Skip to content
Commit 32a4a628 authored by Salvatore Bonaccorso's avatar Salvatore Bonaccorso
Browse files

Mark CVE-2019-384{3,4}/systemd as no-dsa

Attack vector requires control both of an exploitable service and a
helper outside. Futhermore DynamicUsers are not widely used. As per
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1814596/comments/7
in Debian itself those are yet limited, but still present.

The version in stretch (v232) is the version introducing support for
DynamicUsers, earlier versions as for jessie mght thus even not be
affected but would need to be checked.
parent a932167b
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment