Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ce33d4e8 by Moritz Muehlenhoff at 2018-05-14T18:27:51+02:00
new exiv issues (currently pending upstream investigation)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -1,5 +1,6 @@
 CVE-2018-11037 (In Exiv2 0.26, the Exiv2::PngImage::printStructure function in 
...)
-       TODO: check
+       - exiv2 <unfixed>
+       NOTE: https://github.com/Exiv2/exiv2/issues/307
 CVE-2018-11036
        RESERVED
 CVE-2018-11035 (In 2345 Security Guard 3.7, the driver file 
(2345NsProtect.sys, X64 ...)
@@ -75,9 +76,11 @@ CVE-2018-11001
 CVE-2018-11000
        RESERVED
 CVE-2018-10999 (An issue was discovered in Exiv2 0.26. The ...)
-       TODO: check
+       - exiv2 <unfixed>
+       NOTE: https://github.com/Exiv2/exiv2/issues/306
 CVE-2018-10998 (An issue was discovered in Exiv2 0.26. readMetadata in 
jp2image.cpp ...)
-       TODO: check
+       - exiv2 <unfixed>
+       NOTE: https://github.com/Exiv2/exiv2/issues/303
 CVE-2018-10997
        RESERVED
 CVE-2018-10996 (The weblogin_log function in /htdocs/cgibin on D-Link 
DIR-629-B1 ...)
@@ -174,7 +177,8 @@ CVE-2018-10960
 CVE-2018-10959
        RESERVED
 CVE-2018-10958 (In types.cpp in Exiv2 0.26, a large size value may lead to a 
SIGABRT ...)
-       TODO: check
+       - exiv2 <unfixed>
+       NOTE: https://github.com/Exiv2/exiv2/issues/302
 CVE-2018-10957 (CSRF exists on D-Link DIR-868L devices, leading to (for 
example) a ...)
        NOT-FOR-US: D-Link
 CVE-2018-10956



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/ce33d4e8c4295ad5e042511859e1e248b655d943

---
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/ce33d4e8c4295ad5e042511859e1e248b655d943
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to