[Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2018-18501 as affecting firefox-esr

Emilio Pozuelo Monfort pochu at debian.org
Wed Jan 30 07:35:28 GMT 2019


Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
73c2038d by Emilio Pozuelo Monfort at 2019-01-30T07:34:14Z
Mark CVE-2018-18501 as affecting firefox-esr

- - - - -
1c8cad2e by Emilio Pozuelo Monfort at 2019-01-30T07:34:36Z
firefox-esr fixed in unstable

- - - - -
9fc07ec0 by Emilio Pozuelo Monfort at 2019-01-30T07:35:09Z
dla: take firefox-esr

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -20750,7 +20750,7 @@ CVE-2018-18506
 CVE-2018-18505
 	RESERVED
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 60.5.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-01/#CVE-2018-18505
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18505
 CVE-2018-18504
@@ -20768,11 +20768,13 @@ CVE-2018-18502
 CVE-2018-18501
 	RESERVED
 	- firefox <unfixed>
+	- firefox-esr 60.5.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-01/#CVE-2018-18501
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18501
 CVE-2018-18500
 	RESERVED
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 60.5.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-01/#CVE-2018-18500
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18500
 CVE-2018-18499


=====================================
data/dla-needed.txt
=====================================
@@ -26,6 +26,8 @@ exiv2 (Thorsten Alteholz)
 faad2 (Hugo Lefeuvre)
   NOTE: 20190125: No known patch yet. Going to fix the most exploitable issues at first.
 --
+firefox-esr (Emilio)
+--
 firmware-nonfree
   NOTE: needed by sponsors
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/aad5206cf1b75df0d0e6c148a88f584ede7f2ffc...9fc07ec0aef49dfe03e27dd9ec5493a08d71302a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/aad5206cf1b75df0d0e6c148a88f584ede7f2ffc...9fc07ec0aef49dfe03e27dd9ec5493a08d71302a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190130/105909a4/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list