[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff jmm at debian.org
Fri May 15 08:55:25 BST 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2d4fef9 by Moritz Muehlenhoff at 2020-05-15T09:54:45+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5364,11 +5364,11 @@ CVE-2020-11075
 CVE-2020-11074
 	RESERVED
 CVE-2020-11073 (In Autoswitch Python Virtualenv before version 0.16.0, a user who ente ...)
-	TODO: check
+	NOT-FOR-US: zsh-autoswitch-virtualenv
 CVE-2020-11072 (In SLP Validate (npm package slp-validate) before version 1.2.1, users ...)
-	TODO: check
+	NOT-FOR-US: Node slp-validate
 CVE-2020-11071 (SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability w ...)
-	TODO: check
+	NOT-FOR-US: Node slpjs
 CVE-2020-11070 (The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulne ...)
 	NOT-FOR-US: TYPO3
 CVE-2020-11069 (In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has be ...)
@@ -10798,7 +10798,7 @@ CVE-2020-8901
 CVE-2020-8900
 	RESERVED
 CVE-2020-8899 (There is a buffer overwrite vulnerability in the Quram qmg library of  ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2020-8898
 	RESERVED
 CVE-2020-8897
@@ -12489,13 +12489,13 @@ CVE-2020-8158
 CVE-2020-8157 (UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Ke ...)
 	NOT-FOR-US: UniFi Cloud Key
 CVE-2020-8156 (A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Mail
 CVE-2020-8155 (An outdated 3rd party library in the Files PDF viewer for Nextcloud Se ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2020-8154 (An Insecure direct object reference vulnerability in Nextcloud Server  ...)
-	TODO: check
+	- nextcloud-server <itp> (bug #941708)
 CVE-2020-8153 (Improper access control in Groupfolders app 4.0.3 allowed to delete hi ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Groupfolders app
 CVE-2020-8152
 	RESERVED
 CVE-2020-8151 (There is a possible information disclosure issue in Active Resource &l ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2d4fef9678aa4bad7a23f27510a150c96456897

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2d4fef9678aa4bad7a23f27510a150c96456897
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200515/1d354bc0/attachment.html>


More information about the debian-security-tracker-commits mailing list