[Git][security-tracker-team/security-tracker][master] sleuthkit non issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Feb 10 07:52:47 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4ffbbd5 by Moritz Muehlenhoff at 2023-02-10T08:52:31+01:00
sleuthkit non issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18508,7 +18508,8 @@ CVE-2022-45641 (Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via
 CVE-2022-45640 (Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Cause ...)
 	NOT-FOR-US: Tenda
 CVE-2022-45639 (** DISPUTED ** OS Command injection vulnerability in sleuthkit fls too ...)
-	TODO: check
+	NOTE: Bogus report on srcsleuthkit: If a malformed parameter is passed, it needs to be
+	NOTE: sanitised in the calling application
 CVE-2022-45638
 	RESERVED
 CVE-2022-45637



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4ffbbd5274ea71b94132f7dc620a2a563dfc49a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4ffbbd5274ea71b94132f7dc620a2a563dfc49a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230210/c24b381f/attachment.htm>


More information about the debian-security-tracker-commits mailing list