[Git][security-tracker-team/security-tracker][master] Add CVE-2019-{5018,8457}/sqlite3 fixed version in unstable
László Böszörményi
gcs at debian.org
Mon Jun 10 22:07:39 BST 2019
László Böszörményi pushed to branch master at Debian Security Tracker / security-tracker
Commits:
301423cf by Laszlo Boszormenyi (GCS) at 2019-06-10T21:07:02Z
Add CVE-2019-{5018,8457}/sqlite3 fixed version in unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11613,7 +11613,7 @@ CVE-2019-8459
CVE-2019-8458
RESERVED
CVE-2019-8457 (SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-o ...)
- - sqlite3 <unfixed> (bug #929775)
+ - sqlite3 3.27.2-3 (bug #929775)
NOTE: https://www.sqlite.org/src/info/90acdbfce9c08858
CVE-2019-8456 (Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditio ...)
NOT-FOR-US: Check Point
@@ -19974,7 +19974,7 @@ CVE-2019-5020
CVE-2019-5019 (A heap-based overflow vulnerability exists in the PowerPoint document ...)
NOT-FOR-US: Rainbow PDF Office Server Document Converter
CVE-2019-5018 (An exploitable use after free vulnerability exists in the window funct ...)
- - sqlite3 <unfixed> (bug #928770)
+ - sqlite3 3.27.2-3 (bug #928770)
[stretch] - sqlite3 <not-affected> (windowfuncs introduced in 3.25.0)
[jessie] - sqlite3 <not-affected> (windowfuncs introduced in 3.25.0)
NOTE: https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/301423cff6448a279c73b45702d9732e6c713c80
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/301423cff6448a279c73b45702d9732e6c713c80
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190610/db57b9bc/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list