[Git][security-tracker-team/security-tracker][master] Add CVE-2020-10737/oddjob

Salvatore Bonaccorso carnil at debian.org
Sat May 9 10:01:55 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d0510571 by Salvatore Bonaccorso at 2020-05-09T11:00:50+02:00
Add CVE-2020-10737/oddjob

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6147,8 +6147,11 @@ CVE-2020-10739
 	RESERVED
 CVE-2020-10738
 	RESERVED
-CVE-2020-10737
+CVE-2020-10737 [oddjob: race condition in oddjob_selinux_mkdir function in mkhomedir.c can lead to symlink attack]
 	RESERVED
+	- oddjob <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1833042
+	NOTE: https://pagure.io/oddjob/c/10b8aaa1564b723a005b53acc069df71313f4cac
 CVE-2020-10736
 	RESERVED
 CVE-2020-10735



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d05105711de6735154b40ffb0f30b027e2b62e69

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d05105711de6735154b40ffb0f30b027e2b62e69
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200509/16704431/attachment.html>


More information about the debian-security-tracker-commits mailing list