[Git][security-tracker-team/security-tracker][master] Annotate CVE-2017-7481/ansible as not affecting jessie

Roberto C. Sánchez roberto at debian.org
Fri Aug 30 18:19:19 BST 2019



Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e7ddc451 by Roberto C. Sánchez at 2019-08-30T17:18:38Z
Annotate CVE-2017-7481/ansible as not affecting jessie

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -128724,7 +128724,7 @@ CVE-2017-7482 (In the Linux kernel before version 4.12, Kerberos 5 tickets decod
 CVE-2017-7481 (Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark loo ...)
 	- ansible 2.3.1.0+dfsg-1 (bug #862666)
 	[stretch] - ansible <no-dsa> (Minor issue)
-	[jessie] - ansible <no-dsa> (Minor issue)
+	[jessie] - ansible <not-affected> (vulnerable code introduced in version 2.x)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1450018
 	NOTE: Fixed by: https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2
 CVE-2017-7480 (rkhunter versions before 1.4.4 are vulnerable to file download over in ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e7ddc451594026b04685174ce4874feef8711b3b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e7ddc451594026b04685174ce4874feef8711b3b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190830/9d6a22d6/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list