[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso carnil at debian.org
Sat Jun 29 21:18:31 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3f917c02 by Salvatore Bonaccorso at 2019-06-29T20:18:09Z
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,25 +1,25 @@
 CVE-2019-13055 (Certain Logitech Unifying devices allow attackers to dump AES keys and ...)
-	TODO: check
+	NOT-FOR-US: Logitech
 CVE-2019-13054 (The Logitech R500 presentation clicker allows attackers to determine t ...)
-	TODO: check
+	NOT-FOR-US: Logitech
 CVE-2019-13053 (Logitech Unifying devices allow keystroke injection, bypassing encrypt ...)
-	TODO: check
+	NOT-FOR-US: Logitech
 CVE-2019-13052 (Logitech Unifying devices allow live decryption if the pairing of a ke ...)
-	TODO: check
+	NOT-FOR-US: Logitech
 CVE-2019-13051
 	RESERVED
 CVE-2019-13050 (Interaction between the sks-keyserver code through 1.2.0 of the SKS ke ...)
 	TODO: check
 CVE-2019-13049 (An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows user ...)
-	TODO: check
+	NOT-FOR-US: ToaruOS
 CVE-2019-13048 (kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of serv ...)
-	TODO: check
+	NOT-FOR-US: ToaruOS
 CVE-2019-13047 (kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access co ...)
-	TODO: check
+	NOT-FOR-US: ToaruOS
 CVE-2019-13046 (linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH ...)
-	TODO: check
+	NOT-FOR-US: ToaruOS
 CVE-2019-13044 (An insecure login process was discovered in Panduit IntraVUE before 3. ...)
-	TODO: check
+	NOT-FOR-US: Panduit
 CVE-2019-13043
 	RESERVED
 CVE-2019-13042
@@ -37,11 +37,11 @@ CVE-2019-13037
 CVE-2019-13036
 	RESERVED
 CVE-2019-13035 (Artica Pandora FMS 7.0 NG before 735 suffers from local privilege esca ...)
-	TODO: check
+	NOT-FOR-US: Artica Pandora FMS
 CVE-2019-13034
 	RESERVED
 CVE-2016-10761 (Logitech Unifying devices before 2016-02-26 allow keystroke injection, ...)
-	TODO: check
+	NOT-FOR-US: Logitech
 CVE-2019-13045 (Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when S ...)
 	- irssi <unfixed> (bug #931264)
 	NOTE: https://irssi.org/security/irssi_sa_2019_06.txt



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/3f917c0221fc107d9cff77980e470b92d18fefa5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/3f917c0221fc107d9cff77980e470b92d18fefa5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190629/0fc7dd60/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list