[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
carnil at debian.org
Mon Dec 17 08:10:23 GMT 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
87eb9f2f by security tracker role at 2018-12-17T08:10:14Z
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,25 @@
+CVE-2018-20172
+ RESERVED
+CVE-2018-20171
+ RESERVED
+CVE-2018-20170 (** DISPUTED ** OpenStack Keystone through 14.0.1 has a user enumeration ...)
+ TODO: check
+CVE-2018-20169 (An issue was discovered in the Linux kernel before 4.19.9. The USB ...)
+ TODO: check
+CVE-2018-20168 (Google gVisor before 2018-08-22 reuses a pagetable in a different level ...)
+ TODO: check
+CVE-2018-20167 (Terminology before 1.3.1 allows Remote Code Execution because popmedia ...)
+ TODO: check
+CVE-2018-20166
+ RESERVED
+CVE-2017-18355 (Installed packages are exposed by node_modules in Rendertron 1.0.0, ...)
+ TODO: check
+CVE-2017-18354 (Rendertron 1.0.0 allows for alternative protocols such as 'file://' ...)
+ TODO: check
+CVE-2017-18353 (Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome ...)
+ TODO: check
+CVE-2017-18352 (Error reporting within Rendertron 1.0.0 allows reflected Cross Site ...)
+ TODO: check
CVE-2018-XXXX [custom control sequence remote code execution]
- terminology <unfixed> (bug #916630)
NOTE: https://phab.enlightenment.org/T7504
@@ -4145,7 +4167,7 @@ CVE-2018-19960 (The debug_mode function in web/web.py in OnionShare through 1.3.
NOTE: https://github.com/micahflee/onionshare/issues/837
NOTE: Negligable (and disputable) security impact, as the debug mode is not enabled by default
CVE-2018-19935 (ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote ...)
- {DSA-4353-1}
+ {DSA-4353-1 DLA-1608-1}
- php7.3 7.3.0-1
- php7.2 <removed>
- php7.0 <removed>
@@ -8124,7 +8146,7 @@ CVE-2018-19475 (psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote
NOTE: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=aeea342904978c9fe17d85f4906a0f6fcce2d315 (master)
NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=700153
CVE-2018-19518 (University of Washington IMAP Toolkit 2007f on UNIX, as used in ...)
- {DSA-4353-1}
+ {DSA-4353-1 DLA-1608-1}
- php7.3 7.3.0-1 (bug #913775)
- php7.2 <removed> (bug #913835)
- php7.0 <removed> (bug #913836)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/87eb9f2f6ccd5cbfcb1fce438b154780977cb4cf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/87eb9f2f6ccd5cbfcb1fce438b154780977cb4cf
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181217/46e4331b/attachment.html>
More information about the debian-security-tracker-commits
mailing list