summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-02-15 21:42:48 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2022-02-15 21:44:53 +0100
commit5a31628d47b343a466ba311cf7b6038aba45a8d0 (patch)
tree93688ba71aea3f0b51918f5c6f9545b8d7febf66
parent0c58187b6aaf362906709af52cdc9253685c1d1d (diff)
Update note for CVE-2022-0563/util-linux
Unfortunately the situation is compliated. util-linux is compiled with readline support. But additionally it is configured with --disable-chfn-chsh. The chfn and chsh utilities are until now provided by src:shadow (and the passwd binary package).
-rw-r--r--data/CVE/list.20223
1 files changed, 2 insertions, 1 deletions
diff --git a/data/CVE/list.2022 b/data/CVE/list.2022
index 4b1fd5a238..8010cc7b9a 100644
--- a/data/CVE/list.2022
+++ b/data/CVE/list.2022
@@ -1189,7 +1189,8 @@ CVE-2022-0563 [partial disclosure of arbitrary files in chfn and chsh when compi
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2053151
NOTE: https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w@ws.net.home/T/#u
NOTE: https://github.com/util-linux/util-linux/commit/faa5a3a83ad0cb5e2c303edbfd8cd823c9d94c17
- NOTE: util-linux in Debian not built with readline support
+ NOTE: util-linux in Debian does build with readline support but chfn and chsh are provided
+ NOTE: by src:shadow and util-linux is configured with --disable-chfn-chsh
CVE-2022-0562 (Null source pointer passed as an argument to memcpy() function within ...)
- tiff 4.3.0-4
[bullseye] - tiff <no-dsa> (Minor issue)

© 2014-2024 Faster IT GmbH | imprint | privacy policy