[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Fri Nov 20 21:02:09 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
610182f2 by Salvatore Bonaccorso at 2020-11-20T22:01:35+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -228,7 +228,7 @@ CVE-2020-28879
 CVE-2020-28878
 	RESERVED
 CVE-2020-28877 (Buffer overflow in in the copy_msg_element function for the devDiscove ...)
-	TODO: check
+	NOT-FOR-US: TP-Link
 CVE-2020-28876
 	RESERVED
 CVE-2020-28875
@@ -292,7 +292,7 @@ CVE-2020-28847
 CVE-2020-28846
 	RESERVED
 CVE-2020-28845 (A CSV injection vulnerability in the Admin portal for Netskope 75.0 al ...)
-	TODO: check
+	NOT-FOR-US: Admin portal for Netskope
 CVE-2020-28844
 	RESERVED
 CVE-2020-28843
@@ -4272,11 +4272,11 @@ CVE-2020-28215
 CVE-2020-28214
 	RESERVED
 CVE-2020-28213 (A CWE-494: Download of Code Without Integrity Check vulnerability exis ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Control Expert
 CVE-2020-28212 (A CWE-307: Improper Restriction of Excessive Authentication Attempts v ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Control Expert
 CVE-2020-28211 (A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulat ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Control Expert
 CVE-2020-28210 (A CWE-79 Improper Neutralization of Input During Web Page Generation ( ...)
 	NOT-FOR-US: EcoStruxure Building Operation WebStation
 CVE-2020-28209 (A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStru ...)
@@ -10037,7 +10037,7 @@ CVE-2020-25841
 CVE-2020-25840
 	RESERVED
 CVE-2020-25839 (NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected b ...)
-	TODO: check
+	NOT-FOR-US: NetIQ Identity Manager
 CVE-2020-25838
 	RESERVED
 CVE-2020-25837 (Sensitive information disclosure vulnerability in Micro Focus Self Ser ...)
@@ -53983,7 +53983,7 @@ CVE-2020-7561 (A CWE-284: Improper Access Control vulnerability exists in Easerg
 CVE-2020-7560
 	RESERVED
 CVE-2020-7559 (A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Control Expert
 CVE-2020-7558 (A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition  ...)
 	NOT-FOR-US: IGSS Definition (Def.exe)
 CVE-2020-7557 (A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition ( ...)
@@ -54013,7 +54013,7 @@ CVE-2020-7546
 CVE-2020-7545
 	RESERVED
 CVE-2020-7544 (A CWE-269 Improper Privilege Management vulnerability exists in EcoStr ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Operator Terminal Expert runtime
 CVE-2020-7543
 	RESERVED
 CVE-2020-7542
@@ -54025,7 +54025,7 @@ CVE-2020-7540
 CVE-2020-7539
 	RESERVED
 CVE-2020-7538 (A CWE-754: Improper Check for Unusual or Exceptional Conditions vulner ...)
-	TODO: check
+	NOT-FOR-US: EcoStruxure Control Expert
 CVE-2020-7537
 	RESERVED
 CVE-2020-7536
@@ -62768,9 +62768,9 @@ CVE-2020-4007
 CVE-2020-4006
 	RESERVED
 CVE-2020-4005 (VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-2020111 ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2020-4004 (VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-2020111 ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2020-4003
 	RESERVED
 CVE-2020-4002



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/610182f28520cda44773aa0e1ef62b397a0bfe53

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/610182f28520cda44773aa0e1ef62b397a0bfe53
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201120/e678bc4d/attachment.html>


More information about the debian-security-tracker-commits mailing list