Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (4)
mark CVE-2018-19760 as no-dsa for Jessie
· 2b23d4af
Thorsten Alteholz
authored
Dec 02, 2018
2b23d4af
add jasper
· 030c8d5b
Thorsten Alteholz
authored
Dec 02, 2018
030c8d5b
add freerdp
· c9e79efb
Thorsten Alteholz
authored
Dec 02, 2018
c9e79efb
add exiv2
· 95e5216e
Thorsten Alteholz
authored
Dec 02, 2018
95e5216e
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
95e5216e
...
...
@@ -60,6 +60,7 @@ CVE-2018-19761 (There is an illegal address access at fromsixel.c (function: ...
CVE-2018-19760 (cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. ...)
- confuse <unfixed> (low)
[stretch] - confuse <no-dsa> (Minor issue)
[jessie] - confuse <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1649152
CVE-2018-19759 (There is a heap-based buffer over-read at stb_image_write.h (function: ...)
TODO: check
data/dla-needed.txt
View file @
95e5216e
...
...
@@ -16,6 +16,14 @@ cairo
enigmail
NOTE: 20181113: depends on gnupg2 updates, see 87r2fqnja0.fsf@curie.anarc.at (anarcat)
--
exiv2 (Thorsten Alteholz)
NOTE: also recheck other CVEs
--
freerdp
NOTE: 20181202: Mike is uploader, so he should probably take this
--
jasper
--
libapache-mod-jk (Roberto C. Sánchez)
NOTE: 20181123: Packages ready, testing complete, waiting on security team feedback,
NOTE: 20181123: as this work includes an updated package for stretch. (roberto)
...
...