[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Update note on openssh.

Mike Gabriel sunweaver at debian.org
Thu Feb 28 21:07:13 GMT 2019


Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f07c512 by Mike Gabriel at 2019-02-28T21:07:00Z
data/dla-needed.txt: Update note on openssh.

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -88,6 +88,8 @@ openjdk-7 (Emilio)
 openssh (Mike Gabriel)
   NOTE: 20190227: Work in progress. First draft is still vulnerable to PoC: https://www.exploit-db.com/exploits/46193
   NOTE: 20190227: Problematic is that jessie's / wheezy's versions don't have the utf8.(c|h) code, yet. Probably needs to be backported.
+  NOTE: 20190228: CVE-2019-6111 seemingly not-yet-fixed, see https://bugs.debian.org/923486
+  NOTE: 20190228: Package draft for jessie LTS locally, but the CVE-2019-6111 patch requires being fixed first before proceeding
 --
 openssl (Markus Koschany)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5f07c5129d86a76ad235b909f03d1f11a51ab23a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5f07c5129d86a76ad235b909f03d1f11a51ab23a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190228/99c5c16d/attachment.html>


More information about the debian-security-tracker-commits mailing list