Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 444a55f2 by Moritz Muehlenhoff at 2020-07-03T16:04:13+02:00 libyang fixed in experimental hylafax bug - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -242,12 +242,12 @@ CVE-2020-15399 CVE-2020-15398 RESERVED CVE-2020-15397 (HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execut ...) - - hylafax <unfixed> + - hylafax <unfixed> (bug #964198) [buster] - hylafax <no-dsa> (Minor issue) [stretch] - hylafax <no-dsa> (Minor issue) NOTE: https://sourceforge.net/p/hylafax/HylaFAX+/2534/ CVE-2020-15396 (In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility ...) - - hylafax <unfixed> + - hylafax <unfixed> (bug #964198) [buster] - hylafax <no-dsa> (Minor issue) [stretch] - hylafax <no-dsa> (Minor issue) NOTE: https://sourceforge.net/p/hylafax/HylaFAX+/2534/ @@ -20119,47 +20119,55 @@ CVE-2020-7904 (In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories CVE-2019-20399 (A timing vulnerability in the Scalar::check_overflow function in Parit ...) NOT-FOR-US: libsecp256k1-rs (Rust Implementation of secp256k1) CVE-2019-20398 (A NULL pointer dereference is present in libyang before v1.0-r3 in the ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793935 NOTE: https://github.com/CESNET/libyang/commit/7852b272ef77f8098c35deea6c6f09cb78176f08 NOTE: https://github.com/CESNET/libyang/issues/773 CVE-2019-20397 (A double-free is present in libyang before v1.0-r1 in the function yyp ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793928 NOTE: https://github.com/CESNET/libyang/commit/88bd6c548ba79bce176cd875e9b56e7e0ef4d8d4 NOTE: https://github.com/CESNET/libyang/issues/739 CVE-2019-20396 (A segmentation fault is present in yyparse in libyang before v1.0-r1 d ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://github.com/CESNET/libyang/commit/a1f17693904ed6fecc8902c747fc50a8f20e6af8 NOTE: https://github.com/CESNET/libyang/issues/740 CVE-2019-20395 (A stack consumption issue is present in libyang before v1.0-r1 due to ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793924 NOTE: https://github.com/CESNET/libyang/commit/4e610ccd87a2ba9413819777d508f71163fcc237 NOTE: https://github.com/CESNET/libyang/issues/724 CVE-2019-20394 (A double-free is present in libyang before v1.0-r3 in the function yyp ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793932 NOTE: https://github.com/CESNET/libyang/commit/6cc51b1757dfbb7cff92de074ada65e8523289a6 NOTE: https://github.com/CESNET/libyang/issues/769 CVE-2019-20393 (A double-free is present in libyang before v1.0-r1 in the function yyp ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793930 NOTE: https://github.com/CESNET/libyang/commit/d9feacc4a590d35dbc1af21caf9080008b4450ed NOTE: https://github.com/CESNET/libyang/issues/742 CVE-2019-20392 (An invalid memory access flaw is present in libyang before v1.0-r1 in ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793922 NOTE: https://github.com/CESNET/libyang/commit/32fb4993bc8bb49e93e84016af3c10ea53964be5 NOTE: https://github.com/CESNET/libyang/issues/723 CVE-2019-20391 (An invalid memory access flaw is present in libyang before v1.0-r3 in ...) + [experimental] - libyang 1.0.167-1 - libyang <unfixed> [buster] - libyang <no-dsa> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1793934 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/444a55f230bfaf3ae1e424c1e929cf7026cd6d3a -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/444a55f230bfaf3ae1e424c1e929cf7026cd6d3a You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits