[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Dolibarr removed from unstable

Salvatore Bonaccorso carnil at debian.org
Sat Feb 24 08:00:06 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f482b166 by Salvatore Bonaccorso at 2018-02-24T08:59:29+01:00
Dolibarr removed from unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -3016,7 +3016,7 @@ CVE-2018-1000019 (OpenEMR version 5.0.0 contains a OS Command Injection vulnerab
 CVE-2017-1000510 (Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) ...)
 	NOT-FOR-US: Croogo
 CVE-2017-1000509 (Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) ...)
-	- dolibarr <unfixed>
+	- dolibarr <removed>
 	NOTE: https://github.com/Dolibarr/dolibarr/issues/7727
 CVE-2017-1000508 (Invoice Plane version 1.5.4 and earlier contains a Cross Site ...)
 	NOT-FOR-US: Invoice Plane
@@ -9406,7 +9406,7 @@ CVE-2017-1000501 (Awstats version 7.6 and earlier is vulnerable to a path traver
 CVE-2017-17972
 	RESERVED
 CVE-2017-17971 (The test_sql_and_script_inject function in htdocs/main.inc.php in ...)
-	- dolibarr <unfixed> (bug #885828)
+	- dolibarr <removed> (bug #885828)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/issues/8000
@@ -10024,23 +10024,23 @@ CVE-2017-17902
 CVE-2017-17901 (ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of ...)
 	NOT-FOR-US: ZyXEL
 CVE-2017-17900 (SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM ...)
-	- dolibarr <unfixed> (bug #885321)
+	- dolibarr <removed> (bug #885321)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/4a5988accbb770b74105baacd5a034689272128c
 CVE-2017-17899 (SQL injection vulnerability in adherents/subscription/info.php in ...)
-	- dolibarr <unfixed> (bug #885321)
+	- dolibarr <removed> (bug #885321)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/4a5988accbb770b74105baacd5a034689272128c
 CVE-2017-17898 (Dolibarr ERP/CRM version 6.0.4 does not block direct requests to ...)
-	- dolibarr <unfixed> (bug #885321)
+	- dolibarr <removed> (bug #885321)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/4a5988accbb770b74105baacd5a034689272128c
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/6a62e139604dbbd5729e57df2433b37a5950c35c
 CVE-2017-17897 (SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM ...)
-	- dolibarr <unfixed> (bug #885321)
+	- dolibarr <removed> (bug #885321)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/4a5988accbb770b74105baacd5a034689272128c
@@ -28399,27 +28399,27 @@ CVE-2017-14244 (An authentication bypass vulnerability on iBall Baton ADSL2+ Hom
 CVE-2017-14243 (An authentication bypass vulnerability on UTStar WA3002G4 ADSL ...)
 	NOT-FOR-US: UTStar
 CVE-2017-14242 (SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 ...)
-	- dolibarr <unfixed> (bug #885319)
+	- dolibarr <removed> (bug #885319)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/33e2179b65331d9d9179b59d746817c5be1fecdb
 CVE-2017-14241 (Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 ...)
-	- dolibarr <unfixed> (bug #885320)
+	- dolibarr <removed> (bug #885320)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/d26b2a694de30f95e46ea54ea72cc54f0d38e548
 CVE-2017-14240 (There is a sensitive information disclosure vulnerability in ...)
-	- dolibarr <unfixed> (bug #885320)
+	- dolibarr <removed> (bug #885320)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/d26b2a694de30f95e46ea54ea72cc54f0d38e548
 CVE-2017-14239 (Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM ...)
-	- dolibarr <unfixed> (bug #885320)
+	- dolibarr <removed> (bug #885320)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/d26b2a694de30f95e46ea54ea72cc54f0d38e548
 CVE-2017-14238 (SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM ...)
-	- dolibarr <unfixed> (bug #885320)
+	- dolibarr <removed> (bug #885320)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 	NOTE: https://github.com/Dolibarr/dolibarr/commit/d26b2a694de30f95e46ea54ea72cc54f0d38e548
@@ -39664,7 +39664,7 @@ CVE-2017-9841 (Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5
 	NOTE: https://github.com/sebastianbergmann/phpunit/commit/284a69fb88a2d0845d23f42974a583d8f59bf5a5
 	NOTE: http://phpunit.vulnbusters.com/
 CVE-2017-9840 (Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload ...)
-	- dolibarr <unfixed> (bug #867495)
+	- dolibarr <removed> (bug #867495)
 	[stretch] - dolibarr <no-dsa> (Minor issue)
 	[jessie] - dolibarr <no-dsa> (Minor issue)
 CVE-2017-9839



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/f482b166a879ca10acc572eca6bcc4522bfc1c9a

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/f482b166a879ca10acc572eca6bcc4522bfc1c9a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180224/e5755f94/attachment.html>


More information about the Secure-testing-commits mailing list