Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2c13e3f8 by Salvatore Bonaccorso at 2019-11-12T15:25:11Z
Sync linux status with kernel sec for three CVEs
CVE-2019-16994 was apparently incorrectly triaged.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7768,10 +7768,12 @@ CVE-2017-18636 (CDG through 2017-01-01 allows
downloadDocument.jsp?command=downl
CVE-2019-16995 (In the Linux kernel before 5.0.3, a memory leak exits in
hsr_dev_final ...)
- linux 4.19.37-1
[stretch] - linux 4.9.168-1
+ [jessie] - linux <not-affected> (Vulnerability introduced later)
NOTE:
https://git.kernel.org/linus/6caabe7f197d3466d238f70915d65301f1716626
CVE-2019-16994 (In the Linux kernel before 5.0, a memory leak exists in
sit_init_net() ...)
- linux 4.19.28-1
- [stretch] - linux 4.9.168-1
+ [stretch] - linux <not-affected> (Vulnerability introduced later)
+ [jessie] - linux <not-affected> (Vulnerability introduced later)
NOTE:
https://git.kernel.org/linus/07f12b26e21ab359261bf75cfcb424fdc7daeb6d
CVE-2019-16992 (The Keybase app 2.13.2 for iOS provides potentially
insufficient notic ...)
NOT-FOR-US: Keybase
@@ -8552,6 +8554,8 @@ CVE-2019-16729 (pam-python before 1.0.7-1 has an issue in
regard to the default
NOTE:
https://sourceforge.net/p/pam-python/code/ci/0247ab687b4347cc52859ca461fb0126dd7e2ebe/
CVE-2019-16714 (In the Linux kernel before 5.2.14, rds6_inc_info_copy in
net/rds/recv. ...)
- linux 5.2.17-1
+ [stretch] - linux <not-affected> (Vulnerable code not present)
+ [jessie] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/7d0a06586b2686ba80c4a2da5f91cb10ffbea736
CVE-2019-16705 (Ming (aka libming) 0.4.8 has an out of bounds read
vulnerability in th ...)
- ming <removed>
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c13e3f8ce9b31c3f382db8606fef45383854fef
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c13e3f8ce9b31c3f382db8606fef45383854fef
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits