Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 94c16d35 by Moritz Muehlenhoff at 2019-07-15T18:01:34Z buster/stretch triage - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -979,6 +979,7 @@ CVE-2019-13180 RESERVED CVE-2019-13179 (Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile ...) - calamares 3.2.11-1 (bug #931392) + [buster] - calamares <ignored> (Mitigated via calamares-settings-debian in Debian) - calamares-settings-debian 10.0.23-1 (bug #931373) [buster] - calamares-settings-debian <no-dsa> (Will be fixed via Buster point release) NOTE: https://github.com/calamares/calamares/issues/1191 @@ -7377,6 +7378,7 @@ CVE-2019-10732 (In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP e {DLA-1825-1} - kf5-messagelib <unfixed> (bug #926996) [buster] - kf5-messagelib <postponed> (Revisit when fixed upstream) + [stretch] - kf5-messagelib <postponed> (Revisit when fixed upstream) - kdepim <removed> [stretch] - kdepim <postponed> (Revisit when fixed upstream) NOTE: https://bugs.kde.org/show_bug.cgi?id=404698 @@ -57439,6 +57441,7 @@ CVE-2018-11564 (Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user NOT-FOR-US: Pagekit CMS CVE-2018-11563 (An issue was discovered in Open Ticket Request System (OTRS) 6.0.x thr ...) - otrs2 6.0.8-1 + [stretch] - otrs2 <no-dsa> (Non-free not supported) NOTE: https://community.otrs.com/security-advisory-2018-02-security-update-for-otrs-framework/ NOTE: https://github.com/OTRS/otrs/commit/50861a2a1183a07daf99cc2e71395e79f022338f CVE-2018-11562 (An issue was discovered in MISP 2.4.91. A vulnerability in app/View/El ...) @@ -86941,6 +86944,7 @@ CVE-2018-1258 (Spring Framework version 5.0.5 when used in combination with any NOTE: https://pivotal.io/security/cve-2018-1258 CVE-2018-1257 (Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior ...) - libspring-java 4.3.19-1 + [stretch] - libspring-java <no-dsa> (Minor issue) [jessie] - libspring-java <no-dsa> (hard to find upstream commits regarding this) NOTE: https://pivotal.io/security/cve-2018-1257 CVE-2018-1256 (Spring Cloud SSO Connector, version 2.1.2, contains a regression which ...) @@ -104596,7 +104600,14 @@ CVE-2017-12653 (360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege NOT-FOR-US: 360 Total Security CVE-2017-12652 (libpng before 1.6.32 does not properly check the length of chunks agai ...) - libpng1.6 1.6.32-1 - TODO: check, details on fix + [stretch] - libpng1.6 <ignored> (Minor issue) + NOTE: https://github.com/glennrp/libpng/commit/347538efbdc21b8df684ebd92d37400b3ce85d55 + NOTE: https://github.com/glennrp/libpng/commit/a1fe2c98489519d415b72bc0026f0c86d82278b7 + NOTE: https://github.com/glennrp/libpng/commit/095b4ce16bb46acb259ea1a4ca6562a623e58d93 + NOTE: https://github.com/glennrp/libpng/commit/2dbef2f2a9e759a80d2decb6862518acf4919c59 + NOTE: https://github.com/glennrp/libpng/commit/2dca15686fadb1b8951cb29b02bad4cae73448da + NOTE: https://github.com/glennrp/libpng/commit/fcd1bb93124d76059abef98216d8390f520c577b + NOTE: https://github.com/glennrp/libpng/commit/13bc0b6b1f8f2f2491fcc9f0c1c939ff06e13c15 CVE-2017-12651 (Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelis ...) NOT-FOR-US: Loginizer plugin for WordPress CVE-2017-12650 (SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPres ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/94c16d3521e9740673f74e1e954d50bbcd4bda57 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/94c16d3521e9740673f74e1e954d50bbcd4bda57 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits