Re: "Recommended" status of Leap update openSUSE-2020-1390

Marcus Meissner <[email protected]> Sun, 13 Sep 2020 09:14:41 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Software Solutions Ger many GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany , GF: Felix Imendörffer, HRB 36809, AG Nürnber g
Message-ID <[email protected]>
On Sat, Sep 12, 2020 at 10:06:23PM +0300, Alexander Shchadilov wrote:
> Hello,
> openSUSE-2020-1390 patch for "libmediainfo" and "mediainfo" fixes some
> CVE issue but is classified as "recommended" and not as "security".
> https://bugzilla.suse.com/show_bug.cgi?id=1173630
> https://lists.opensuse.org/opensuse-updates/2020-09/msg00077.html
> 
> Does this mean that "security" status is restricted to updates that
> modify critical software from some closed list (a list of packages
> that is tracked by the security team)?

We depend a bit on the packagers also mentioning the CVE in their
changes entries (and not just this line:

- Add libmediainfo-MpegPs.patch (fixes boo#1173630)

)

As it was not correctly submitted (without CVE in changes entry)
I missed this while processing it.

So if you have a CVE, please always also add it to the .changes entry,
our automation then automatically marks it as security. 

Ciao, Marcus
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]