Skip to content
Commits on Source (2)
......@@ -9,7 +9,9 @@ CVE-2018-12902 (In Easy Magazine through 2012-10-26, there is XSS in the search
CVE-2018-12901
RESERVED
CVE-2018-12900 (Heap-based buffer overflow in the cpSeparateBufToContigBuf function in ...)
TODO: check
- tiff <unfixed>
[stretch] - tiff <postponed> (Minor issue, can be fixed along in future DSA)
NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2798
CVE-2018-12899
RESERVED
CVE-2018-12898
......@@ -44,7 +46,8 @@ CVE-2018-12885
CVE-2018-12884 (In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user ...)
NOT-FOR-US: Octopus Deploy
CVE-2018-1000205 (U-Boot contains a CWE-20: Improper Input Validation vulnerability in ...)
TODO: check
- u-boot <unfixed> (unimportant)
NOTE: No security impact as supported/packaged in Debian
CVE-2018-XXXX [grep-excuses: uses YAML::Syck in a unsafe way]
- devscripts <unfixed> (low; bug #902409)
[stretch] - devscripts <no-dsa> (Minor issue)