Author: sectracker Date: 2017-12-02 09:10:16 +0000 (Sat, 02 Dec 2017) New Revision: 58209
Modified: data/CVE/list Log: automatic update Modified: data/CVE/list =================================================================== --- data/CVE/list 2017-12-02 08:42:31 UTC (rev 58208) +++ data/CVE/list 2017-12-02 09:10:16 UTC (rev 58209) @@ -1,3 +1,5 @@ +CVE-2017-17090 (An issue was discovered in chan_skinny.c in Asterisk Open Source ...) + TODO: check CVE-2018-1040 RESERVED CVE-2018-1039 @@ -600,23 +602,23 @@ RESERVED CVE-2017-17089 RESERVED -CVE-2017-17091 [Use a properly generated hash for the 'newbloguser' key instead of a determinate substring] +CVE-2017-17091 (wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser ...) - wordpress <unfixed> NOTE: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c NOTE: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ -CVE-2017-17093 [Add escaping to the language attributes used on 'html' elements] +CVE-2017-17093 (wp-includes/general-template.php in WordPress before 4.9.1 does not ...) - wordpress <unfixed> NOTE: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a NOTE: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ -CVE-2017-17094 [Ensure the attributes of enclosures are correctly escaped in RSS and Atom feeds] +CVE-2017-17094 (wp-includes/feed.php in WordPress before 4.9.1 does not properly ...) - wordpress <unfixed> NOTE: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de NOTE: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ -CVE-2017-17092 [Remove the ability to upload JavaScript files for users who do not have the 'unfiltered_html' capability] +CVE-2017-17092 (wp-includes/functions.php in WordPress before 4.9.1 does not require ...) - wordpress <unfixed> NOTE: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509 NOTE: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ -CVE-2017-17095 [heap-based buffer overflow in the pal2rgb tool] +CVE-2017-17095 (tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to ...) - tiff <unfixed> (unimportant) - tiff3 <removed> (unimportant) NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2750 _______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits