Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (3)
add libjpeg-turbo
· fc84d3d9
Thorsten Alteholz
authored
Jan 21, 2019
fc84d3d9
mark CVE-2019-6285 as no-dsa for jessie
· eb80e652
Thorsten Alteholz
authored
Jan 21, 2019
eb80e652
mark CVE-2019-6292 as no-dsa for jessie
· 18cbe035
Thorsten Alteholz
authored
Jan 21, 2019
18cbe035
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
18cbe035
...
...
@@ -535,8 +535,10 @@ CVE-2019-6293 (An issue was discovered in the function mark_beginning_as_normal
CVE-2019-6292 (An issue was discovered in singledocparser.cpp in yaml-cpp (aka ...)
- yaml-cpp <unfixed> (bug #919430)
[stretch] - yaml-cpp <no-dsa> (Minor issue)
[jessie] - yaml-cpp <no-dsa> (Minor issue)
- yaml-cpp0.3 <removed>
[stretch] - yaml-cpp0.3 <no-dsa> (Minor issue)
[jessie] - yaml-cpp0.3 <no-dsa> (Minor issue)
NOTE: https://github.com/jbeder/yaml-cpp/issues/657
CVE-2019-6291 (An issue was discovered in the function expr6 in eval.c in Netwide ...)
- nasm <unfixed> (unimportant)
...
...
@@ -559,8 +561,10 @@ CVE-2019-6286 (In LibSass 3.5.5, a heap-based buffer over-read exists in ...)
CVE-2019-6285 (The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka ...)
- yaml-cpp <unfixed> (bug #919432)
[stretch] - yaml-cpp <no-dsa> (Minor issue)
[jessie] - yaml-cpp <no-dsa> (Minor issue)
- yaml-cpp0.3 <removed>
[stretch] - yaml-cpp0.3 <no-dsa> (Minor issue)
[jessie] - yaml-cpp0.3 <no-dsa> (Minor issue)
NOTE: https://github.com/jbeder/yaml-cpp/issues/660
CVE-2019-6284 (In LibSass 3.5.5, a heap-based buffer over-read exists in ...)
- libsass <unfixed> (low)
data/dla-needed.txt
View file @
18cbe035
...
...
@@ -71,6 +71,9 @@ libav (Mike Gabriel)
libpng
NOTE: 20190121: Are we sure? Quoting upstream on CVE-2019-6129: "I think this is not a security issue at all". (lamby)
--
libjpeg-turbo
NOTE: 20190121: as Mike is an Uploader:, probably he wants to do this ...
--
libraw (Abhijith PA)
NOTE: 20181222: As usual please consider to fix ignored/no-dsa issues too,
NOTE: especially those that are still marked vulnerable in Stretch but also
...
...