[Git][security-tracker-team/security-tracker][master] asked for rejection of CVE-2020-0487

Moritz Muehlenhoff jmm at debian.org
Wed Dec 16 09:47:59 GMT 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2be9f3ac by Moritz Muehlenhoff at 2020-12-16T10:47:37+01:00
asked for rejection of CVE-2020-0487

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -80441,12 +80441,7 @@ CVE-2020-0489 (In Parse_data of eas_mdls.c, there is a possible out of bounds wr
 CVE-2020-0488 (In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse ...)
 	NOT-FOR-US: Android media framework
 CVE-2020-0487 (In read_metadata_vorbiscomment_ of stream_decoder.c, there is possible ...)
-	- flac 1.3.2-2 (low; bug #897015)
-	[stretch] - flac <no-dsa> (Minor issue)
-	NOTE: https://github.com/xiph/flac/commit/4f47b63e9c971e6391590caf00a0f2a5ed612e67
-	NOTE: https://android.googlesource.com/platform/external/flac/+/706c378d541b5e54b108e06a863065d603433b54
-	NOTE: https://source.android.com/security/bulletin/pixel/2020-12-01
-	NOTE: Duplicate of CVE-2017-6888, should be rejected
+	NOTE: Duplicate of CVE-2017-6888, requested rejection
 CVE-2020-0486 (In openAssetFileListener of ContactsProvider2.java, there is a possibl ...)
 	TODO: check
 CVE-2020-0485 (In areFunctionsSupported of UsbBackend.java, there is a possible acces ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2be9f3ac3b969c14ea7e17ecd8d361591b035b9f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2be9f3ac3b969c14ea7e17ecd8d361591b035b9f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201216/6c4f3a31/attachment.html>


More information about the debian-security-tracker-commits mailing list