[Git][security-tracker-team/security-tracker][master] Update status for CVE-2019-6470/isc-dhcp

Salvatore Bonaccorso carnil at debian.org
Sat May 11 09:46:55 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ab05d727 by Salvatore Bonaccorso at 2019-05-11T08:46:25Z
Update status for CVE-2019-6470/isc-dhcp

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13950,9 +13950,14 @@ CVE-2019-6471
 CVE-2019-6470 [DHCPv6 server crashes regularly]
 	RESERVED
 	- isc-dhcp 4.4.1-2 (bug #896122)
+	[stretch] - isc-dhcp <ignored> (Issue triggerable only when build against bind >= 9.11.3)
 	NOTE: https://bugs.isc.org/Public/Ticket/Display.html?id=48804
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1641246
 	NOTE: https://bugs.launchpad.net/ubuntu/%2Bsource/isc-dhcp/%2Bbug/1781699
+	NOTE: Issue is caused by https://gitlab.isc.org/wpk/bind9/commit/65a483106e45704e19781bfe4f4634db4f77562e
+	NOTE: isc-dhcp builds against system bind library, and commit for upstream
+	NOTE: issue 4829 is first introduced in 9.11.3+dfsg-1. The underlying issue
+	NOTE: is only uncovered when build gainst versions >= 9.11.3.
 CVE-2019-6469
 	RESERVED
 CVE-2019-6468



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ab05d72796669e1a35ad2a53f03884202b84a26a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/ab05d72796669e1a35ad2a53f03884202b84a26a
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190511/3f980ead/attachment.html>


More information about the debian-security-tracker-commits mailing list