[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
carnil at debian.org
Sun Dec 13 20:10:37 GMT 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
27bec0a8 by security tracker role at 2020-12-13T20:10:30+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2020-35219
+ RESERVED
+CVE-2020-35218
+ RESERVED
+CVE-2020-35217
+ RESERVED
CVE-2020-XXXX [lxml sanitisng in math/svg, similar to CVE-2020-27783]
- lxml 4.6.2-1
[buster] - lxml 4.3.2-1+deb10u1
@@ -8978,7 +8984,7 @@ CVE-2020-27785
CVE-2020-27784
RESERVED
CVE-2020-27783 (A XSS vulnerability was discovered in python-lxml's clean module. The ...)
- {DLA-2467-1}
+ {DSA-4810-1 DLA-2467-1}
- lxml 4.6.1-1
NOTE: https://github.com/lxml/lxml/commit/89e7aad6e7ff9ecd88678ff25f885988b184b26e (lxml-4.6.1)
CVE-2020-27782
@@ -33054,10 +33060,12 @@ CVE-2020-16590 (A double free vulnerability exists in the Binary File Descriptor
NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c98a4545dc7bf2bcaf1de539c4eb84784680eaa4
NOTE: binutils not covered by security support
CVE-2020-16589 (A head-based buffer overflow exists in Academy Software Foundation Ope ...)
+ {DLA-2491-1}
- openexr 2.5.3-2
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/6bb36714528a9563dd3b92720c5063a1284b86f8 (v2.4.0-beta.1)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/issues/494
CVE-2020-16588 (A Null Pointer Deference issue exists in Academy Software Foundation O ...)
+ {DLA-2491-1}
- openexr 2.5.3-2
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/74504503cff86e986bac441213c403b0ba28d58f (v2.4.0-beta.1)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/issues/493
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27bec0a80d7d9309b4dc165470349305c7aabcea
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27bec0a80d7d9309b4dc165470349305c7aabcea
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201213/c33da8f9/attachment.html>
More information about the debian-security-tracker-commits
mailing list