Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ad9f988d by Salvatore Bonaccorso at 2019-04-11T19:32:40Z
Add Debian bug reference for CVE-2019-11072/lighttpd
- - - - -
e9220d0d by Salvatore Bonaccorso at 2019-04-11T19:33:24Z
CVE-2019-11072: Prefix upstream commit with information
- - - - -
f220aa61 by Salvatore Bonaccorso at 2019-04-11T19:35:42Z
CVE-2019-11072: Update information on introducing issue
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -23,9 +23,12 @@ CVE-2019-11074
CVE-2019-11073
RESERVED
CVE-2019-11072 (lighttpd before 1.4.54 has a signed integer overflow, which
might allo ...)
- - lighttpd <unfixed>
+ - lighttpd <unfixed> (bug #926885)
+ [stretch] - lighttpd <not-affected> (Vulnerable code introduced later)
+ [jessie] - lighttpd <not-affected> (Vulnerable code introduced later)
NOTE: https://redmine.lighttpd.net/issues/2945
- NOTE:
https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354
+ NOTE: Fixed by:
https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354
+ NOTE: Introduced with:
https://github.com/lighttpd/lighttpd1.4/commit/3eb7902e10ba75b3f2eb159e244d0d8e5037ccd2
CVE-2019-11070 (WebKitGTK and WPE WebKit prior to version 2.24.1 failed to
properly ap ...)
- webkit2gtk 2.24.1-1
[stretch] - webkit2gtk <ignored> (Not covered by security support in
stretch)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/compare/ae58432467129a0ef8b8291dd85e0fac9f46c2f5...f220aa6100670feca90d8f389a778fc88a314631
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/compare/ae58432467129a0ef8b8291dd85e0fac9f46c2f5...f220aa6100670feca90d8f389a778fc88a314631
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits