[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-16167/sysstat
Salvatore Bonaccorso
carnil at debian.org
Tue Sep 10 07:00:00 BST 2019
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a083fea2 by Salvatore Bonaccorso at 2019-09-10T05:59:34Z
Update information on CVE-2019-16167/sysstat
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -38,7 +38,11 @@ CVE-2019-16169
RESERVED
CVE-2019-16167 (sysstat before 12.1.6 has memory corruption due to an Integer Overflow ...)
- sysstat <unfixed>
+ [buster] - sysstat <no-dsa> (Minor issue, can be fixed via point release)
+ [stretch] - sysstat <not-affected> (Vulnerable code introduced later)
+ [jessie] - sysstat <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/sysstat/sysstat/issues/230
+ NOTE: Introduced after: https://github.com/sysstat/sysstat/commit/65ac30359e49ee717397e39950d7c24a6610d57c (v11.7.1)
NOTE: Fixed by: https://github.com/sysstat/sysstat/commit/edbf507678bf10914e9804ff8a06737fdcb2e781
CVE-2019-16166 (GNU cflow through 1.6 has a heap-based buffer over-read in the nexttok ...)
- cflow <unfixed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a083fea2fa62bb76f1dea21fefcf38bce8172278
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190910/4bf85325/attachment.html>
More information about the debian-security-tracker-commits
mailing list