[Git][security-tracker-team/security-tracker][master] CVE-2020-9365 marked as not affected since the vulnerable function does not...

Ola Lundqvist opal at debian.org
Tue Feb 25 06:55:48 GMT 2020



Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6cbebbf5 by Ola Lundqvist at 2020-02-25T07:55:37+01:00
CVE-2020-9365 marked as not affected since the vulnerable function does not exist in the jessie version of pure-ftpd. Instead of the vulnerable pure_strcmp the regular strcmp is used in this version.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -21,6 +21,7 @@ CVE-2020-9367
 	RESERVED
 CVE-2020-9365 (An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) re ...)
 	- pure-ftpd <unfixed> (bug #952471)
+	[jessie] - pure-ftpd <not-affected> (Vulnerable code does not exist)
 	NOTE: https://github.com/jedisct1/pure-ftpd/commit/36c6d268cb190282a2c17106acfd31863121b
 CVE-2020-9364
 	RESERVED



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cbebbf545085fc44516e7cc0004837b64719c56

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cbebbf545085fc44516e7cc0004837b64719c56
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200225/dab9275e/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list