Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a083fea2 by Salvatore Bonaccorso at 2019-09-10T05:59:34Z
Update information on CVE-2019-16167/sysstat
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -38,7 +38,11 @@ CVE-2019-16169
RESERVED
CVE-2019-16167 (sysstat before 12.1.6 has memory corruption due to an Integer
Overflow ...)
- sysstat <unfixed>
+ [buster] - sysstat <no-dsa> (Minor issue, can be fixed via point
release)
+ [stretch] - sysstat <not-affected> (Vulnerable code introduced later)
+ [jessie] - sysstat <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/sysstat/sysstat/issues/230
+ NOTE: Introduced after:
https://github.com/sysstat/sysstat/commit/65ac30359e49ee717397e39950d7c24a6610d57c
(v11.7.1)
NOTE: Fixed by:
https://github.com/sysstat/sysstat/commit/edbf507678bf10914e9804ff8a06737fdcb2e781
CVE-2019-16166 (GNU cflow through 1.6 has a heap-based buffer over-read in the
nexttok ...)
- cflow <unfixed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits