[Secure-testing-commits] r57918 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Nov 22 05:43:51 UTC 2017


Author: carnil
Date: 2017-11-22 05:43:51 +0000 (Wed, 22 Nov 2017)
New Revision: 57918

Modified:
   data/CVE/list
Log:
Mark CVE-2017-11883 and CVE-2017-11770 as NFU

Quoting Paul Wise on IRC:

> [05:53] < pabs> carnil: re the external check mails, I asked on
> #debian-cli and got <directhex> pabs: .net core bugs, not mono

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-11-22 05:30:27 UTC (rev 57917)
+++ data/CVE/list	2017-11-22 05:43:51 UTC (rev 57918)
@@ -14638,7 +14638,7 @@
 CVE-2017-11884 (Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-11883 (.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to ...)
-	TODO: check with Debian mono maintainers
+	NOT-FOR-US: .NET core
 CVE-2017-11882 (Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-11881
@@ -14864,7 +14864,7 @@
 CVE-2017-11771 (The Microsoft Windows Search component on Microsoft Windows Server ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-11770 (.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to ...)
-	TODO: check with Debian mono maintainers
+	NOT-FOR-US: .NET Core
 CVE-2017-11769 (The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, ...)
 	NOT-FOR-US: Microsoft
 CVE-2017-11768 (Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 ...)




More information about the Secure-testing-commits mailing list