[Git][security-tracker-team/security-tracker][master] Add CVE-2018-1113

Salvatore Bonaccorso carnil at debian.org
Wed Apr 25 07:25:05 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
edc9281f by Salvatore Bonaccorso at 2018-04-25T08:24:51+02:00
Add CVE-2018-1113

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -24989,6 +24989,8 @@ CVE-2018-1114
 	RESERVED
 CVE-2018-1113
 	RESERVED
+	NOT-FOR-US: Red Hat specific CVE assignment for Red Hat / Fedora setups (nologin listed in /etc/shells violates security expectations)
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1571094
 CVE-2018-1112 [glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)]
 	RESERVED
 	- glusterfs <not-affected> (Fix for CVE-2018-1088 was not applied/ incomplete fix not applied)	



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/edc9281f933be8d460d4e1e67e9d0f4c9293a7e7

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/edc9281f933be8d460d4e1e67e9d0f4c9293a7e7
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180425/4ba5f975/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list