Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
CVE-2018-6767 doe not affect wheezy and jessie
· 675068a2
Thorsten Alteholz
authored
Feb 17, 2018
675068a2
wavpack done
· dacf736a
Thorsten Alteholz
authored
Feb 17, 2018
dacf736a
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
dacf736a
...
...
@@ -1055,6 +1055,8 @@ CVE-2018-6760
RESERVED
CVE-2018-6767 (A stack-based buffer over-read in the ParseRiffHeaderConfig function of ...)
- wavpack <unfixed> (bug #889276)
[jessie] - wavpack <not-affected> (Vulnerable code introduced later in 4.80.0)
[wheezy] - wavpack <not-affected> (Vulnerable code introduced later in 4.80.0)
NOTE: https://github.com/dbry/WavPack/issues/27
NOTE: https://github.com/dbry/WavPack/commit/d5bf76b5a88d044a1be1d5656698e3ba737167e5
CVE-2018-6764 [guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init]
data/dla-needed.txt
View file @
dacf736a
...
...
@@ -84,7 +84,5 @@ suricata (Santiago R.R.)
NOTE: StreamTcpInlineDropInvalid function does not exist at all. Perhaps contact
NOTE: upstream and ask for a clarification?
--
wavpack (Thorsten Alteholz)
--
wordpress
NOTE: 20180217: Upstream unsure how to fix at the moment (lamby)