-
-
Notifications
You must be signed in to change notification settings - Fork 14.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability roundup 47 (master) #47121
Comments
An attempt to incorporate some 2.30 patches got stuck at #41042 |
Some initial investigations:
|
Looks like |
For
You can confirm that both of those fixes are present in the given release tag here. |
CVE-2018-14394 and CVE-2018-14395 seem to be in. |
|
excempi (CVE-2018-12648) has been fixed on master in #47496. |
procps CVE-2018-1121: I'm satisfied by https://bugzilla.redhat.com/show_bug.cgi?id=1575473#c3 |
Most unchecked vulns had already been fixed in the mean time, I just backported the openjpeg fix to master. CVE-2018-13410, the last non-fixed one, is disputed with what looks like a real argument: it's an off-by-one that can be triggered only when using an option that allows arbitrary code execution. As this is the last one of this report, I'm going to close this issue. Thank you all! :) |
Scanned nixos/release-combined.nix @ 5664e64. Filtered out previously reported CVEs. May contain false positives.
binutils-2.30 (search, files)
exempi-2.4.5 (search, files)
ffmpeg-3.4.4 (search, files)
libsndfile-1.0.28 (search, files)
libtiff-4.0.9 (search, files)
openjpeg-2.3.0 (search, files)
procps-3.3.15 (search, files)
sddm-0.17.0 (search, files)
zip-3.0 (search, files)
Cc: @joepie91, @phanimahesh, @the-kenny, @7c6f434c, @k0001, @peterhoeg, @nh2, @LnL7, @grahamc, @adisbladis, @fpletz, @vcunat
Contact @ckauhaus for any questions.
The text was updated successfully, but these errors were encountered: