[Git][security-tracker-team/security-tracker][master] bullseye triage

Moritz Muehlenhoff jmm at debian.org
Sun Dec 13 18:55:57 GMT 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8986421e by Moritz Mühlenhoff at 2020-12-13T19:55:38+01:00
bullseye triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35308,6 +35308,7 @@ CVE-2019-20907 (In Lib/tarfile.py in Python through 3.8.3, an attacker is able t
 	[buster] - python3.7 3.7.3-2+deb10u2
 	- python3.5 <removed> (low)
 	- python2.7 <unfixed> (low; bug #970099)
+	[bullseye] - python2.7 <ignored> (Python 2 not covered by security support)
 	[buster] - python2.7 <no-dsa> (Minor issue)
 	[stretch] - python2.7 <postponed> (Minor issue, can be fixed in next DLA)
 	NOTE: https://bugs.python.org/issue39017
@@ -55607,6 +55608,7 @@ CVE-2020-8492 (Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10,
 	- python3.4 <removed>
 	[jessie] - python3.4 <postponed> (Minor issue)
 	- python2.7 <unfixed> (low; bug #970099)
+	[bullseye] - python2.7 <ignored> (Python 2 not covered by security support)
 	[buster] - python2.7 <no-dsa> (Minor issue)
 	[stretch] - python2.7 <no-dsa> (Minor issue)
 	[jessie] - python2.7 <no-dsa> (Minor issue)
@@ -116315,12 +116317,14 @@ CVE-2015-9281 (Logon Manager in SAS Web Infrastructure Platform before 9.4M3 all
 	NOT-FOR-US: SAS Web Infrastructure Platform
 CVE-2019-6462 (An issue was discovered in cairo 1.16.0. There is an infinite loop in  ...)
 	- cairo <unfixed> (low; bug #929945)
+	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
 	[jessie] - cairo <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/cairo/cairo/issues/353
 CVE-2019-6461 (An issue was discovered in cairo 1.16.0. There is an assertion problem ...)
 	- cairo <unfixed> (low; bug #929944)
+	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
 	[jessie] - cairo <no-dsa> (Minor issue)
@@ -138402,6 +138406,7 @@ CVE-2018-18065 (_set_key in agent/helpers/table_container.c in Net-SNMP before 5
 	NOTE: https://sourceforge.net/p/net-snmp/code/ci/7ffb8e25a0db851953155de91f0170e9bf8c457d/
 CVE-2018-18064 (cairo through 1.15.14 has an out-of-bounds stack-memory write during p ...)
 	- cairo <unfixed> (low; bug #916083)
+	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
 	[jessie] - cairo <no-dsa> (Minor issue)
@@ -209316,6 +209321,7 @@ CVE-2017-9815 (In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libt
 	NOTE: The issue is addressed with the same commit as for CVE-2017-9403
 CVE-2017-9814 (cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote atta ...)
 	- cairo <unfixed> (low; bug #868580)
+	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
 	[jessie] - cairo <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8986421ee96706d3fa961609f1ac13d3dd2e6878

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8986421ee96706d3fa961609f1ac13d3dd2e6878
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201213/53a10e8b/attachment.html>


More information about the debian-security-tracker-commits mailing list