Bug#985427: Wrong DLA number for spice CVEs

Boyuan Yang <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <c7650d4afcd848976e2a7a197de531c2cf6fcee5.camel__14856.6020232224$1616272224$gmane$org@debian.org>
Hi,

在 2021-03-18星期四的 07:15 +0100,Salvatore Bonaccorso写道:
> For the record, the security-tracker ships the authoritative
> assignment, they are:
> 
> [31 Aug 2018] DLA-1488-1 mariadb-10.0 - security update
>         {CVE-2018-3058 CVE-2018-3063 CVE-2018-3064 CVE-2018-3066}
>         [jessie] - mariadb-10.0 10.0.36-0+deb8u1
> 
> [31 Aug 2018] DLA-1486-1 spice - security update
>         {CVE-2018-10873}
>         [jessie] - spice 0.12.5-1+deb8u6
> 
> https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec38e10ec1289c204c18999585bcbf7967ad7413
> and
> https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdaa7f41280c397e155037320704cde369172aae
> 
> So the wepage of DLA 1488 should just be correct to for the mariadb-
> 10.0
> announcement. (The spice DLA seems to have been sent out twice).


I'd be glad to apply the fix if anyone provides a patch or a Merge
Request targeting this issue for
https://salsa.debian.org/webmaster-team/webwml/ repository.

Thanks,
Boyuan Yang
signature.asc (application/pgp-signature, 858 B)
-----BEGIN PGP SIGNATURE-----

iQJFBAABCgAvFiEEfncpR22H1vEdkazLwpPntGGCWs4FAmBWWnYRHGJ5YW5nQGRl
Ymlhbi5vcmcACgkQwpPntGGCWs5yLA//fUpJUjyMwhPw8dGkaPhdlGMGnz2ZzdH8
Rud0qtNOCVki7s40QXk8kCJzYxxnXgYa+maolYWqb4DUSmjGdAR3oZLL/sVnn9En
5FpXcp7OUn/cikgN9/bQDu7DsKPPDRO29P9WteyILSp3qxJ0EbNgecojWly+SsMC
eTGIeuxlte3gwmQmUXD5vrneYURweGBTd8coVW/tCpRjK8Rt+Wiha3iMgxB6byDm
B1HvStDfLfRynvDemFZVsbXrLdCqTnGVT42dNEaoQK00KSq6LZV6xTE5DbTIXtKS
x44n9pANCf7my0tA33I6wB1mjQjnushbCux2rCrF6GyHBbn8VdXET2JT04fXfd/i
1o2+f2HrLaNc957vvb4zDdDUNOG2k9zzEvDj14zMJIUQBn9oly9bXDkuHmeIcKwV
BCX5Wt3OA7O2MljOmDizq+mz3z0LnbPnaKeQQPIHa7WciOPrgKdx3ALJRIEQe+6Y
wBSd6QkFyydfo2Atm8BJ2mezF1hUTFxleix9iS7AX6cLruvrICWqLJ1UQ8GNwFA3
21gGqYmEQxDRejrYErKJoU7+2hDoMxmCi1o8zvZz+2+TF8IbJf5iSRRyIrrgPR9a
kwYo43K1VvEtMwU5MnU6EdAwUXVdyTnniFu4KynhUmSlw8qscQbX6MRJz8nNmihs
JB/01YJ8YV4=
=PByz
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.