[Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-8608 and CVE-2020-1983
Salvatore Bonaccorso
carnil at debian.org
Sun May 17 09:07:52 BST 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
43ddf267 by Salvatore Bonaccorso at 2020-05-17T10:07:08+02:00
Update information on CVE-2020-8608 and CVE-2020-1983
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12006,11 +12006,12 @@ CVE-2020-8608 (In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snpr
[stretch] - qemu <postponed> (Minor issue)
- qemu-kvm <removed>
- slirp <unfixed>
- - slirp4netns <unfixed>
+ - slirp4netns 1.0.1-1
[buster] - slirp4netns <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/commit/68ccb8021a838066f0951d4b2817eb6b6f10a843
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/commit/30648c03b27fb8d9611b723184216cd3174b6775
NOTE: qemu 1:4.1-2 switched to system libslirp, marking that version as fixed.
+ NOTE: slirp4netns 1.0.1-1 switched to system libslirp, marking that version as fixed.
CVE-2020-8607
RESERVED
CVE-2020-8606
@@ -28740,10 +28741,11 @@ CVE-2020-1983 (A use after free vulnerability in ip_reass() in ip_input.c of lib
- qemu 1:4.1-2
- qemu-kvm <removed>
- libslirp 4.2.0-2
- - slirp4netns <unfixed>
+ - slirp4netns 1.0.1-1
[buster] - slirp4netns <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/9bd6c5913271eabcb7768a58197ed3301fe19f2d
- NOTE: 1:4.1-2 switched to system libslirp, marking that version as fixed
+ NOTE: qemu 1:4.1-2 switched to system libslirp, marking that version as fixed
+ NOTE: slirp4netns 1.0.1-1 switched to system libslirp, marking that version as fixed.
CVE-2020-1982
RESERVED
CVE-2020-1981 (A predictable temporary filename vulnerability in PAN-OS allows local ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43ddf2675a11f8a83845bee9cf2f983f91c97326
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43ddf2675a11f8a83845bee9cf2f983f91c97326
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200517/ea2889fc/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list