Skip to content
Commits on Source (8)
......@@ -81,6 +81,7 @@ CVE-2018-8740 (In SQLite through 3.22.0, databases whose schema is corrupted usi
- sqlite3 3.22.0-2 (bug #893195)
[stretch] - sqlite3 <no-dsa> (Minor issue)
[jessie] - sqlite3 <no-dsa> (Minor issue)
[wheezy] - sqlite3 <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1756349
NOTE: https://www.sqlite.org/cgi/src/vdiff?from=1774f1c3baf0bc3d&to=d75e67654aa9620b
NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6964
......@@ -19829,6 +19830,7 @@ CVE-2018-1324 (A specially crafted ZIP archive can be used to cause an infinite
- libcommons-compress-java <unfixed> (bug #893174)
[stretch] - libcommons-compress-java <no-dsa> (Minor issue)
[jessie] - libcommons-compress-java <not-affected> (Vulnerable code introduced later)
[wheezy] - libcommons-compress-java <not-affected> (Vulnerable code introduced later)
NOTE: Fixed by: https://git-wip-us.apache.org/repos/asf?p=commons-compress.git;a=blobdiff;f=src/main/java/org/apache/commons/compress/archivers/zip/X0017_StrongEncryptionHeader.java;h=acc3b22346b49845e85b5ef27a5814b69e834139;hp=0feb9c98cc622cde1defa3bbd268ef82b4ae5c18;hb=2a2f1dc48e22a34ddb72321a4db211da91aa933b;hpb=dcb0486fb4cb2b6592c04d6ec2edbd3f690df5f2
NOTE: https://issues.apache.org/jira/browse/COMPRESS-432
CVE-2018-1323 (The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector ...)
......@@ -15,6 +15,9 @@ adminer (Chris Lamb)
NOTE: 20181603: No patch/upstream info for CVE-2018-7667 yet. (lamby)
NOTE: 20181803: Still patch/upstream info for CVE-2018-7667. (lamby)
--
cups
NOTE: 20180318: not clear whether patch is fine, so no email to maintainer sent
--
curl (Santiago R.R.)
--
dovecot (Thorsten Alteholz)
......@@ -67,6 +70,10 @@ libgcrypt11
--
libmad (Kurt Roeckx)
--
libpodofo
NOTE: maybe a dupe
NOTE: 20180318: no patch available yet, so no email to maintainer sent
--
libreoffice
--
libvorbis
......@@ -116,6 +123,12 @@ rubygems
--
samba (Holger Levsen)
--
sharutils
NOTE: 20180318: no patch available yet, so no email to maintainer sent
--
squirrelmail
NOTE: 20180318: no patch available yet, so no email to maintainer sent
--
tiff (Hugo Lefeuvre)
NOTE: incomplete fix of CVE-2017-18013, see CVE-2018-7456.
--
......@@ -123,6 +136,9 @@ tiff3
--
uwsgi (Abhijith PA)
--
web2py
NOTE: 20180318: no patch available yet, so no email to maintainer sent
--
wireshark (Thorsten Alteholz)
--
wordpress
......