[Git][security-tracker-team/security-tracker][master] bugnums
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 9 22:37:35 BST 2021
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
16caa251 by Moritz Mühlenhoff at 2021-08-09T23:36:57+02:00
bugnums
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -247,11 +247,12 @@ CVE-2021-38189 (An issue was discovered in the lettre crate before 0.9.6 for Rus
CVE-2021-38188 (An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. ...)
NOT-FOR-US: Rust crate iced-x86
CVE-2021-38187 (An issue was discovered in the anymap crate through 0.12.1 for Rust. I ...)
- TODO: check
+ - rust-anymap <unfixed> (bug #992046)
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2021-0065.html
CVE-2021-38186 (An issue was discovered in the comrak crate before 0.10.1 for Rust. It ...)
NOT-FOR-US: Rust crate comrak
CVE-2021-38185 (GNU cpio through 2.13 allows attackers to execute arbitrary code via a ...)
- - cpio <unfixed>
+ - cpio <unfixed> (bug #992045)
NOTE: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b
NOTE: https://github.com/fangqyi/cpiopwn
NOTE: https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html
@@ -283,7 +284,8 @@ CVE-2021-3689
CVE-2020-36472 (An issue was discovered in the max7301 crate before 0.2.0 for Rust. Th ...)
NOT-FOR-US: Rust crate max7301
CVE-2020-36471 (An issue was discovered in the generator crate before 0.7.0 for Rust. ...)
- TODO: check
+ - rust-generator <unfixed> (bug #992047)
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2020-0151.html
CVE-2020-36470 (An issue was discovered in the disrustor crate through 2020-12-17 for ...)
NOT-FOR-US: Rust crate disrustor
CVE-2020-36469 (An issue was discovered in the appendix crate through 2020-11-15 for R ...)
@@ -295,7 +297,8 @@ CVE-2020-36467 (An issue was discovered in the cgc crate through 2020-12-10 for
CVE-2020-36466 (An issue was discovered in the cgc crate through 2020-12-10 for Rust. ...)
NOT-FOR-US: Rust crate cgc
CVE-2020-36465 (An issue was discovered in the generic-array crate before 0.13.3 for R ...)
- TODO: check
+ - rust-generic-array 0.14.4-1
+ NOTE: https://rustsec.org/advisories/RUSTSEC-2020-0146.html
CVE-2020-36464 (An issue was discovered in the heapless crate before 0.6.1 for Rust. T ...)
NOT-FOR-US: Rust crate heapless
CVE-2020-36463 (An issue was discovered in the multiqueue crate through 2020-12-25 for ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16caa251fae0e90c189fc668c3c2134f75068089
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16caa251fae0e90c189fc668c3c2134f75068089
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210809/4f3c4b69/attachment.htm>
More information about the debian-security-tracker-commits
mailing list