Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (3)
mark CVE-2018-19532 as no-dsa for jessie
· dde4f9cd
Thorsten Alteholz
authored
Nov 29, 2018
dde4f9cd
nothing needs to be done with tcpdump
· 1db3eb70
Thorsten Alteholz
authored
Nov 29, 2018
1db3eb70
add sleuthkit
· e4250239
Thorsten Alteholz
authored
Nov 29, 2018
e4250239
Hide whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
e4250239
...
...
@@ -2995,6 +2995,7 @@ CVE-2018-19533
CVE-2018-19532 (A NULL pointer dereference vulnerability exists in the function ...)
- libpodofo <unfixed> (low)
[stretch] - libpodofo <no-dsa> (Minor issue)
[jessie] - libpodofo <no-dsa> (Minor issue)
NOTE: https://sourceforge.net/p/podofo/tickets/32/
CVE-2018-19531 (HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote ...)
NOT-FOR-US: HTTL
data/dla-needed.txt
View file @
e4250239
...
...
@@ -50,15 +50,15 @@ samba (Emilio Pozuelo)
salt (Mike Gabriel)
NOTE: 20181128: Have spent 0.75h on looking for the actual commits that fixed both open CVEs.
NOTE: 20181128: No such URLs / hints / messages in Git log found.
--
sleuthkit
NOTE: seem to be more problems than mentioned in the CVE if nodesize == rec_off or (rec_off + keylen) == nodesize
--
symfony (Roberto C. Sánchez)
--
systemd
NOTE: 20181119: tmpfiles.d issues remain, fix invasive, consider backporting all of tmpfiles.c (anarcat)
--
tcpdump (Thorsten Alteholz)
--
tiff (Hugo Lefeuvre)
NOTE: CVE-2018-19210: Working on a patch, see https://gitlab.com/libtiff/libtiff/merge_requests/47
NOTE: CVE-2018-18661: Easy to patch, but unable to reproduce the error.
...
...