Hugo Lefeuvre pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1c63290a by Hugo Lefeuvre at 2019-01-22T15:53:14Z
openjpeg2: triage CVE-2018-5727 as unimportant

This is only a ubsan integer overflow check failure, doesn't have any
security impact per se. It doesn't look like there would be any subsequent
security relevant issues (asan and valgrind silent + see investigations
report on upstream bug).

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54050,9 +54050,10 @@ CVE-2018-5729 (MIT krb5 1.6 or later allows an 
authenticated kadmin with permiss
 CVE-2018-5728 (Cobham Sea Tel 121 build 222701 devices allow remote attackers 
to ...)
        NOT-FOR-US: Cobham Sea Tel 121 build 222701 devices
 CVE-2018-5727 (In OpenJPEG 2.3.0, there is an integer overflow vulnerability 
in the ...)
-       - openjpeg2 <unfixed> (low; bug #888532)
-       [jessie] - openjpeg2 <ignored> (Minor issue, security impact not clear)
+       - openjpeg2 <unfixed> (unimportant; bug #888532)
        NOTE: https://github.com/uclouvain/openjpeg/issues/1053
+       NOTE: ubsan error (integer overflow), no security impact per se and 
unlikely
+       NOTE: to trigger any security relevant issue
 CVE-2018-5726 (MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to 
obtain ...)
        NOT-FOR-US: MASTER IPCAMERA01 3.3.4.2103 devices
 CVE-2018-5725 (MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c63290a30f2ee667c4723738e4972bc7c1aab50

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c63290a30f2ee667c4723738e4972bc7c1aab50
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to