[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-14249/dwarfutils

Salvatore Bonaccorso carnil at debian.org
Sun Jul 28 21:16:07 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c19e1d67 by Salvatore Bonaccorso at 2019-07-28T20:15:51Z
Update information on CVE-2019-14249/dwarfutils

The difivison by zero issue was introduced while refactoring the code
and introduced in 20190505 and the code not backported to any supported
version in Debian.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -330,12 +330,10 @@ CVE-2019-14250 (An issue was discovered in GNU libiberty, as distributed in GNU
 	NOTE: https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html
 	NOTE: binutils not covered by security support
 CVE-2019-14249 (dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attacker ...)
-	- dwarfutils <unfixed> (low)
-	[buster] - dwarfutils <no-dsa> (Minor issue)
-	[stretch] - dwarfutils <no-dsa> (Minor issue)
-	[jessie] - dwarfutils <no-dsa> (Minor issue)
+	- dwarfutils <not-affected> (Vulnerable code introduced in 20190505 version)
 	NOTE: https://sourceforge.net/p/libdwarf/code/merge-requests/4/
 	NOTE: Fixed by: https://sourceforge.net/p/libdwarf/code/ci/cb7198abde46c2ae29957ad460da6886eaa606ba
+	NOTE: Introduced in: https://sourceforge.net/p/libdwarf/code/ci/4709f63c8b7488241b5b522267a796834a66db3a
 CVE-2019-14248 (In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows  ...)
 	- nasm <unfixed> (unimportant; bug #932907)
 	NOTE: https://bugzilla.nasm.us/show_bug.cgi?id=3392576



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/c19e1d67a4d0899b89c2c8822c4fe6ac44408515

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/c19e1d67a4d0899b89c2c8822c4fe6ac44408515
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190728/5ee43f23/attachment.html>


More information about the debian-security-tracker-commits mailing list