[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Wed Oct 14 09:20:39 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
27e95c4f by Salvatore Bonaccorso at 2020-10-14T10:20:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31125,7 +31125,7 @@ CVE-2020-12935
 CVE-2020-12934
 	RESERVED
 CVE-2020-12933 (A denial of service vulnerability exists in the D3DKMTEscape handler f ...)
-	TODO: check
+	NOT-FOR-US: AMD ATIKMDAG.SYS
 CVE-2020-12932
 	RESERVED
 CVE-2020-12931
@@ -31169,7 +31169,7 @@ CVE-2020-12913
 CVE-2020-12912
 	RESERVED
 CVE-2020-12911 (A denial of service vulnerability exists in the D3DKMTCreateAllocation ...)
-	TODO: check
+	NOT-FOR-US: AMD ATIKMDAG.SYS
 CVE-2020-12910
 	RESERVED
 CVE-2020-12909
@@ -42459,7 +42459,7 @@ CVE-2020-9092
 CVE-2020-9091 (Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out ...)
 	NOT-FOR-US: Huawei
 CVE-2020-9090 (FusionAccess version 6.5.1 has an improper authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2020-9089
 	RESERVED
 CVE-2020-9088
@@ -46222,7 +46222,7 @@ CVE-2020-7592 (A vulnerability has been identified in SIMATIC HMI Basic Panels 1
 CVE-2020-7591
 	RESERVED
 CVE-2020-7590 (A vulnerability has been identified in DCA Vantage Analyzer (All versi ...)
-	TODO: check
+	NOT-FOR-US: DCA Vantage Analyzer
 CVE-2020-7589 (A vulnerability has been identified in LOGO!8 BM (incl. SIPLUS variant ...)
 	NOT-FOR-US: Siemens
 CVE-2020-7588 (A vulnerability has been identified in Opcenter Execution Discrete (Al ...)
@@ -52595,27 +52595,27 @@ CVE-2020-5145
 CVE-2020-5144
 	RESERVED
 CVE-2020-5143 (SonicOS SSLVPN login page allows a remote unauthenticated attacker to  ...)
-	TODO: check
+	NOT-FOR-US: SonicOS SSLVPN
 CVE-2020-5142 (A stored cross-site scripting (XSS) vulnerability exists in the SonicO ...)
-	TODO: check
+	NOT-FOR-US: SonicOS SSLVPN
 CVE-2020-5141 (A vulnerability in SonicOS allows a remote unauthenticated attacker to ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5140 (A vulnerability in SonicOS allows a remote unauthenticated attacker to ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5139 (A vulnerability in SonicOS SSLVPN service allows a remote unauthentica ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5138 (A Heap Overflow vulnerability in the SonicOS allows a remote unauthent ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5137 (A buffer overflow vulnerability in SonicOS allows a remote unauthentic ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5136 (A buffer overflow vulnerability in SonicOS allows an authenticated att ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5135 (A buffer overflow vulnerability in SonicOS allows a remote attacker to ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5134 (A vulnerability in SonicOS allows an authenticated attacker to cause o ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5133 (A vulnerability in SonicOS allows a remote unauthenticated attacker to ...)
-	TODO: check
+	NOT-FOR-US: SonicOS
 CVE-2020-5132 (SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misc ...)
 	NOT-FOR-US: SonicWall
 CVE-2020-5131 (SonicWall NetExtender Windows client vulnerable to arbitrary file writ ...)
@@ -70965,7 +70965,7 @@ CVE-2019-17446 (An issue was discovered in Eracent EPA Agent through 10.2.26. Th
 CVE-2019-17445 (An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Ag ...)
 	NOT-FOR-US: Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent
 CVE-2019-17444 (Jfrog Artifactory uses default passwords (such as "password") for admi ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2019-17443
 	RESERVED
 CVE-2019-17442



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27e95c4f216744c4e138a3ff354486206a0ccb7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27e95c4f216744c4e138a3ff354486206a0ccb7d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201014/cebad721/attachment.html>


More information about the debian-security-tracker-commits mailing list