[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add three CVEs in apport for further tracking

Salvatore Bonaccorso carnil at debian.org
Wed Feb 21 21:06:10 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dd173858 by Salvatore Bonaccorso at 2018-02-21T22:04:28+01:00
Add three CVEs in apport for further tracking

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -28036,15 +28036,21 @@ CVE-2017-14183
 CVE-2017-14182 (A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to ...)
 	NOT-FOR-US: Fortinet
 CVE-2017-14180 (Apport 2.13 through 2.20.7 does not properly handle crashes ...)
-	TODO: check
+	[experimental] - apport <unfixed>
+	NOTE: apport only in experimental, so we cannot track this in security-tracker
+	NOTE: add it, to have an explicit reference for apport if it ever enters unstable
 CVE-2017-14179 (Apport before 2.13 does not properly handle crashes originating from a ...)
-	TODO: check
+	[experimental] - apport <unfixed>
+	NOTE: apport only in experimental, so we cannot track this in security-tracker
+	NOTE: add it, to have an explicit reference for apport if it ever enters unstable
 CVE-2017-14178 (In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to ...)
 	- snapd 2.30-1
 	[stretch] - snapd <not-affected> (Issue introduced in 2.27)
 	NOTE: https://launchpad.net/bugs/1730255
 CVE-2017-14177 (Apport through 2.20.7 does not properly handle core dumps from setuid ...)
-	TODO: check
+	[experimental] - apport <unfixed>
+	NOTE: apport only in experimental, so we cannot track this in security-tracker
+	NOTE: add it, to have an explicit reference for apport if it ever enters unstable
 CVE-2017-14181 (DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 ...)
 	NOT-FOR-US: aacplusenc
 CVE-2017-14175 (In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/dd173858c080da3edbef6e75e166c99fb418e0de

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/dd173858c080da3edbef6e75e166c99fb418e0de
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180221/70030de8/attachment-0001.html>


More information about the Secure-testing-commits mailing list