Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
Add jackson-databind to dla-needed.txt with notes.
· f7cc1aa0
Markus Koschany
authored
Jan 05, 2020
f7cc1aa0
CVE-2019-5063,CVE-2019-5064,opencv: Jessie is not affected
· 7a5a1a56
Markus Koschany
authored
Jan 05, 2020
The vulnerable code was introduced later.
7a5a1a56
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
7a5a1a56
...
...
@@ -54538,11 +54538,13 @@ CVE-2019-5065 (An exploitable information disclosure vulnerability exists in the
CVE-2019-5064 (An exploitable heap buffer overflow vulnerability exists in the data s ...)
[experimental] - opencv 4.2.0+dfsg-1
- opencv <unfixed>
[jessie] - opencv <not-affected> (The vulnerable code was introduced later)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2019-0853
NOTE: Fixed by: https://github.com/opencv/opencv/commit/f42d5399aac80d371b17d689851406669c9b9111 (4.2.0)
CVE-2019-5063 (An exploitable heap buffer overflow vulnerability exists in the data s ...)
[experimental] - opencv 4.2.0+dfsg-1
- opencv <unfixed>
[jessie] - opencv <not-affected> (The vulnerable code was introduced later)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2019-0852
NOTE: Fixed by: https://github.com/opencv/opencv/commit/f42d5399aac80d371b17d689851406669c9b9111 (4.2.0)
CVE-2019-5062 (An exploitable denial-of-service vulnerability exists in the 802.11w s ...)
data/dla-needed.txt
View file @
7a5a1a56
...
...
@@ -35,6 +35,9 @@ ibus (Emilio)
NOTE: 20191210: See https://bugs.debian.org/941018
NOTE: 20191210: See https://gitlab.gnome.org/GNOME/glib/merge_requests/1176
--
jackson-databind
NOTE: 20200105: Can be postponed again. (apo)
--
libexif (Hugo Lefeuvre)
NOTE: 20191111: Contacted upstream for relevant commits of CVE-2019-9278. (utkarsh2102)
NOTE: 20191114: Pinged upstream; just have the Android patch yet. (utkarsh2102)
...
...