[Git][security-tracker-team/security-tracker][master] Add CVE-2018-500{4,5,6}/libraw

Salvatore Bonaccorso carnil at debian.org
Sat Jun 16 08:06:24 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9b4411bd by Salvatore Bonaccorso at 2018-06-16T09:05:51+02:00
Add CVE-2018-500{4,5,6}/libraw

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -18049,12 +18049,18 @@ CVE-2018-5808
 	RESERVED
 CVE-2018-5807
 	RESERVED
-CVE-2018-5806
+CVE-2018-5806 [NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp]
 	RESERVED
-CVE-2018-5805
+	- libraw 0.18.8-1
+	NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
+CVE-2018-5805 [Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp]
 	RESERVED
-CVE-2018-5804
+	- libraw 0.18.8-1
+	NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
+CVE-2018-5804 [type confusion error in identify() function in internal/dcraw_common.cpp]
 	RESERVED
+	- libraw 0.18.8-1
+	NOTE: https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
 CVE-2018-5803 (In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, ...)
 	{DSA-4188-1 DSA-4187-1 DLA-1369-1}
 	- linux 4.15.11-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9b4411bd342cbb78fe3bd878fe100b72e72f4c8b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9b4411bd342cbb78fe3bd878fe100b72e72f4c8b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180616/55120d1e/attachment.html>


More information about the debian-security-tracker-commits mailing list