[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff jmm at debian.org
Fri Oct 25 08:20:29 BST 2019



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
96e4b2ef by Moritz Muehlenhoff at 2019-10-25T07:19:59Z
NFUs
linux, osc n/a

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4414,8 +4414,7 @@ CVE-2019-16923 (kkcms 1.3 has jx.php?url= XSS. ...)
 CVE-2019-16922 (SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows uninten ...)
 	NOT-FOR-US: SuiteCRM
 CVE-2019-16921 (In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/in ...)
-	- linux <undetermined>
-	TODO: check, see kernel-sec
+	- linux <not-affected> (Did not affect any released kernel)
 CVE-2019-16920 (Unauthenticated remote code execution occurs in D-Link products such a ...)
 	NOT-FOR-US: D-Link
 CVE-2019-16928 (Exim 4.92 through 4.92.2 allows remote code execution, a different vul ...)
@@ -28108,7 +28107,7 @@ CVE-2019-9292 (In the Activity Manager service, there is a possible information
 CVE-2019-9291 (In Bluetooth, there is a possible remote code execution due to an impr ...)
 	NOT-FOR-US: Android
 CVE-2019-9290 (In tzdata there is possible memory corruption due to a mismatch betwee ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2019-9289 (In Bluetooth, there is a possible out of bounds read due to a missing  ...)
 	NOT-FOR-US: Android
 CVE-2019-9288 (In libhidcommand_jni, there is a possible out of bounds write due to a ...)
@@ -28134,7 +28133,7 @@ CVE-2019-9279 (In the wifi hotspot service, there is a possible denial of servic
 CVE-2019-9278 (In libexif, there is a possible out of bounds write due to an integer  ...)
 	TODO: check
 CVE-2019-9277 (In the proc filesystem, there is a possible information disclosure due ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2019-9276 (In the Android kernel in the synaptics_dsx_htc touchscreen driver ther ...)
 	NOT-FOR-US: Android kernel
 CVE-2019-9275 (In the Android kernel in the mnh driver there is a use after free due  ...)
@@ -28221,9 +28220,9 @@ CVE-2019-9236 (In NFC, there is a possible out of bounds read due to a missing b
 CVE-2019-9235 (In NFC, there is a possible out of bounds read due to a missing bounds ...)
 	NOT-FOR-US: Android
 CVE-2019-9234 (In wpa_supplicant_8, there is a possible out of bounds read due to a m ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2019-9233 (In wpa_supplicant_8, there is a possible out of bounds read due to an  ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2019-9232 (In libvpx, there is a possible out of bounds read due to a missing bou ...)
 	TODO: check
 CVE-2019-9231 (An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M80 ...)
@@ -42024,8 +42023,7 @@ CVE-2019-3686
 	RESERVED
 CVE-2019-3685 [Fails to adequately verify TLS certificates allowing for a man in the middle attack]
 	RESERVED
-	- osc <undetermined> (bug #941667)
-	TODO: check, might affect only 0.165.0 through 0.165.2, but not earlier versions
+	- osc <not-affected> (Affects 0.165.x only, bug #941667)
 CVE-2019-3684 (SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a71 ...)
 	NOT-FOR-US: SUSE Manager
 CVE-2019-3683



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/96e4b2ef89c2d589be1cf4853c37bb1b26d9a92b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/96e4b2ef89c2d589be1cf4853c37bb1b26d9a92b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191025/7cad07dc/attachment.html>


More information about the debian-security-tracker-commits mailing list