Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (3)
Add Debian bug reference for CVE-2019-11072/lighttpd
· ad9f988d
Salvatore Bonaccorso
authored
Apr 11, 2019
ad9f988d
CVE-2019-11072: Prefix upstream commit with information
· e9220d0d
Salvatore Bonaccorso
authored
Apr 11, 2019
e9220d0d
CVE-2019-11072: Update information on introducing issue
· f220aa61
Salvatore Bonaccorso
authored
Apr 11, 2019
f220aa61
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
f220aa61
...
...
@@ -23,9 +23,12 @@ CVE-2019-11074
CVE-2019-11073
RESERVED
CVE-2019-11072 (lighttpd before 1.4.54 has a signed integer overflow, which might allo ...)
- lighttpd <unfixed>
- lighttpd <unfixed> (bug #926885)
[stretch] - lighttpd <not-affected> (Vulnerable code introduced later)
[jessie] - lighttpd <not-affected> (Vulnerable code introduced later)
NOTE: https://redmine.lighttpd.net/issues/2945
NOTE: https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354
NOTE: Fixed by: https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354
NOTE: Introduced with: https://github.com/lighttpd/lighttpd1.4/commit/3eb7902e10ba75b3f2eb159e244d0d8e5037ccd2
CVE-2019-11070 (WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly ap ...)
- webkit2gtk 2.24.1-1
[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)