Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (5)
readd graphicsmagick
· 9e376c9c
Thorsten Alteholz
authored
Jun 28, 2018
9e376c9c
add intel-microcode
· f055cbea
Thorsten Alteholz
authored
Jun 28, 2018
f055cbea
follow security team for libraw
· 96565d92
Thorsten Alteholz
authored
Jun 28, 2018
96565d92
add tiff
· 0562701a
Thorsten Alteholz
authored
Jun 28, 2018
0562701a
follow security team for yara
· d0e10800
Thorsten Alteholz
authored
Jun 28, 2018
d0e10800
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
d0e10800
...
...
@@ -2339,10 +2339,12 @@ CVE-2018-12036 (OWASP Dependency-Check before 3.2.0 allows attackers to write to
CVE-2018-12035 (In YARA 3.7.1 and prior, parsing a specially crafted compiled rule ...)
- yara 3.7.1-3 (low)
[stretch] - yara <no-dsa> (Minor issue)
[jessie] - yara <no-dsa> (Minor issue)
NOTE: https://github.com/VirusTotal/yara/issues/891
CVE-2018-12034 (In YARA 3.7.1 and prior, parsing a specially crafted compiled rule ...)
- yara 3.7.1-3 (low)
[stretch] - yara <no-dsa> (Minor issue)
[jessie] - yara <no-dsa> (Minor issue)
NOTE: https://github.com/VirusTotal/yara/issues/891
CVE-2018-12033
RESERVED
...
...
@@ -19365,16 +19367,19 @@ CVE-2018-5806 [NULL pointer dereference in leaf_hdr_load_raw() function in inter
RESERVED
- libraw 0.18.8-1 (low)
[stretch] - libraw <no-dsa> (Minor issue)
[jessie] - libraw <no-dsa> (Minor issue)
NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
CVE-2018-5805 [Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp]
RESERVED
- libraw 0.18.8-1 (low)
[stretch] - libraw <no-dsa> (Minor issue)
[jessie] - libraw <no-dsa> (Minor issue)
NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
CVE-2018-5804 [type confusion error in identify() function in internal/dcraw_common.cpp]
RESERVED
- libraw 0.18.8-1 (low)
[stretch] - libraw <no-dsa> (Minor issue)
[jessie] - libraw <no-dsa> (Minor issue)
NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
CVE-2018-5803 (In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, ...)
{DSA-4188-1 DSA-4187-1 DLA-1369-1}
data/dla-needed.txt
View file @
d0e10800
...
...
@@ -39,6 +39,10 @@ firefox-esr (Emilio Pozuelo)
--
git
--
graphicsmagick
--
intel-microcode
--
ipsec-tools
NOTE: CVE-2016-10396 fixed in wheezy. No further point release so this should be fixed this way instead.
--
...
...
@@ -101,6 +105,8 @@ slurm-llnl (Thorsten Alteholz)
--
thunderbird (Emilio Pozuelo)
--
tiff
--
tiff3 (Holger Levsen)
--
tomcat8 (Roberto C. Sánchez)
...
...