Skip to content
Commits on Source (2)
......@@ -21647,6 +21647,7 @@ CVE-2019-5439 (A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash w
NOTE: http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security
CVE-2019-12779 (libqb before 1.0.5 allows local users to overwrite arbitrary files via ...)
- libqb 1.0.4-1 (unimportant; bug #927159)
[jessie] - libqb <end-of-life> (https://salsa.debian.org/debian/debian-security-support/commit/ba638006d397eda2cc094761ed7a7bfdca9e534b)
NOTE: https://github.com/ClusterLabs/libqb/issues/338
NOTE: https://github.com/ClusterLabs/libqb/commit/6a4067c1d1764d93d255eccecfd8bf9f43cb0b4d
NOTE: Regression fix: https://github.com/ClusterLabs/libqb/pull/349
......@@ -71,13 +71,6 @@ libmatio (Adrian Bunk)
NOTE: 20190428: older changes seem to also be required for them
NOTE: 20191111: work is ongoing
--
libqb (Roberto C. Sánchez)
NOTE: 20190616: Upstream patch does not apply at all, but it appears that
NOTE: 20190616: package is still vulnerable in ipc_posix_mq.c etc. or
NOTE: 20190616: wherever it uses c->pid w/NAME_MAX. (lamby)
NOTE: 20190619: See https://lists.debian.org/debian-lts/2019/06/msg00015.html
NOTE: 20191111: Made an attempt at backporting relevant commits; requested review by upstream. (roberto)
--
libvpx (Dylan Aïssi)
--
linux (Ben Hutchings)
......