Skip to content
Commits on Source (2)
......@@ -1055,6 +1055,8 @@ CVE-2018-6760
RESERVED
CVE-2018-6767 (A stack-based buffer over-read in the ParseRiffHeaderConfig function of ...)
- wavpack <unfixed> (bug #889276)
[jessie] - wavpack <not-affected> (Vulnerable code introduced later in 4.80.0)
[wheezy] - wavpack <not-affected> (Vulnerable code introduced later in 4.80.0)
NOTE: https://github.com/dbry/WavPack/issues/27
NOTE: https://github.com/dbry/WavPack/commit/d5bf76b5a88d044a1be1d5656698e3ba737167e5
CVE-2018-6764 [guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init]
......@@ -84,7 +84,5 @@ suricata (Santiago R.R.)
NOTE: StreamTcpInlineDropInvalid function does not exist at all. Perhaps contact
NOTE: upstream and ask for a clarification?
--
wavpack (Thorsten Alteholz)
--
wordpress
NOTE: 20180217: Upstream unsure how to fix at the moment (lamby)