Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (3)
follow security team with no-dsa for CVE-2019-14247 in Jessie
· 6dce3021
Thorsten Alteholz
authored
Jul 30, 2019
6dce3021
no security support for node modules
· 34fbfcc8
Thorsten Alteholz
authored
Jul 30, 2019
34fbfcc8
add libreoffice
· 6ab05da9
Thorsten Alteholz
authored
Jul 30, 2019
6ab05da9
Hide whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
6ab05da9
...
...
@@ -515,6 +515,7 @@ CVE-2019-14248 (In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c a
CVE-2019-14247 (The scan() function in mad.c in mpg321 0.3.2 allows remote attackers t ...)
- mpg321 0.3.2-2
[stretch] - mpg321 <no-dsa> (Minor issue)
[jessie] - mpg321 <no-dsa> (Minor issue)
NOTE: https://sourceforge.net/p/mpg321/bugs/51/
NOTE: Fixed by handle_illegal_bitrate_value.patch
CVE-2019-14246
...
...
@@ -10256,6 +10257,7 @@ CVE-2019-10744 (Versions of lodash lower than 4.17.12 are vulnerable to Prototyp
- node-lodash <unfixed> (bug #933079)
[buster] - node-lodash <no-dsa> (Minor issue; can be fixed in point release)
[stretch] - node-lodash <ignored> (Nodejs in stretch not covered by security support)
[jessie] - node-lodash <ignored> (Nodejs in stretch not covered by security support)
NOTE: https://snyk.io/vuln/SNYK-JS-LODASH-450202
NOTE: https://github.com/lodash/lodash/issues/4348
NOTE: https://github.com/lodash/lodash/pull/4336
data/dla-needed.txt
View file @
6ab05da9
...
...
@@ -65,6 +65,9 @@ libqb
NOTE: 20190616: wherever it uses c->pid w/NAME_MAX. (lamby)
NOTE: 20190619: See https://lists.debian.org/debian-lts/2019/06/msg00015.html
--
libreoffice
NOTE: probably Jessie is affected as well
--
libsdl1.2 (Hugo Lefeuvre)
NOTE: see libsdl2 entry.
--
...
...