From 773c0460fb716e09437420d626c5d75db1c4227c Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Thu, 23 Jun 2022 07:18:10 +0200 Subject: Add CVE-2022-34299/dwarfutils --- data/CVE/list | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index 820d5f0bc3..ae0d4190aa 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -56,7 +56,10 @@ CVE-2022-34300 (In tinyexr 1.0.1, there is a heap-based buffer over-read in tiny - tinyexr NOTE: https://github.com/syoyo/tinyexr/issues/167 CVE-2022-34299 (There is a heap-based buffer over-read in libdwarf 0.4.0. This issue i ...) - TODO: check + - dwarfutils + NOTE: https://github.com/davea42/libdwarf-code/commit/7ef09e1fc9ba07653dd078edb2408631c7969162 + NOTE: https://github.com/davea42/libdwarf-code/issues/119 + NOTE: https://www.prevanders.net/dwarfbug.html#DW202206-001 CVE-2022-34298 (The NT auth module in OpenAM before 14.6.6 allows a "replace Samba use ...) TODO: check CVE-2022-34297 -- cgit v1.2.3