Merge ~mainek00n/ubuntu-cve-tracker:patch-1 into ubuntu-cve-tracker:master

Proposed by MaineK00n
Status: Merged
Merged at revision: 6af7e65807722faba358be272b98960528d6ea9c
Proposed branch: ~mainek00n/ubuntu-cve-tracker:patch-1
Merge into: ubuntu-cve-tracker:master
Diff against target: 116 lines (+8/-7)
10 files modified
active/CVE-2018-12294 (+1/-0)
active/CVE-2021-23214 (+0/-1)
active/CVE-2021-23222 (+0/-1)
active/CVE-2022-1552 (+0/-2)
retired/CVE-2007-4351 (+1/-1)
retired/CVE-2008-4098 (+1/-1)
retired/CVE-2010-1850 (+2/-0)
retired/CVE-2011-1837 (+1/-0)
retired/CVE-2012-0809 (+1/-0)
retired/CVE-2012-3410 (+1/-1)
Reviewer Review Type Date Requested Status
Steve Beattie Approve
Review via email: mp+427960@code.launchpad.net
To post a comment you must log in.
Revision history for this message
Steve Beattie (sbeattie) wrote :

LGTM, merged.

One note, for the sudo cve, that issue was discovered and resolved while precise was under development and had not been released yet. When we retire a cve, we don't turn the `devel` status into the release name under development, so that results in things like this.

review: Approve
Revision history for this message
MaineK00n (mainek00n) wrote :

Thank you for the review.

In the case of CVE-2012-0809, I questioned why Tags are defined for precise, but not package status, and suggested a change.

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
1diff --git a/active/CVE-2018-12294 b/active/CVE-2018-12294
2index 2516412..a00e423 100644
3--- a/active/CVE-2018-12294
4+++ b/active/CVE-2018-12294
5@@ -37,6 +37,7 @@ impish_webkitgtk: DNE
6 jammy_webkitgtk: DNE
7 devel_webkitgtk: DNE
8
9+Patches_webkit2gtk:
10 upstream_webkit2gtk: released (2.20.2)
11 precise/esm_webkit2gtk: DNE
12 trusty_webkit2gtk: DNE
13diff --git a/active/CVE-2021-23214 b/active/CVE-2021-23214
14index 3a2d888..159be07 100644
15--- a/active/CVE-2021-23214
16+++ b/active/CVE-2021-23214
17@@ -97,4 +97,3 @@ hirsute_postgresql-9.1: DNE
18 impish_postgresql-9.1: DNE
19 jammy_postgresql-9.1: DNE
20 devel_postgresql-9.1: DNE
21-upstream_postgresql: needs-triage
22diff --git a/active/CVE-2021-23222 b/active/CVE-2021-23222
23index 548670f..4e7954c 100644
24--- a/active/CVE-2021-23222
25+++ b/active/CVE-2021-23222
26@@ -96,4 +96,3 @@ hirsute_postgresql-9.1: DNE
27 impish_postgresql-9.1: DNE
28 jammy_postgresql-9.1: DNE
29 devel_postgresql-9.1: DNE
30-upstream_postgresql: needs-triage
31diff --git a/active/CVE-2022-1552 b/active/CVE-2022-1552
32index d9ac331..df10fe1 100644
33--- a/active/CVE-2022-1552
34+++ b/active/CVE-2022-1552
35@@ -97,5 +97,3 @@ focal_postgresql-9.1: DNE
36 impish_postgresql-9.1: DNE
37 jammy_postgresql-9.1: DNE
38 devel_postgresql-9.1: DNE
39-Patches_postrgesql:
40-upstream_postrgesql: needs-triage
41diff --git a/retired/CVE-2007-4351 b/retired/CVE-2007-4351
42index dffc1ba..c3b6482 100644
43--- a/retired/CVE-2007-4351
44+++ b/retired/CVE-2007-4351
45@@ -16,7 +16,7 @@ Discovered-by:
46 Assigned-to: kees
47 CVSS:
48 upstream_cupsys: released (1.3.4)
49-Tags_cups_gutsy: apparmor
50+Tags_cupsys_gutsy: apparmor
51 dapper_cupsys: released (1.2.2-0ubuntu0.6.06.4)
52 edgy_cupsys: released (1.2.4-2ubuntu3.1)
53 feisty_cupsys: released (1.2.8-0ubuntu8.1)
54diff --git a/retired/CVE-2008-4098 b/retired/CVE-2008-4098
55index 121f267..cb4bbe8 100644
56--- a/retired/CVE-2008-4098
57+++ b/retired/CVE-2008-4098
58@@ -36,4 +36,4 @@ devel_mysql-dfsg-5.0: not-affected (5.1.30really5.0.83-0ubuntu3)
59 Tags_mysql-dfsg-5.0_hardy: apparmor
60 Tags_mysql-dfsg-5.0_intrepid: apparmor
61 Tags_mysql-dfsg-5.0_jaunty: apparmor
62-Tags_mysql-dfsg-5.1_karmic: apparmor
63+Tags_mysql-dfsg-5.0_karmic: apparmor
64diff --git a/retired/CVE-2010-1850 b/retired/CVE-2010-1850
65index 633efb8..0a2974e 100644
66--- a/retired/CVE-2010-1850
67+++ b/retired/CVE-2010-1850
68@@ -26,6 +26,7 @@ Patches_mysql-dfsg-5.0:
69 upstream_mysql-dfsg-5.0: released (5.0.91)
70 dapper_mysql-dfsg-5.0: released (5.0.22-0ubuntu6.06.14)
71 hardy_mysql-dfsg-5.0: released (5.0.51a-3ubuntu5.7)
72+intrepid_mysql-dfsg-5.0: ignored (reached end-of-life)
73 jaunty_mysql-dfsg-5.0: released (5.1.30really5.0.75-0ubuntu10.5)
74 karmic_mysql-dfsg-5.0: ignored (reached end-of-life)
75 lucid_mysql-dfsg-5.0: DNE
76@@ -45,6 +46,7 @@ maverick_mysql-dfsg-5.1: DNE
77 natty_mysql-dfsg-5.1: DNE
78 devel_mysql-dfsg-5.1: DNE
79
80+Patches_mysql-5.1:
81 upstream_mysql-5.1: needs-triage
82 dapper_mysql-5.1: DNE
83 hardy_mysql-5.1: DNE
84diff --git a/retired/CVE-2011-1837 b/retired/CVE-2011-1837
85index 968d19c..4ee0368 100644
86--- a/retired/CVE-2011-1837
87+++ b/retired/CVE-2011-1837
88@@ -26,4 +26,5 @@ hardy_ecryptfs-utils: not-affected (code not present)
89 lucid_ecryptfs-utils: released (83-0ubuntu3.2.10.04.1)
90 maverick_ecryptfs-utils: released (83-0ubuntu3.2.10.10.1)
91 natty_ecryptfs-utils: released (87-0ubuntu1.1)
92+oneiric_ecryptfs-utils: released (89-0ubuntu2)
93 devel_ecryptfs-utils: released (89-0ubuntu2)
94diff --git a/retired/CVE-2012-0809 b/retired/CVE-2012-0809
95index 745c094..b06d466 100644
96--- a/retired/CVE-2012-0809
97+++ b/retired/CVE-2012-0809
98@@ -26,4 +26,5 @@ lucid_sudo: not-affected
99 maverick_sudo: not-affected
100 natty_sudo: not-affected
101 oneiric_sudo: not-affected (1.7.4p6-1ubuntu2)
102+precise_sudo: released (1.8.3p1-1ubuntu3)
103 devel_sudo: released (1.8.3p1-1ubuntu3)
104diff --git a/retired/CVE-2012-3410 b/retired/CVE-2012-3410
105index 866389b..8851e52 100644
106--- a/retired/CVE-2012-3410
107+++ b/retired/CVE-2012-3410
108@@ -21,7 +21,7 @@ Assigned-to:
109 CVSS:
110
111 Tags_bash: fortify-source
112-Tags_hardy_bash: stack-protector
113+Tags_bash_hardy: stack-protector
114 Patches_bash:
115 other: ftp://ftp.gnu.org/pub/gnu/bash/bash-4.2-patches/bash42-033
116 upstream_bash: released (4.2-4)

Subscribers

People subscribed via source and target branches