dla-needed.txt4
3 files changed, 3 insertions, 5 deletions
diff --git a/data/CVE/list.2017 b/data/CVE/list.2017
index 0d424ebeed..9a94998c29 100644
--- a/data/CVE/list.2017
+++ b/data/CVE/list.2017
@@ -638,7 +638,6 @@ CVE-2017-18639 (Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parame
CVE-2017-1002201 (In haml versions prior to version 5.0.0.beta.2, when using user input ...)
{DLA-1986-1}
- ruby-haml 5.0.4-1
- [stretch] - ruby-haml <no-dsa> (Minor issue)
NOTE: https://snyk.io/vuln/SNYK-RUBY-HAML-20362
NOTE: https://github.com/haml/haml/commit/18576ae6e9bdcb4303fdbe6b3199869d289d67c2
CVE-2017-18638 (send_email in graphite-web/webapp/graphite/composer/views.py in Graphi ...)
diff --git a/data/DLA/list b/data/DLA/list
index df93a88c8b..e8cc36d2b1 100644
--- a/data/DLA/list
+++ b/data/DLA/list
@@ -1,3 +1,6 @@
+[29 Dec 2021] DLA-2864-1 ruby-haml - security update
+ {CVE-2017-1002201}
+ [stretch] - ruby-haml 4.0.7-1+deb9u1
[29 Dec 2021] DLA-2863-1 firefox-esr - security update
{CVE-2021-38503 CVE-2021-38504 CVE-2021-38506 CVE-2021-38507 CVE-2021-38508 CVE-2021-38509 CVE-2021-43534 CVE-2021-43535 CVE-2021-43536 CVE-2021-43537 CVE-2021-43538 CVE-2021-43539 CVE-2021-43541 CVE-2021-43542 CVE-2021-43543 CVE-2021-43545 CVE-2021-43546}
[stretch] - firefox-esr 91.4.1esr-1~deb9u1
diff --git a/data/dla-needed.txt b/data/dla-needed.txt
index 0272d0d0e6..0192c38214 100644
--- a/data/dla-needed.txt
+++ b/data/dla-needed.txt
@@ -83,10 +83,6 @@ pgbouncer (Christoph Berg)
--
resiprocate (Adrian Bunk)
--
-ruby-haml (Utkarsh Gupta)
- NOTE: 20211229: more commits to be added rather than just one.
- NOTE: 20211229: taking over w/ permission since fixed it earlier as well. (utkarsh)
---
samba (Utkarsh Gupta)
NOTE: 20211128: WIP https://salsa.debian.org/lts-team/packages/samba/
NOTE: 20211212: Fix is too large, coordination with ELTS-upload

© 2014-2024 Faster IT GmbH | imprint | privacy policy