Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (4)
mark CVE-2019-14751 as no-dsa for Jessie
· d88c7168
Thorsten Alteholz
authored
Aug 23, 2019
d88c7168
add common-beanutils
· bbd80e0e
Thorsten Alteholz
authored
Aug 23, 2019
bbd80e0e
add icedtea-web
· 55851d1e
Thorsten Alteholz
authored
Aug 23, 2019
55851d1e
add libcrypto++
· 0c9c524d
Thorsten Alteholz
authored
Aug 23, 2019
0c9c524d
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
0c9c524d
...
...
@@ -2233,6 +2233,7 @@ CVE-2019-14752
RESERVED
CVE-2019-14751 (NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, a ...)
- nltk <unfixed> (bug #935201)
[jessie] - nltk <no-dsa> (Minor issue; user has to configure a compromised server)
NOTE: https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/
NOTE: https://github.com/nltk/nltk/commit/f59d7ed8df2e0e957f7f247fe218032abdbe9a10
CVE-2019-14750 (An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1. ...)
data/dla-needed.txt
View file @
0c9c524d
...
...
@@ -24,6 +24,8 @@ clamav (Hugo Lefeuvre)
NOTE: 20190822: upstream has released 0.101.4, wait for stretch update (see bug
NOTE: report) (hle)
--
commons-beanutils
--
dnsmasq (Mike Gabriel)
--
djvulibre (Thorsten Alteholz)
...
...
@@ -47,6 +49,8 @@ hdf5 (Hugo Lefeuvre)
NOTE: wait for the next HDF5 point release and either do full package upgrade
NOTE: or cherry pick fixes (hle)
--
icedtea-web
--
libav
NOTE: 20190529: There are currently 19 CVE issues known for libav in jessie,
NOTE: 20190529: 11 tagged as <no-dsa>. These issues have been triaged, no patch
...
...
@@ -54,6 +58,8 @@ libav
NOTE: 20190529: out patches yourself.
NOTE: 20190731: New CVEs occurred, need to be triaged.
--
libcrypto++
--
libmatio (Adrian Bunk)
NOTE: fairly high number of open issues. Not sure why we never had a look at them.
NOTE: triage work needed, help security team for fixes if needed.
...
...