[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso carnil at debian.org
Sat Nov 21 08:10:31 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
002d7587 by security tracker role at 2020-11-21T08:10:24+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2455,7 +2455,7 @@ CVE-2020-28362 (Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Serv
 	[stretch] - golang-1.7 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ
 	NOTE: https://github.com/golang/go/issues/42552
-CVE-2020-28974 [slab-out-of-bounds Read in fbcon]
+CVE-2020-28974 (A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 co ...)
 	- linux 5.9.9-1
 	NOTE: https://git.kernel.org/linus/3c4e0dff2095c579b142d5a0693257f1c58b4804
 	NOTE: https://www.openwall.com/lists/oss-security/2020/11/09/2
@@ -10330,8 +10330,7 @@ CVE-2020-25727 (The Reset Password add-on before 1.2.0 for Alfresco suffers from
 	NOT-FOR-US: Reset Password add-on for Alfresco
 CVE-2020-25726
 	REJECTED
-CVE-2020-25725
-	RESERVED
+CVE-2020-25725 (In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOut ...)
 	- xpdf <not-affected> (Debian uses poppler, which is not affected)
 	NOTE: https://forum.xpdfreader.com/viewtopic.php?f=3&t=41915
 CVE-2020-25724
@@ -11701,8 +11700,8 @@ CVE-2020-25187
 	RESERVED
 CVE-2020-25186 (An XXE vulnerability exists within LeviStudioU Release Build 2019-09-2 ...)
 	NOT-FOR-US: LeviStudioU Release
-CVE-2020-25185
-	RESERVED
+CVE-2020-25185 (The affected product is vulnerable to five post-authentication buffer  ...)
+	TODO: check
 CVE-2020-25184
 	RESERVED
 CVE-2020-25183
@@ -50792,7 +50791,7 @@ CVE-2020-8825 (index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows
 	NOT-FOR-US: Vanilla Forums
 CVE-2020-8824 (Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name ...)
 	NOT-FOR-US: Hitron devices
-CVE-2020-8823 (htmlfile in lib/transport/htmlfile.js in SockJS before 3.0 is vulnerab ...)
+CVE-2020-8823 (htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulner ...)
 	NOT-FOR-US: SockJS
 CVE-2020-8822 (Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices  ...)
 	NOT-FOR-US: Digi TransPort
@@ -58472,8 +58471,8 @@ CVE-2020-5799
 	RESERVED
 CVE-2020-5798
 	RESERVED
-CVE-2020-5797
-	RESERVED
+CVE-2020-5797 (UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180 ...)
+	TODO: check
 CVE-2020-5796 (Improper preservation of permissions in Nagios XI 5.7.4 allows a local ...)
 	NOT-FOR-US: Nagios XI
 CVE-2020-5795 (UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/002d7587967b8b8c888ec4da9422b581e7bd64f6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/002d7587967b8b8c888ec4da9422b581e7bd64f6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201121/c69ce4d8/attachment.html>


More information about the debian-security-tracker-commits mailing list