[Git][security-tracker-team/security-tracker][master] 3 commits: Update CVE-2019-20477 status
Scott Kitterman
kitterman at debian.org
Tue Mar 3 14:11:09 GMT 2020
Scott Kitterman pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fc16a25c by Scott Kitterman at 2020-03-03T09:09:35-05:00
Update CVE-2019-20477 status
- - - - -
bce286e8 by Scott Kitterman at 2020-03-03T09:09:57-05:00
Merge branch 'master' of salsa.debian.org:security-tracker-team/security-tracker
- - - - -
29947ea4 by Scott Kitterman at 2020-03-03T09:10:40-05:00
Merge branch 'master' of salsa.debian.org:security-tracker-team/security-tracker
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1646,7 +1646,10 @@ CVE-2019-20478 (In ruamel.yaml through 0.16.7, the load method allows remote cod
NOTE: various CVE IDs have been assigned to applications misusing the API over the years.
NOTE: pyyaml 5.1 changed the default hebaviour
CVE-2019-20477 (PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and ...)
- - pyyaml <unfixed> (unimportant)
+ - pyyaml 5.2-1
+ [buster] - pyyaml <not-affected> (Vulnerability introduced in 5.1)
+ [stretch] - pyyaml <not-affected> (Vulnerability introduced in 5.1)
+ [jessie] - pyyaml <not-affected> (Vulnerability introduced in 5.1)
NOTE: CVE exists due to an incomplete fix for CVE-2017-18342.
CVE-2019-20476
RESERVED
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9645ea8a5dc74b359d39e83c912887368260c4bf...29947ea46d6eb5ca8d0fa8a0322e386bacdb9e3c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9645ea8a5dc74b359d39e83c912887368260c4bf...29947ea46d6eb5ca8d0fa8a0322e386bacdb9e3c
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200303/aecae7ac/attachment.html>
More information about the debian-security-tracker-commits
mailing list