[Git][security-tracker-team/security-tracker][master] Add CVE-2010-2496/{cluster-glue,pacemaker}

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jun 22 07:44:55 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e9fc70a3 by Salvatore Bonaccorso at 2021-06-22T08:44:23+02:00
Add CVE-2010-2496/{cluster-glue,pacemaker}

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -418359,8 +418359,13 @@ CVE-2010-2498 (The psh_glyph_find_strong_points function in pshinter/pshalgo.c i
 CVE-2010-2497 (Integer underflow in glyph handling in FreeType before 2.4.0 allows re ...)
 	{DSA-2070-1}
 	- freetype 2.4.0-1
-CVE-2010-2496
+CVE-2010-2496 [cluster-glue: passes the stonith parameters via the commandline which could result in password leaks]
 	RESERVED
+	- cluster-glue 1.0.6-1
+	- pacemaker 1.1.13-1
+	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=620781
+	NOTE: https://github.com/ClusterLabs/cluster-glue/commit/3d7b464439ee0271da76e0ee9480f3dc14005879 (glue-1.0.6)
+	NOTE: https://github.com/ClusterLabs/pacemaker/commit/7901f43c5800374d41ae2287fe122692fe045664 (Pacemaker-1.1.3)
 CVE-2010-2493 (The default configuration of the deployment descriptor (aka web.xml) i ...)
 	- jbossas4 <not-affected> (Only builds a few libraries, not the full application server, #581226)
 CVE-2010-2492 (Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messagin ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9fc70a320b95ade5bf7427edc7c685d81af3659

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9fc70a320b95ade5bf7427edc7c685d81af3659
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210622/1df5c3ab/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list