[Git][security-tracker-team/security-tracker][master] Add CVE-2015-9542/libpam-radius-auth

Salvatore Bonaccorso carnil at debian.org
Thu Feb 13 06:28:16 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
19a07f6f by Salvatore Bonaccorso at 2020-02-13T07:27:47+01:00
Add CVE-2015-9542/libpam-radius-auth

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -233,8 +233,13 @@ CVE-2020-8840 (FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain x
 	NOTE: but still an issue when Default Typing is enabled.
 CVE-2020-8839 (Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter dev ...)
 	NOT-FOR-US: CHIYU BF-430 232/485 TCP/IP Converter devices
-CVE-2015-9542
+CVE-2015-9542 [buffer overflow in password field]
 	RESERVED
+	- libpam-radius-auth <unfixed>
+	NOTE: https://github.com/FreeRADIUS/pam_radius/commit/01173ec
+	NOTE: https://github.com/FreeRADIUS/pam_radius/commit/6bae92d
+	NOTE: https://github.com/FreeRADIUS/pam_radius/commit/ac2c1677
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1686980
 CVE-2020-8838
 	RESERVED
 CVE-2020-8837



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/19a07f6f1771b563a1183841ab4db1bbbf7209f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/19a07f6f1771b563a1183841ab4db1bbbf7209f4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200213/a1045289/attachment.html>


More information about the debian-security-tracker-commits mailing list