[Git][security-tracker-team/security-tracker][master] update NOTE of CVE-2018-19211 and mark it as ignored in Stretch

Thorsten Alteholz alteholz at debian.org
Fri Sep 25 16:26:10 BST 2020



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b63449c1 by Thorsten Alteholz at 2020-09-25T17:25:51+02:00
update NOTE of CVE-2018-19211 and mark it as ignored in Stretch

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -120964,10 +120964,11 @@ CVE-2018-19212 (In libwebm through 2018-10-03, there is an abort caused by libwe
 	NOTE: Chromium and qtwebengine bundle the library, but not a security issue there
 CVE-2018-19211 (In ncurses 6.1, there is a NULL pointer dereference at function _nc_pa ...)
 	- ncurses 6.1+20180210-3 (low)
-	[stretch] - ncurses <no-dsa> (Minor issue)
+	[stretch] - ncurses <ignored> (Minor issue)
 	[jessie] - ncurses <no-dsa> (Minor issue)
 	[wheezy] - ncurses <ignored> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1643754
+	NOTE: according to this Redhat bug, this is a duplicate of CVE-2018-10754, which has been rejected
 CVE-2018-19210 (In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWrite ...)
 	{DSA-4670-1 DLA-1680-1}
 	- tiff 4.0.10-4 (bug #913675)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b63449c175b0744d9128deaf978587844fbaa439

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b63449c175b0744d9128deaf978587844fbaa439
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200925/f6fd92cb/attachment.html>


More information about the debian-security-tracker-commits mailing list