[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] new libzypp issues

Moritz Muehlenhoff jmm at debian.org
Sun Mar 4 20:47:19 UTC 2018


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9edc3a09 by Moritz Muehlenhoff at 2018-03-04T21:46:56+01:00
new libzypp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -44203,7 +44203,7 @@ CVE-2017-9271 (The commandline package update tool zypper writes HTTP proxy ...)
 CVE-2017-9270 (In cryptctl before version 2.0 a malicious server could send RPC ...)
 	TODO: check
 CVE-2017-9269 (In libzypp before August 2018 GPG keys attached to YUM repositories ...)
-	TODO: check
+	- libzypp <unfixed>
 CVE-2017-9268 (In the open build service before 201707022 the wipetrigger and rebuild ...)
 	TODO: check
 CVE-2017-9267 (In Novell eDirectory before 9.0.3.1 the LDAP interface was not ...)
@@ -50203,9 +50203,9 @@ CVE-2017-7438 (NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowe
 CVE-2017-7437
 	RESERVED
 CVE-2017-7436 (In libzypp before 20170803 it was possible to retrieve unsigned ...)
-	TODO: check
+	- libzypp <unfixed>
 CVE-2017-7435 (In libzypp before 20170803 it was possible to add unsigned YUM ...)
-	TODO: check
+	- libzypp <unfixed>
 CVE-2017-7434 (In the JDBC driver of NetIQ Identity Manager before 4.6 sending out ...)
 	NOT-FOR-US: NetIQ Identity Manager
 CVE-2017-7433 (An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9edc3a09f0e15c5aed7901910a3e7aead9c629f6

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9edc3a09f0e15c5aed7901910a3e7aead9c629f6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180304/af9559ff/attachment.html>


More information about the Secure-testing-commits mailing list