[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-14491,CVE-2019-14492,CVE-2019-14493/opencv: jessie postponed

Sylvain Beucler beuc at debian.org
Wed Oct 2 15:47:54 BST 2019



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
39ad5e82 by Sylvain Beucler at 2019-10-02T14:47:39Z
CVE-2019-14491,CVE-2019-14492,CVE-2019-14493/opencv: jessie postponed

- - - - -
969d433a by Sylvain Beucler at 2019-10-02T14:47:40Z
CVE-2019-14850,CVE-2019-14851/nbdkit: jessie <ignored>

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6266,6 +6266,7 @@ CVE-2019-14852
 CVE-2019-14851 [assertion failure by issuing commands in the wrong order]
 	RESERVED
 	- nbdkit 1.14.2-1
+	[jessie] - nbdkit <not-affected> (introduced by CVE-2019-14850)
 	NOTE: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html
 	NOTE: 1.15 (development branch):
 	NOTE: https://github.com/libguestfs/nbdkit/commit/a6b88b195a959b17524d1c8353fd425d4891dc5f
@@ -6276,6 +6277,7 @@ CVE-2019-14851 [assertion failure by issuing commands in the wrong order]
 CVE-2019-14850 [denial of service due to premature opening of back-end connection]
 	RESERVED
 	- nbdkit 1.14.1-1
+	[jessie] - nbdkit <ignored> (Minor issue, DoS/amplification for specific configuration, non-trivial backport, low popcon)
 	NOTE: https://www.redhat.com/archives/libguestfs/2019-September/msg00084.html
 	NOTE: 1.15 (development branch):
 	NOTE: https://github.com/libguestfs/nbdkit/commit/c05686f9577fa91b6a3a4d8c065954ca6fc3fd62
@@ -7266,6 +7268,7 @@ CVE-2019-14494 (An issue was discovered in Poppler through 0.78.0. There is a di
 CVE-2019-14493 (An issue was discovered in OpenCV before 4.1.1. There is a NULL pointe ...)
 	[experimental] - opencv 4.1.1+dfsg-1
 	- opencv <unfixed>
+	[jessie] - opencv <postponed> (Minor issue, DoS, PoC not crashing)
 	NOTE: https://github.com/opencv/opencv/issues/15127
 	NOTE: https://github.com/opencv/opencv/commit/5691d998ead1d9b0542bcfced36c2dceb3a59023
 	NOTE: In older versions of opencv missing NULL pointer check(s) are in
@@ -7274,11 +7277,13 @@ CVE-2019-14493 (An issue was discovered in OpenCV before 4.1.1. There is a NULL
 CVE-2019-14492 (An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. T ...)
 	[experimental] - opencv 4.1.1+dfsg-1
 	- opencv <unfixed>
+	[jessie] - opencv <postponed> (Minor issue, DoS, PoC not crashing)
 	NOTE: https://github.com/opencv/opencv/issues/15124
 	NOTE: https://github.com/opencv/opencv/commit/ac425f67e4c1d0da9afb9203f0918d8d57c067ed
 CVE-2019-14491 (An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. T ...)
 	[experimental] - opencv 4.1.1+dfsg-1
 	- opencv <unfixed>
+	[jessie] - opencv <postponed> (Minor issue, DoS, PoC not crashing)
 	NOTE: https://github.com/opencv/opencv/issues/15125
 	NOTE: https://github.com/opencv/opencv/commit/ac425f67e4c1d0da9afb9203f0918d8d57c067ed
 CVE-2019-14490



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/f5de262517923b4d263f61255e8cfcd5ea5a3703...969d433adcdea90fad4ac9766ce606807728f715

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/f5de262517923b4d263f61255e8cfcd5ea5a3703...969d433adcdea90fad4ac9766ce606807728f715
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191002/1a28644c/attachment.html>


More information about the debian-security-tracker-commits mailing list