2 ignored security issues in jessie

package:
cgminer
severity:
low
created:
2018-06-03
last updated:
2019-07-04

There are 2 open security issues in jessie.
2 issues skipped by the security teams:
  • CVE-2018-10057: The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).
  • CVE-2018-10058: The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
Please fix them.