Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 2c13e3f8 by Salvatore Bonaccorso at 2019-11-12T15:25:11Z Sync linux status with kernel sec for three CVEs CVE-2019-16994 was apparently incorrectly triaged. - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -7768,10 +7768,12 @@ CVE-2017-18636 (CDG through 2017-01-01 allows downloadDocument.jsp?command=downl CVE-2019-16995 (In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_final ...) - linux 4.19.37-1 [stretch] - linux 4.9.168-1 + [jessie] - linux <not-affected> (Vulnerability introduced later) NOTE: https://git.kernel.org/linus/6caabe7f197d3466d238f70915d65301f1716626 CVE-2019-16994 (In the Linux kernel before 5.0, a memory leak exists in sit_init_net() ...) - linux 4.19.28-1 - [stretch] - linux 4.9.168-1 + [stretch] - linux <not-affected> (Vulnerability introduced later) + [jessie] - linux <not-affected> (Vulnerability introduced later) NOTE: https://git.kernel.org/linus/07f12b26e21ab359261bf75cfcb424fdc7daeb6d CVE-2019-16992 (The Keybase app 2.13.2 for iOS provides potentially insufficient notic ...) NOT-FOR-US: Keybase @@ -8552,6 +8554,8 @@ CVE-2019-16729 (pam-python before 1.0.7-1 has an issue in regard to the default NOTE: https://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/ CVE-2019-16714 (In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv. ...) - linux 5.2.17-1 + [stretch] - linux <not-affected> (Vulnerable code not present) + [jessie] - linux <not-affected> (Vulnerable code not present) NOTE: https://git.kernel.org/linus/7d0a06586b2686ba80c4a2da5f91cb10ffbea736 CVE-2019-16705 (Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in th ...) - ming <removed> View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c13e3f8ce9b31c3f382db8606fef45383854fef -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c13e3f8ce9b31c3f382db8606fef45383854fef You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits