[Git][security-tracker-team/security-tracker][master] CVE-2020-9365 marked as not affected since the vulnerable function does not...
Ola Lundqvist
opal at debian.org
Tue Feb 25 06:55:48 GMT 2020
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6cbebbf5 by Ola Lundqvist at 2020-02-25T07:55:37+01:00
CVE-2020-9365 marked as not affected since the vulnerable function does not exist in the jessie version of pure-ftpd. Instead of the vulnerable pure_strcmp the regular strcmp is used in this version.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21,6 +21,7 @@ CVE-2020-9367
RESERVED
CVE-2020-9365 (An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) re ...)
- pure-ftpd <unfixed> (bug #952471)
+ [jessie] - pure-ftpd <not-affected> (Vulnerable code does not exist)
NOTE: https://github.com/jedisct1/pure-ftpd/commit/36c6d268cb190282a2c17106acfd31863121b
CVE-2020-9364
RESERVED
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cbebbf545085fc44516e7cc0004837b64719c56
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cbebbf545085fc44516e7cc0004837b64719c56
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200225/dab9275e/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list