Skip to content

Commits on Source 2

......@@ -347,6 +347,7 @@ CVE-2019-12905 (FileRun 2019.05.21 allows XSS via the filename to the ?module=fi
CVE-2019-12904 (In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flu ...)
- libgcrypt20 <unfixed> (bug #930885)
- libgcrypt11 <removed>
[jessie] - libgcrypt20 <not-affected> (Vulnerable code introduced later in version 1.7.0)
NOTE: https://dev.gnupg.org/T4541
NOTE: https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020
NOTE: https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762
......@@ -57,8 +57,6 @@ libav
NOTE: 20190529: has been found, so far. If you pick libav, be prepared to work
NOTE: 20190529: out patches yourself.
--
libgcrypt20 (Thorsten Alteholz)
--
libmatio (Adrian Bunk)
NOTE: fairly high number of open issues. Not sure why we never had a look at them.
NOTE: triage work needed, help security team for fixes if needed.
......