Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 998f50dd by Salvatore Bonaccorso at 2019-10-27T21:50:00Z Mark lz4 as no-dsa for buster and stretch - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -3042,6 +3042,8 @@ CVE-2019-17544 (libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer NOTE: https://github.com/GNUAspell/aspell/commit/80fa26c74279fced8d778351cff19d1d8f44fe4e CVE-2019-17543 (LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (rela ...) - lz4 <unfixed> + [buster] - lz4 <no-dsa> (Minor issue) + [stretch] - lz4 <no-dsa> (Minor issue) [jessie] - lz4 <no-dsa> (Very hard to exploit, low risk) NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15941 NOTE: https://github.com/lz4/lz4/pull/756 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/998f50dd8ed22e51e04c7f51241e5ebf5ce2fa81 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/998f50dd8ed22e51e04c7f51241e5ebf5ce2fa81 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits