[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Wed Jul 31 21:31:48 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9873096c by Salvatore Bonaccorso at 2019-07-31T20:31:13Z
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -163,7 +163,7 @@ CVE-2018-20874
 CVE-2018-20873
 	RESERVED
 CVE-2018-20872 (DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or  ...)
-	TODO: check
+	NOT-FOR-US: DrayTek routers
 CVE-2017-18482
 	RESERVED
 CVE-2017-18481
@@ -571,7 +571,7 @@ CVE-2019-14447
 CVE-2019-14446
 	RESERVED
 CVE-2007-6763 (SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, w ...)
-	TODO: check
+	NOT-FOR-US: SAS Drug Development (SDD)
 CVE-2019-14445
 	RESERVED
 CVE-2019-14444 (apply_relocations in readelf.c in GNU Binutils 2.32 contains an intege ...)
@@ -1003,7 +1003,7 @@ CVE-2019-1020013 (parse-server before 3.6.0 allows account enumeration. ...)
 CVE-2019-1020012 (parse-server before 3.4.1 allows DoS after any POST to a volatile clas ...)
 	TODO: check
 CVE-2019-1020011 (SmokeDetector intentionally does automatic deployments of updated copi ...)
-	TODO: check
+	NOT-FOR-US: SmokeDetector
 CVE-2019-1020010 (Misskey before 10.102.4 allows hijacking a user's token. ...)
 	TODO: check
 CVE-2019-1020009 (Fleet before 2.1.2 allows exposure of SMTP credentials. ...)
@@ -4629,7 +4629,7 @@ CVE-2019-13128 (An issue was discovered on D-Link DIR-823G devices with firmware
 CVE-2019-13127 (An issue was discovered in mxGraph through 4.0.0, related to the "draw ...)
 	NOT-FOR-US: mxGraph
 CVE-2019-13126 (An integer overflow in NATS Server 2.0.0 allows a remote attacker to c ...)
-	TODO: check
+	NOT-FOR-US: NATS Server
 CVE-2019-13125 (HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evad ...)
 	NOT-FOR-US: Tencent
 CVE-2019-13124
@@ -4912,7 +4912,7 @@ CVE-2019-13028 (An incorrect implementation of a local web server in eID client
 CVE-2019-13027 (Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has S ...)
 	NOT-FOR-US: Realization Concerto Critical Chain Planner
 CVE-2019-13026 (OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Inject ...)
-	TODO: check
+	NOT-FOR-US: OXID eShop
 CVE-2019-13025
 	RESERVED
 CVE-2019-13024 (Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web be ...)
@@ -5535,7 +5535,7 @@ CVE-2019-12799 (In createInstanceFromNamedArguments in Shopware through 5.6.x, a
 CVE-2019-12798 (An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c do ...)
 	NOT-FOR-US: MuJS
 CVE-2019-12797 (A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN ...)
-	TODO: check
+	NOT-FOR-US: ELM327 OBD2 Bluetooth device
 CVE-2019-12796
 	RESERVED
 CVE-2019-12795 (daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x bef ...)
@@ -5688,7 +5688,7 @@ CVE-2019-12752
 CVE-2019-12751 (Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a p ...)
 	NOT-FOR-US: Symantec
 CVE-2019-12750 (Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 an ...)
-	TODO: check
+	NOT-FOR-US: Symantec Endpoint Protection
 CVE-2019-12749 (dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, ...)
 	{DSA-4462-1 DLA-1818-1}
 	- dbus 1.12.16-1 (bug #930375)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9873096c4462c8e26ca4c8d9ede43448a560f318

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/9873096c4462c8e26ca4c8d9ede43448a560f318
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190731/bfa14995/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list