Skip to content
Commits on Source (3)
......@@ -878,6 +878,7 @@ CVE-2019-20433 (libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read f
- aspell 0.60.7-3 (bug #935128)
[buster] - aspell <no-dsa> (Minor issue)
[stretch] - aspell <no-dsa> (Minor issue)
[jessie] - aspell <ignored> (Minor issue)
NOTE: http://aspell.net/buffer-overread-ucs.txt
NOTE: Fixed by: https://github.com/GNUAspell/aspell/commit/de29341638833ba7717bd6b5e6850998454b044b
NOTE: Recommended additionally: https://github.com/GNUAspell/aspell/commit/cefd447e5528b08bb0cd6656bc52b4255692cefc
......@@ -6882,22 +6883,28 @@ CVE-2020-5215 (In TensorFlow before 1.15.2 and 2.0.1, converting a string (from
TODO: check
CVE-2020-5214 (In NetHack before 3.6.5, detecting an unknown configuration file optio ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-p8fw-rq89-xqx6
CVE-2020-5213 (In NetHack before 3.6.5, too long of a value for the SYMBOL configurat ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-rr25-4v34-pr7v
CVE-2020-5212 (In NetHack before 3.6.5, an extremely long value for the MENUCOLOR con ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-g89f-m829-4m56
CVE-2020-5211 (In NetHack before 3.6.5, an invalid extended command in value for the ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-r788-4jf4-r9f7
CVE-2020-5210 (In NetHack before 3.6.5, an invalid argument to the -w command line op ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-v5pg-hpjg-9rpp
NOTE: https://github.com/NetHack/NetHack/commit/f3def5c0b999478da2d0a8f0b6a7c370a2065f77
CVE-2020-5209 (In NetHack before 3.6.5, unknown options starting with -de and -i can ...)
- nethack <unfixed>
[jessie] - nethack <end-of-life>
NOTE: https://github.com/NetHack/NetHack/security/advisories/GHSA-fw72-r8xm-45p8
NOTE: https://github.com/NetHack/NetHack/commit/f3def5c0b999478da2d0a8f0b6a7c370a2065f77
CVE-2020-5208
......@@ -31,6 +31,8 @@ ibus
NOTE: 20191210: See https://bugs.debian.org/941018
NOTE: 20191210: See https://gitlab.gnome.org/GNOME/glib/merge_requests/1176
--
intel-microcode
--
jackson-databind
NOTE: 20200105: Can be postponed again. (apo)
--
......