[Git][security-tracker-team/security-tracker][master] Update information for CVE-2019-14276/fig2dev

Salvatore Bonaccorso carnil at debian.org
Fri Jul 26 12:45:17 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e02f535e by Salvatore Bonaccorso at 2019-07-26T11:44:12Z
Update information for CVE-2019-14276/fig2dev

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,9 +13,10 @@ CVE-2019-14277 (Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with c
 CVE-2019-14276
 	RESERVED
 CVE-2019-14275 (Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arro ...)
-	- fig2dev <unfixed>
-	- transfig <removed>
+	- fig2dev <unfixed> (unimportant)
+	- transfig <removed> (unimportant)
 	NOTE: https://sourceforge.net/p/mcj/tickets/52/
+	NOTE: Crash in CLI tool, no security impact, hardening build
 CVE-2019-14274 (MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function i ...)
 	- mcpp <unfixed>
 	NOTE: https://sourceforge.net/p/mcpp/bugs/13/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e02f535efab0decc86a1eefe559a180909f020b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e02f535efab0decc86a1eefe559a180909f020b0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190726/e17ee820/attachment.html>


More information about the debian-security-tracker-commits mailing list