[Git][security-tracker-team/security-tracker][master] Fill in details for CVE-2018-16986 in python-django, including Debian bug#

Chris Lamb lamby at debian.org
Mon Oct 1 12:46:46 BST 2018


Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac2eb633 by Chris Lamb at 2018-10-01T11:46:20Z
Fill in details for CVE-2018-16986 in python-django, including Debian bug#

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1885,8 +1885,8 @@ CVE-2018-16986
 	RESERVED
 CVE-2018-16985 (In Lizard (formerly LZ5) 2.0, use of an invalid memory address was ...)
 	NOT-FOR-US: Lizard
-CVE-2018-16984
-	RESERVED
+CVE-2018-16984 (Password hash disclosure to "view only" admin users)
+	- python-django <unfixed> (bug #910016)
 CVE-2018-16983 (NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other ...)
 	- mozilla-noscript <unfixed> (unimportant)
 	NOTE: This is not a security issue in NoScript by itself



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ac2eb633b232eb5fea6eeba7214a10e773b45b6b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ac2eb633b232eb5fea6eeba7214a10e773b45b6b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181001/244ca9eb/attachment.html>


More information about the debian-security-tracker-commits mailing list