[Git][security-tracker-team/security-tracker][master] mp4v2, libsixel bugs

Moritz Muehlenhoff jmm at debian.org
Sun Jul 15 22:49:49 BST 2018


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4c11a2b by Moritz Muehlenhoff at 2018-07-15T23:49:24+02:00
mp4v2, libsixel bugs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -11,10 +11,10 @@ CVE-2018-14075
 CVE-2018-14074
 	RESERVED
 CVE-2018-14073 (libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c. ...)
-	- libsixel <unfixed> (low)
+	- libsixel <unfixed> (low; bug #903858)
 	[stretch] - libsixel <no-dsa> (Minor issue)
 CVE-2018-14072 (libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, ...)
-	- libsixel <unfixed> (low)
+	- libsixel <unfixed> (low; bug #903858)
 	[stretch] - libsixel <no-dsa> (Minor issue)
 CVE-2018-14071
 	RESERVED
@@ -129,7 +129,7 @@ CVE-2018-1000207 (MODX Revolution version <=2.6.4 contains a Incorrect Access
 CVE-2018-1000206 (JFrog Artifactory version since 5.11 contains a Cross ite Request ...)
 	NOT-FOR-US: JFrog Artifactory
 CVE-2018-14054 (A double free exists in the MP4StringProperty class in mp4property.cpp ...)
-	- mp4v2 <unfixed>
+	- mp4v2 <unfixed> (bug #903859)
 	[stretch] - mp4v2 <no-dsa> (Minor issue)
 	NOTE: http://www.openwall.com/lists/oss-security/2018/07/13/1
 CVE-2018-14036 (Directory Traversal with ../ sequences occurs in AccountsService before ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e4c11a2bc732aeaba44f60dedf7f6e4bbdf1a9ca

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e4c11a2bc732aeaba44f60dedf7f6e4bbdf1a9ca
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180715/b62a5ad6/attachment.html>


More information about the debian-security-tracker-commits mailing list