[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Remove CVE-2018-8086 entry

Salvatore Bonaccorso carnil at debian.org
Tue Mar 13 20:06:37 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d55696b by Salvatore Bonaccorso at 2018-03-13T21:05:21+01:00
Remove CVE-2018-8086 entry

Investigation from upstream showed that the issue is invalid, cf.

https://sourceware.org/bugzilla/show_bug.cgi?id=22958

and the CVE assignement was premature. The CVE is now rejected by MITRE
and will show up as such in next updates.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -1,11 +1,8 @@
 CVE-2018-8087 (Memory leak in the hwsim_new_radio_nl function in ...)
 	- linux <unfixed>
 	NOTE: Fixed by: https://git.kernel.org/linus/0ddcff49b672239dda94d70d0fcf50317a9f4b51
-CVE-2018-8086 (The basename implementation in string/basename.c in the GNU C Library ...)
-	- glibc <unfixed>
-	- eglibc <removed>
-	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1554538
-	TODO: check
+CVE-2018-8086
+	REJECTED
 CVE-2018-8085
 	RESERVED
 CVE-2018-1000097 (Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8d55696b4365e536e849b819e25508d4a0901bae

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8d55696b4365e536e849b819e25508d4a0901bae
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180313/f368328d/attachment.html>


More information about the Secure-testing-commits mailing list