[Git][security-tracker-team/security-tracker][master] buster triage

Moritz Muehlenhoff jmm at debian.org
Tue Apr 27 21:49:07 BST 2021



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1eca9933 by Moritz Muehlenhoff at 2021-04-27T22:48:07+02:00
buster triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -96,6 +96,7 @@ CVE-2021-31805
 	RESERVED
 CVE-2020-36325 (An issue was discovered in Jansson through 2.13.1. Due to a parsing er ...)
 	- jansson <unfixed>
+	[buster] - jansson <no-dsa> (Minor issue)
 	NOTE: https://github.com/akheron/jansson/issues/548
 CVE-2021-31826 (Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointe ...)
 	{DSA-4905-1}
@@ -104,9 +105,10 @@ CVE-2021-31826 (Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL
 	NOTE: https://issues.shibboleth.net/jira/browse/SSPCPP-927
 	NOTE: https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=5a47c3b9378f4c49392dd4d15189b70956f9f2ec
 CVE-2021-31804 (LeoCAD before 21.03 sometimes allows a use-after-free during the openi ...)
-	- leocad <unfixed>
+	- leocad <unfixed> (unimportant)
 	NOTE: https://github.com/leozide/leocad/issues/645
 	NOTE: https://github.com/leozide/leocad/commit/233affe3fcdc851fa82cb058871bddd0046e1c87
+	NOTE: Crash in CLI tool, no security impact
 CVE-2021-31803 (cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SE ...)
 	NOT-FOR-US: cPanel
 CVE-2021-31802 (NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow tha ...)
@@ -5252,6 +5254,7 @@ CVE-2021-29474 (HedgeDoc (formerly known as CodiMD) is an open-source collaborat
 	NOT-FOR-US: HedgeDoc
 CVE-2021-29473 (Exiv2 is a C++ library and a command-line utility to read, write, dele ...)
 	- exiv2 <unfixed>
+	[buster] - exiv2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-7569-phvm-vwc2
 	NOTE: https://github.com/github/advisory-review/pull/1587
 CVE-2021-29472



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1eca993365285fdcd7e1456e0fc366f9ca429711

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1eca993365285fdcd7e1456e0fc366f9ca429711
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210427/cd5816be/attachment.htm>


More information about the debian-security-tracker-commits mailing list