[Git][security-tracker-team/security-tracker][master] Track the new 13 vulnerabilities in u-boot

Salvatore Bonaccorso carnil at debian.org
Thu Aug 1 08:15:39 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8717b3ea by Salvatore Bonaccorso at 2019-08-01T07:14:02Z
Track the new 13 vulnerabilities in u-boot

Tracking as no-dsa because is mainly an issue when u-boot is configured
to use the network for fetching the next stage boot resources and this
probably should happen only in trusted environments.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1218,31 +1218,70 @@ CVE-2019-14206 (An Arbitrary File Deletion vulnerability in the Nevma Adaptive I
 CVE-2019-14205 (A Local File Inclusion vulnerability in the Nevma Adaptive Images plug ...)
 	NOT-FOR-US: Nevma Adaptive Images plugin for WordPress
 CVE-2019-14204 (An issue was discovered in Das U-Boot through 2019.07. There is a stac ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14203 (An issue was discovered in Das U-Boot through 2019.07. There is a stac ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14202 (An issue was discovered in Das U-Boot through 2019.07. There is a stac ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14201 (An issue was discovered in Das U-Boot through 2019.07. There is a stac ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14200 (An issue was discovered in Das U-Boot through 2019.07. There is a stac ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14199 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14198 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14197 (An issue was discovered in Das U-Boot through 2019.07. There is a read ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14196 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14195 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14194 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14193 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14192 (An issue was discovered in Das U-Boot through 2019.07. There is an unb ...)
-	TODO: check
+	- u-boot <unfixed>
+	[buster] - u-boot <no-dsa> (Minor issue)
+	[stretch] - u-boot <no-dsa> (Minor issue)
+	NOTE: https://blog.semmle.com/uboot-rce-nfs-vulnerability/
 CVE-2019-14191
 	RESERVED
 CVE-2019-14190



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8717b3ea622cbad111c5298d54718ca94076e011

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8717b3ea622cbad111c5298d54718ca94076e011
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190801/623a6bcc/attachment.html>


More information about the debian-security-tracker-commits mailing list