[Git][security-tracker-team/security-tracker][master] dla: xerces-c status update
Sylvain Beucler
beuc at debian.org
Thu Mar 12 15:10:39 GMT 2020
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
50906e93 by Sylvain Beucler at 2020-03-12T16:10:10+01:00
dla: xerces-c status update
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -131721,6 +131721,7 @@ CVE-2018-1311 (The Apache Xerces-C 3.0.0 to 3.2.2 XML parser contains a use-afte
NOTE: http://xerces.apache.org/xerces-c/secadv/CVE-2018-1311.txt
NOTE: https://issues.apache.org/jira/browse/XERCESC-2188
NOTE: http://vault.centos.org/7.7.1908/updates/Source/SPackages/xerces-c-3.1.1-10.el7_7.src.rpm (fix with possible memory leak)
+ NOTE: Mitigation by setting the XERCES_DISABLE_DTD environment variable
CVE-2018-1310 (Apache NiFi JMS Deserialization issue because of ActiveMQ client vulne ...)
NOT-FOR-US: Apache NiFi
CVE-2018-1309 (Apache NiFi External XML Entity issue in SplitXML processor. Malicious ...)
=====================================
data/dla-needed.txt
=====================================
@@ -99,7 +99,8 @@ xen (Roberto C. Sánchez)
NOTE: 20200302: https://lists.debian.org/debian-lts/2020/03/msg00024.html
--
xerces-c (Sylvain Beucler)
- NOTE: 20200306: no sanctioned patch, pinging upstream (beuc)
+ NOTE: 20200312: no patch, little upstream resource to review one (beuc)
+ NOTE: 20200312: waiting a bit for activity and possibly following RedHat's leak-vs-rce route (beuc)
--
yubikey-val (Utkarsh Gupta)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50906e936c7de786b4db9bdd6eedff3d998bbade
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50906e936c7de786b4db9bdd6eedff3d998bbade
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200312/95540401/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list