From 0c83acae800fc4464405285cc6e4895e4bf1f81e Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Fri, 5 Mar 2021 09:15:22 +0100 Subject: Do not track CVE-2021-24032 for DLA-2573-1 The CVE was assigned for an incomplete fix (which affected indeed unstable and buster, but for stretch the issue in CVE-2021-24031 was in one go fixed with the correct fix without opening CVE-2021-24032). Adjust tracking to reflect the situation in the supported suites. --- data/CVE/list.2021 | 3 ++- data/DLA/list | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/data/CVE/list.2021 b/data/CVE/list.2021 index 11eeca9c2f..09a7875983 100644 --- a/data/CVE/list.2021 +++ b/data/CVE/list.2021 @@ -2395,8 +2395,9 @@ CVE-2021-26910 (Firejail before 0.9.64.4 allows attackers to bypass intended acc NOTE: https://unparalleled.eu/publications/2021/advisory-unpar-2021-0.txt NOTE: https://unparalleled.eu/blog/2021/20210208-rigged-race-against-firejail-for-local-root/ CVE-2021-24032 (Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for ...) - {DSA-4859-1 DLA-2573-1} + {DSA-4859-1} - libzstd 1.4.8+dfsg-2 (bug #982519) + [stretch] - libzstd (Incomplete fix for CVE-2021-24031 not applied) NOTE: https://github.com/facebook/zstd/issues/2491 CVE-2021-24031 (In the Zstandard command-line utility prior to v1.4.1, output files we ...) {DSA-4850-1 DLA-2573-1} diff --git a/data/DLA/list b/data/DLA/list index 24c15acc4e..9fff463b7b 100644 --- a/data/DLA/list +++ b/data/DLA/list @@ -22,7 +22,7 @@ {CVE-2021-27212} [stretch] - openldap 2.4.44+dfsg-5+deb9u8 [20 Feb 2021] DLA-2573-1 libzstd - security update - {CVE-2021-24031 CVE-2021-24032} + {CVE-2021-24031} [stretch] - libzstd 1.1.2-1+deb9u1 [20 Feb 2021] DLA-2572-1 wpa - security update {CVE-2021-0326} -- cgit v1.2.3