[Git][security-tracker-team/security-tracker][master] 2 commits: Fix URL to advisory for CVE-2018-12207

Salvatore Bonaccorso carnil at debian.org
Tue Nov 12 18:39:19 GMT 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f48c05c7 by Salvatore Bonaccorso at 2019-11-12T18:37:02Z
Fix URL to advisory for CVE-2018-12207

- - - - -
0c28ed0c by Salvatore Bonaccorso at 2019-11-12T18:38:44Z
Add two new xen issues (XSA-304 and XSA-305)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25775,7 +25775,9 @@ CVE-2019-11135 [TSX Asynchronous Abort]
 	RESERVED
 	- linux <unfixed>
 	- intel-microcode <unfixed>
+	- xen <unfixed>
 	NOTE: https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort
+	NOTE: https://xenbits.xen.org/xsa/advisory-305.html
 CVE-2019-11134
 	RESERVED
 CVE-2019-11133 (Improper access control in the Intel(R) Processor Diagnostic Tool befo ...)
@@ -76460,7 +76462,9 @@ CVE-2018-12207 [iTLB Multihit]
 	RESERVED
 	- linux <unfixed>
 	[jessie] - linux <ignored> (Untrusted guests are no longer supportable)
-	NOTE: https://software.intel.com/security-software-guidance/insights/deep-dive-machine-check-error-avoidance-page-size-change
+	- xen <unfixed>
+	NOTE: https://software.intel.com/security-software-guidance/insights/deep-dive-machine-check-error-avoidance-page-size-change-0
+	NOTE: https://xenbits.xen.org/xsa/advisory-304.html
 CVE-2018-12206 (Improper configuration of hardware access in Intel QuickAssist Technol ...)
 	NOT-FOR-US: Intel QuickAssist Technology for Linux
 CVE-2018-12205 (Improper certificate validation in Platform Sample/ Silicon Reference  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/0a8996f90d08a8ea3daabf986759d8173dd721b0...0c28ed0c0a0ac7f59499baf747772686ea2c900e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/0a8996f90d08a8ea3daabf986759d8173dd721b0...0c28ed0c0a0ac7f59499baf747772686ea2c900e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191112/dddaacea/attachment.html>


More information about the debian-security-tracker-commits mailing list