[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff jmm at debian.org
Wed Apr 17 22:19:26 BST 2019



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
735bb1cf by Moritz Muehlenhoff at 2019-04-17T21:19:02Z
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12052,7 +12052,7 @@ CVE-2019-6581
 CVE-2019-6580
 	RESERVED
 CVE-2019-6579 (A vulnerability has been identified in Spectrum Power™ 4 (with W ...)
-	TODO: check
+	NOT-FOR-US: Spectrum Power
 CVE-2019-6578
 	RESERVED
 CVE-2019-6577
@@ -12060,7 +12060,7 @@ CVE-2019-6577
 CVE-2019-6576
 	RESERVED
 CVE-2019-6575 (A vulnerability has been identified in SIMATIC CP443-1 OPC UA (All ver ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2019-6574
 	RESERVED
 CVE-2019-6573
@@ -12070,11 +12070,11 @@ CVE-2019-6572
 CVE-2019-6571
 	RESERVED
 CVE-2019-6570 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2019-6569 (A vulnerability has been identified in Scalance X-200 (All versions),  ...)
 	NOT-FOR-US: Scalance
 CVE-2019-6568 (A vulnerability has been identified in CP1604 (All versions), CP1616 ( ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2019-6567
 	RESERVED
 CVE-2019-6566
@@ -18481,7 +18481,7 @@ CVE-2019-3800
 CVE-2019-3799
 	RESERVED
 CVE-2019-3798 (Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0,  ...)
-	TODO: check
+	NOT-FOR-US: Cloud Foundry
 CVE-2019-3797
 	RESERVED
 CVE-2019-3796
@@ -18660,9 +18660,9 @@ CVE-2019-3711 (RSA Authentication Manager versions prior to 8.4 P1 contain an In
 CVE-2019-3710 (Dell Networking OS10 has been updated to address a vulnerability which ...)
 	NOT-FOR-US: Dell Networking OS10
 CVE-2019-3709 (IsilonSD Management Server 1.1.0 contains a cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: IsilonSD Management Server
 CVE-2019-3708 (IsilonSD Management Server 1.1.0 contains a cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: IsilonSD Management Server
 CVE-2019-3707
 	RESERVED
 CVE-2019-3706
@@ -30189,7 +30189,7 @@ CVE-2019-0165
 CVE-2019-0164
 	RESERVED
 CVE-2019-0163 (Insufficient input validation in system firmware for Intel(R) Broadwel ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2019-0162 (Memory access in virtual memory mapping for some microprocessors may a ...)
 	TODO: check
 CVE-2019-0161 (Stack overflow in XHCI for EDK II may allow an unauthenticated user to ...)
@@ -30210,7 +30210,7 @@ CVE-2019-0160 (Buffer overflow in system firmware for EDK II may allow unauthent
 CVE-2019-0159
 	RESERVED
 CVE-2019-0158 (Insufficient path checking in the installation package for Intel(R) Gr ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2019-0157
 	RESERVED
 CVE-2019-0156
@@ -33493,7 +33493,7 @@ CVE-2018-18096 (Improper memory handling in Intel QuickAssist Technology for Lin
 CVE-2018-18095
 	RESERVED
 CVE-2018-18094 (Improper directory permissions in installer for Intel(R) Media SDK bef ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2018-18093 (Improper file permissions in the installer for Intel VTune Amplifier 2 ...)
 	NOT-FOR-US: Intel VTune Amplifier
 CVE-2018-18092
@@ -37459,13 +37459,13 @@ CVE-2018-16563 (A vulnerability has been identified in Firmware variant IEC 6185
 CVE-2018-16562
 	REJECTED
 CVE-2018-16561 (A vulnerability has been identified in SIMATIC S7-300 CPUs (All versio ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-16560
 	REJECTED
 CVE-2018-16559 (A vulnerability has been identified in SIMATIC S7-1500 CPU (All versio ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-16558 (A vulnerability has been identified in SIMATIC S7-1500 CPU (All versio ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-16557 (A vulnerability has been identified in SIMATIC S7-400 (incl. F) V6 and ...)
 	NOT-FOR-US: Siemens
 CVE-2018-16556 (A vulnerability has been identified in SIMATIC S7-400 (incl. F) V6 and ...)
@@ -44627,11 +44627,11 @@ CVE-2018-13812 (A vulnerability has been identified in SIMATIC HMI Comfort Panel
 CVE-2018-13811 (A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (Al ...)
 	NOT-FOR-US: Siemens
 CVE-2018-13810 (A vulnerability has been identified in CP 1604 (All versions < V2.8 ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-13809 (A vulnerability has been identified in CP 1604 (All versions < V2.8 ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-13808 (A vulnerability has been identified in CP 1604 (All versions < V2.8 ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2018-13807 (A vulnerability has been identified in SCALANCE X300 (All versions &lt ...)
 	NOT-FOR-US: Siemens
 CVE-2018-13806 (A vulnerability has been identified in SIEMENS TD Keypad Designer (All ...)
@@ -52259,7 +52259,7 @@ CVE-2018-10961
 CVE-2018-10960
 	RESERVED
 CVE-2018-10959 (Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Un ...)
-	TODO: check
+	NOT-FOR-US: Avecto Defendpoint
 CVE-2018-10958 (In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT d ...)
 	{DSA-4238-1 DLA-1551-1 DLA-1402-1}
 	- exiv2 0.25-4
@@ -62014,7 +62014,7 @@ CVE-2018-7342
 CVE-2018-7341
 	RESERVED
 CVE-2018-7340 (Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the resu ...)
-	TODO: check
+	NOT-FOR-US: Duo Network Gateway
 CVE-2018-7339 (The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Ent ...)
 	- mp4v2 <removed> (low; bug #893544)
 	[stretch] - mp4v2 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/735bb1cfbb28a09f7c9ac6044dff4199dfb4f8e0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/735bb1cfbb28a09f7c9ac6044dff4199dfb4f8e0
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190417/0109848d/attachment.html>


More information about the debian-security-tracker-commits mailing list