[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-16167/sysstat

Salvatore Bonaccorso carnil at debian.org
Tue Sep 10 07:00:00 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a083fea2 by Salvatore Bonaccorso at 2019-09-10T05:59:34Z
Update information on CVE-2019-16167/sysstat

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -38,7 +38,11 @@ CVE-2019-16169
 	RESERVED
 CVE-2019-16167 (sysstat before 12.1.6 has memory corruption due to an Integer Overflow ...)
 	- sysstat <unfixed>
+	[buster] - sysstat <no-dsa> (Minor issue, can be fixed via point release)
+	[stretch] - sysstat <not-affected> (Vulnerable code introduced later)
+	[jessie] - sysstat <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/sysstat/sysstat/issues/230
+	NOTE: Introduced after: https://github.com/sysstat/sysstat/commit/65ac30359e49ee717397e39950d7c24a6610d57c (v11.7.1)
 	NOTE: Fixed by: https://github.com/sysstat/sysstat/commit/edbf507678bf10914e9804ff8a06737fdcb2e781
 CVE-2019-16166 (GNU cflow through 1.6 has a heap-based buffer over-read in the nexttok ...)
 	- cflow <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190910/4bf85325/attachment.html>


More information about the debian-security-tracker-commits mailing list