[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-1798/libclamunrar n/a in jessie

Emilio Pozuelo Monfort pochu at debian.org
Mon Apr 1 16:03:54 BST 2019



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
904e88ca by Emilio Pozuelo Monfort at 2019-04-01T15:02:34Z
CVE-2019-1798/libclamunrar n/a in jessie

- - - - -
bccf0dac by Emilio Pozuelo Monfort at 2019-04-01T15:03:26Z
dla: remove libclamunrar

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -23218,6 +23218,7 @@ CVE-2019-1798 [A use-after-free condition may occur when scanning nested RAR arc
 	RESERVED
 	- libclamunrar 0.101.2-1
 	[stretch] - libclamunrar <not-affected> (Vulnerable code only present in 0.101.1 and 0.101.0)
+	[jessie] - libclamunrar <not-affected> (Vulnerable code only present in 0.101.1 and 0.101.0)
 	- clamav 0.101.2+dfsg-1
 	[stretch] - clamav <not-affected> (Vulnerable code only present in 0.101.1 and 0.101.0)
 	[jessie] - clamav <not-affected> (Vulnerable code introduced later)


=====================================
data/dla-needed.txt
=====================================
@@ -51,10 +51,6 @@ libav
   NOTE: 20190401: has been found, so far. If you pick libav, be prepared to work
   NOTE: 20190401: out patches yourself.
 --
-libclamunrar
-  NOTE: 20190331: Package is non-free and not used by sponsors but maybe it can be fixed
-  NOTE: nonetheless together with clamav? (apo)
---
 liblivemedia
   NOTE: 20190318: CVE-2019-773{2,3}: wait for upstream patch - hle
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d11abdc12d520ab40189fed19e179a9e7243a564...bccf0dac5257da2e7c9393e3dc0f28c15c15dba6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/d11abdc12d520ab40189fed19e179a9e7243a564...bccf0dac5257da2e7c9393e3dc0f28c15c15dba6
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190401/0cd31f4d/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list