From 002d58a19c2d0ff3d2c2dfdde1d8c267b88a8355 Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Thu, 1 Apr 2021 20:10:33 +0200 Subject: Reserve DLA-2614-1 for busybox --- data/DLA/list | 3 +++ data/dla-needed.txt | 4 ---- 2 files changed, 3 insertions(+), 4 deletions(-) diff --git a/data/DLA/list b/data/DLA/list index 727acd13b9..a4509fcda0 100644 --- a/data/DLA/list +++ b/data/DLA/list @@ -1,3 +1,6 @@ +[01 Apr 2021] DLA-2614-1 busybox - security update + {CVE-2021-28831} + [stretch] - busybox 1:1.22.0-19+deb9u2 [31 Mar 2021] DLA-2613-1 underscore - security update {CVE-2021-23358} [stretch] - underscore 1.8.3~dfsg-1+deb9u1 diff --git a/data/dla-needed.txt b/data/dla-needed.txt index d2d68e8e7d..e76bcbbaec 100644 --- a/data/dla-needed.txt +++ b/data/dla-needed.txt @@ -17,10 +17,6 @@ ansible (Markus Koschany) NOTE: 20210322: As discussed with the maintainer I will update Buster first and NOTE: 20210322: after that LTS. Will ask for a maintainer review later this week. -- -busybox - NOTE: 20210319: Version in LTS is missing BAD_HUFT check in the patch, so perhaps - NOTE: 20210319: we are missing other vulnerabilities in this file. (lamby) --- ceph NOTE: 20200707: Vulnerable to at least CVE-2018-14662. (lamby) NOTE: 20200707: Some discussion regarding removal (lamby) -- cgit v1.2.3