[Git][security-tracker-team/security-tracker][master] Remove src:sqlite3 associationg with CVE-2018-18344
Salvatore Bonaccorso
carnil at debian.org
Sat Dec 15 07:10:40 GMT 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
208c2020 by Salvatore Bonaccorso at 2018-12-15T07:06:12Z
Remove src:sqlite3 associationg with CVE-2018-18344
CVE-2018-18344 reads as Inappropriate implementation in Extensions.
Reported by Jann Horn of Google Project Zero on 2018-07-23 and there is
no more public information available for it.
OTOH, there is yet an CVE-usassigned further down in the list in
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
which need identification:
> [$TBD][900910] High To be allocated: Multiple issues in SQLite via
> WebSQL. Reported by Wenxiang Qian of Tencent Blade Team on 2018-11-01
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11135,7 +11135,6 @@ CVE-2018-18345 (Incorrect handling of blob URLS in Site Isolation in Google Chro
- chromium 71.0.3578.80-1
CVE-2018-18344 (Inappropriate allowance of the setDownloadBehavior devtools protocol ...)
{DSA-4352-1}
- - sqlite3 <undetermined>
- chromium 71.0.3578.80-1
CVE-2018-18343 (Incorrect handing of paths leading to a use after free in Skia in ...)
{DSA-4352-1}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/208c2020b7b01b4511c4ebef74e7d3ff2dfd8746
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/208c2020b7b01b4511c4ebef74e7d3ff2dfd8746
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181215/6f452e87/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list