[Git][security-tracker-team/security-tracker][master] new webkit issues

Moritz Muehlenhoff jmm at debian.org
Thu Apr 11 12:46:43 BST 2019



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
808d6b2a by Moritz Muehlenhoff at 2019-04-11T11:46:16Z
new webkit issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25,7 +25,9 @@ CVE-2019-11073
 CVE-2019-11072 (lighttpd before 1.4.54 has a signed integer overflow, which might allo ...)
 	TODO: check
 CVE-2019-11070 (WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly ap ...)
-	TODO: check
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-11069 (Sequelize before 5.3.0 does not properly ensure that standard conformi ...)
 	TODO: check
 CVE-2019-11068 (libxslt through 1.1.33 allows bypass of a protection mechanism because ...)
@@ -6862,6 +6864,9 @@ CVE-2019-8564
 	RESERVED
 CVE-2019-8563
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8562
 	RESERVED
 CVE-2019-8561
@@ -6870,8 +6875,14 @@ CVE-2019-8560
 	RESERVED
 CVE-2019-8559
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8558
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8557
 	RESERVED
 CVE-2019-8556
@@ -6886,6 +6897,9 @@ CVE-2019-8552
 	RESERVED
 CVE-2019-8551
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8550
 	RESERVED
 CVE-2019-8549
@@ -6900,6 +6914,9 @@ CVE-2019-8545
 	RESERVED
 CVE-2019-8544
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8543
 	RESERVED
 CVE-2019-8542
@@ -6916,8 +6933,14 @@ CVE-2019-8537
 	RESERVED
 CVE-2019-8536
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8535
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8534
 	RESERVED
 CVE-2019-8533
@@ -6940,8 +6963,14 @@ CVE-2019-8525
 	RESERVED
 CVE-2019-8524
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8523
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8522
 	RESERVED
 CVE-2019-8521
@@ -6952,12 +6981,18 @@ CVE-2019-8519
 	RESERVED
 CVE-2019-8518
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8517
 	RESERVED
 CVE-2019-8516
 	RESERVED
 CVE-2019-8515
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8514
 	RESERVED
 CVE-2019-8513
@@ -6976,12 +7011,18 @@ CVE-2019-8507
 	RESERVED
 CVE-2019-8506
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8505
 	RESERVED
 CVE-2019-8504
 	RESERVED
 CVE-2019-8503
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-8502
 	RESERVED
 CVE-2019-8501
@@ -9946,6 +9987,9 @@ CVE-2019-7293
 	RESERVED
 CVE-2019-7292
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-7291
 	RESERVED
 CVE-2019-7290
@@ -9960,6 +10004,9 @@ CVE-2019-7286
 	RESERVED
 CVE-2019-7285
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-7284
 	RESERVED
 CVE-2019-7281
@@ -12493,6 +12540,7 @@ CVE-2019-6251 (embed/ephy-web-view.c in GNOME Web (aka Epiphany) through 3.31.4
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/issues/532
 	NOTE: https://bugs.webkit.org/show_bug.cgi?id=194131
 	NOTE: https://bugs.webkit.org/show_bug.cgi?id=194208
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-6249 (An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerabilit ...)
 	NOT-FOR-US: HuCart
 CVE-2019-6250 (A pointer overflow, with code execution, was discovered in ZeroMQ libz ...)
@@ -12631,6 +12679,9 @@ CVE-2019-6202 (An out-of-bounds read was addressed with improved bounds checking
 	NOT-FOR-US: Apple
 CVE-2019-6201
 	RESERVED
+	- webkit2gtk 2.24.1-1
+	[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
+	NOTE: https://webkitgtk.org/security/WSA-2019-0002.html
 CVE-2019-6200 (An out-of-bounds read was addressed with improved input validation. Th ...)
 	NOT-FOR-US: Apple
 CVE-2019-6199



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/808d6b2aa646881d016c3a0c028cbf8ebf6bfeff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/808d6b2aa646881d016c3a0c028cbf8ebf6bfeff
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190411/436bb705/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list