[Git][security-tracker-team/security-tracker][master] Process two NFUs

Salvatore Bonaccorso carnil at debian.org
Sat Jan 12 20:49:57 GMT 2019


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6b37f64f by Salvatore Bonaccorso at 2019-01-12T20:49:16Z
Process two NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -325,7 +325,7 @@ CVE-2018-20684 (In WinSCP before 5.14 beta, due to missing validation, the scp .
 CVE-2017-1002157 (modulemd 1.3.1 and earlier uses an unsafe function for processing ...)
 	TODO: check
 CVE-2017-1002152 (Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting ...)
-	TODO: check
+	NOT-FOR-US: Bodhi
 CVE-2019-6108
 	RESERVED
 CVE-2019-6107
@@ -5119,7 +5119,7 @@ CVE-2019-3804 [Crash when parsing invalid base64 headers]
 	NOTE: https://github.com/cockpit-project/cockpit/pull/10819
 	NOTE: https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12
 CVE-2019-3803 (Pivotal Concourse, all versions prior to 4.2.2, puts the user access ...)
-	TODO: check
+	NOT-FOR-US: Pivotal Concourse
 CVE-2019-3802
 	RESERVED
 CVE-2019-3801



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/6b37f64f5977bbcb09682b9f6b53ca89bb810092

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/6b37f64f5977bbcb09682b9f6b53ca89bb810092
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190112/c4f183cb/attachment.html>


More information about the debian-security-tracker-commits mailing list