X-Original-To: alpine-aports@lists.alpinelinux.org Received: from mail-wr0-f173.google.com (mail-wr0-f173.google.com [209.85.128.173]) by lists.alpinelinux.org (Postfix) with ESMTP id B06115C4E94 for ; Sun, 4 Mar 2018 15:53:41 +0000 (GMT) Received: by mail-wr0-f173.google.com with SMTP id k9so14736225wre.9 for ; Sun, 04 Mar 2018 07:53:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ido50-net.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id; bh=7SUphHsITpTlX/f3FjrAR3ddmGSQOV5Zm2ZVa3wrOVM=; b=XGwo7nV6Icnsfw0CQF/rF5+iQmPw0/QiMAwnYM1ble5gk252N/U5BV200ADU0/YddG 0i4Rv0cNViAZZKnm0mf6pA4c/++oSpN4msJtkGKnL4kwztqspwUQ21/3nqI2UvP0qNMU 11K3r4McuH3vooSZbs9SnBuPRtrOqyf7kESGSzIjPgpJV49Llw+HnGQ7AjO1iDqnzc3X 23PD+QAh/qNyLlv7bAICiqY6/Vy/j+icJ/bpl4Wq6XNRP8EalmcI0leXano0mL7WvoQx WLhRlNeNX+OPF9Fa7cYKjk1kj8RRPDtAuG60JZpHCRkWwV5yQ3ZKcobupYO11AUThlH2 +iDw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=7SUphHsITpTlX/f3FjrAR3ddmGSQOV5Zm2ZVa3wrOVM=; b=oTnmiRFG8okqQEjIp+YB71iTmOma2srBbrDKG6xfWB4GTRYrD7uvAx2cEl+Gr3wIid emjJNSl7hC9dQ1j+Btg6W9qiZIhl2p849lLj0h13UM0BYKxQXCqsClCkYKfYKtUkDTe5 sJlnFKhaUiFOj9w8LGeaI8BMDYQrBfyneQGjOwiKmbvHTZZbt9GTFbUYu4bKns+AlBCo JCrzTGr2c5pWZSl2jymu8Kewu6djUKUSOrFzUktRY4wJXXs23/Z0sW3LKh3f2K7A1hDg DlZ6I7JFNkUdLx/b4iBIlnndddjt2U0jzfN9HpisRIq8yBcbrTP8+SHO261FuR3+E3vo HjGg== X-Gm-Message-State: APf1xPAIxLg5G7VF/4W2jyRDJ2VRhdea6o22ZEBXus+vL1fpke8yNNVY Ospgab+hxme1ulPSYzAvJkK29EaVJxE= X-Google-Smtp-Source: AG47ELuJLQYs53y7k9Dgg8UclFh4vlsvWFi1jeVltcYs0NCzV/iloO85+V5HOucHgW8wjExtritU3g== X-Received: by 10.223.153.51 with SMTP id x48mr9666167wrb.216.1520178820625; Sun, 04 Mar 2018 07:53:40 -0800 (PST) Received: from localhost.localdomain (bzq-219-40-178.isdn.bezeqint.net. [62.219.40.178]) by smtp.gmail.com with ESMTPSA id c1sm6635451wre.27.2018.03.04.07.53.39 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 04 Mar 2018 07:53:39 -0800 (PST) From: Ido Perlmuter To: alpine-aports@lists.alpinelinux.org Cc: Ido Perlmuter Subject: [alpine-aports] [PATCH] Add missing vulnerabilities in 3.3 Date: Sun, 4 Mar 2018 17:53:35 +0200 Message-Id: <20180304155335.7384-1-ido@ido50.net> X-Mailer: git-send-email 2.16.2 X-Mailinglist: alpine-aports Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: The following vulnerabilities were fixed in the main 3.3 repository, but were missing from the relevant yaml file: - CVE-2016-2147 and CVE-2016-2148 were fixed in busybox 1.24.2-r0 (aports commit 1ac4d54468). - CVE-2016-0787 was fixed in libssh2 1.6.0-r1 (aports commit c922c86918). --- v3.3/main.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/v3.3/main.yaml b/v3.3/main.yaml index eff8448..ba75383 100644 --- a/v3.3/main.yaml +++ b/v3.3/main.yaml @@ -64,6 +64,9 @@ packages: - CVE-2017-16544 1.24.2-r1: - CVE-2016-6301 + 1.24.2-r0: + - CVE-2016-2147 + - CVE-2016-2148 - pkg: name: c-ares secfixes: @@ -903,3 +906,8 @@ packages: - CVE-2016-9841 - CVE-2016-9842 - CVE-2016-9843 + - pkg: + name: libssh2 + secfixes: + 1.6.0-r1: + - CVE-2016-0787 -- 2.16.2 --- Unsubscribe: alpine-aports+unsubscribe@lists.alpinelinux.org Help: alpine-aports+help@lists.alpinelinux.org ---