[Git][security-tracker-team/security-tracker][master] Demote severity of CVE-2018-16301 to unimportant

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Feb 9 20:21:31 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6cae5458 by Salvatore Bonaccorso at 2022-02-09T21:20:51+01:00
Demote severity of CVE-2018-16301 to unimportant

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -226412,11 +226412,12 @@ CVE-2018-16303 (PDF-XChange Editor through 7.0.326.1 allows remote attackers to
 CVE-2018-16302 (MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted fil ...)
 	NOT-FOR-US: MediaComm Zip-n-Go
 CVE-2018-16301 (The command-line argument parser in tcpdump before 4.99.0 has a buffer ...)
-	- tcpdump 4.99.0-1
+	- tcpdump 4.99.0-1 (unimportant)
 	NOTE: https://github.com/the-tcpdump-group/libpcap/issues/855
 	NOTE: https://github.com/the-tcpdump-group/tcpdump/commit/ad7c25bc0decf96dc7768c9e903734d38528b1bd
 	NOTE: https://www.tcpdump.org/public-cve-list.txt
 	NOTE: Fixed along with: https://github.com/the-tcpdump-group/tcpdump/commit/faf8fb70af3a013e5d662b8283dec742fd6b1a77 (tcpdump-4.99-bp)
+	NOTE: Negligible security impact
 CVE-2018-16300 (The BGP parser in tcpdump before 4.9.3 allows stack consumption in pri ...)
 	{DSA-4547-1 DLA-1955-1}
 	- tcpdump 4.9.3-1 (bug #941698)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cae54583711d1d2362cb0a42dfc2bedf390a6dc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cae54583711d1d2362cb0a42dfc2bedf390a6dc
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220209/7dabc931/attachment.htm>


More information about the debian-security-tracker-commits mailing list