Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f1c83412 by Salvatore Bonaccorso at 2020-09-05T17:02:22+02:00
Track four CVEs for src:linux fixed via 5.8.7-1 upload
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -22865,11 +22865,11 @@ CVE-2020-14387 [rsync-ssl does not verify the
hostname in the server certificate
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1875549
CVE-2020-14386 [af_packet memory corruption]
RESERVED
- - linux <unfixed>
+ - linux 5.8.7-1
NOTE: https://www.openwall.com/lists/oss-security/2020/09/03/3
CVE-2020-14385 [xfs: fix boundary test in xfs_attr_shortform_verify]
RESERVED
- - linux <unfixed>
+ - linux 5.8.7-1
[stretch] - linux <not-affected> (Vulnerable code introduced later)
NOTE:
https://git.kernel.org/linus/f4020438fab05364018c91f7e02ebdd192085933
CVE-2020-14384
@@ -23142,7 +23142,7 @@ CVE-2020-14315
NOTE:
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:29.bspatch.asc
CVE-2020-14314 [buffer uses out of index in ext3/4 filesystem]
RESERVED
- - linux <unfixed>
+ - linux 5.8.7-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1853922
NOTE:
https://git.kernel.org/linus/5872331b3d91820e14716632ebb56b1399b34fe1
CVE-2020-14313 (An information disclosure vulnerability was found in Red Hat
Quay in v ...)
@@ -26743,7 +26743,7 @@ CVE-2020-12890
CVE-2020-12889 (MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection
across us ...)
NOT-FOR-US: MISP
CVE-2020-12888 (The VFIO PCI driver in the Linux kernel through 5.6.13
mishandles atte ...)
- - linux <unfixed>
+ - linux 5.8.7-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1836244
CVE-2020-12887 (Memory leaks were discovered in the CoAP library in Arm Mbed
OS 5.15.3 ...)
NOT-FOR-US: Mbed CoAP (diffrent from src:mbedtls)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1c8341234ec22229cb54b378118a0e22a62e2cf
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1c8341234ec22229cb54b378118a0e22a62e2cf
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits