[Git][security-tracker-team/security-tracker][master] add strongSwan CVE (no-dsa)

Yves-Alexis Perez corsac at debian.org
Wed May 23 19:02:03 BST 2018


Yves-Alexis Perez pushed to branch master at Debian Security Tracker / security-tracker


Commits:
64d2830a by Yves-Alexis Perez at 2018-05-23T20:01:41+02:00
add strongSwan CVE (no-dsa)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -16180,8 +16180,13 @@ CVE-2018-5390
 	RESERVED
 CVE-2018-5389
 	RESERVED
-CVE-2018-5388
+CVE-2018-5388 [buffer underflow in charon IKE daemon]
 	RESERVED
+	- strongswan <unfixed>
+	[jessie] - strongswan <no-dsa> (needs root priv for access to the stroke socket)
+	[stretch] - strongswan <no-dsa> (needs root priv for access to the stroke socket)
+	NOTE: https://www.kb.cert.org/vuls/id/338343
+	NOTE: https://git.strongswan.org/?p=strongswan.git;a=commitdiff;h=0acd1ab4
 CVE-2018-5387
 	RESERVED
 CVE-2018-5386



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/64d2830a1d80b7888c3e2a6b45954149f9a68201

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/64d2830a1d80b7888c3e2a6b45954149f9a68201
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180523/166ee206/attachment.html>


More information about the debian-security-tracker-commits mailing list