Skip to content
Commits on Source (3)
......@@ -121,6 +121,7 @@ CVE-2019-8344
CVE-2019-8343 (In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in ...)
- nasm <unfixed> (bug #922433)
[stretch] - nasm <no-dsa> (Minor issue)
[jessie] - nasm <no-dsa> (Minor issue)
NOTE: https://bugzilla.nasm.us/show_bug.cgi?id=3392556
CVE-2019-8342
RESERVED
......@@ -10285,6 +10286,7 @@ CVE-2019-3832 [incomplete fix for CVE-2018-19758]
RESERVED
- libsndfile <unfixed> (bug #922372)
[stretch] - libsndfile <not-affected> (Incomplete fix for CVE-2018-19758 not applied)
[jessie] - libsndfile <not-affected> (Incomplete fix for CVE-2018-19758 not applied)
NOTE: https://github.com/erikd/libsndfile/issues/456#issuecomment-463542436
CVE-2019-3831
RESERVED
......@@ -54,6 +54,8 @@ jackson-databind
NOTE: 20190210: this blacklist (class SubTypeValidator) is not available in Jessie
NOTE: 20190210: should that be backported or the CVEs marked as no-dsa?
--
kde4libs
--
libav (Mike Gabriel)
NOTE: 20190131: Re-added after ~deb8u5 upload. Still not done, yet.
--
......