[Git][security-tracker-team/security-tracker][master] bugnums

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 9 22:37:35 BST 2021



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
16caa251 by Moritz Mühlenhoff at 2021-08-09T23:36:57+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -247,11 +247,12 @@ CVE-2021-38189 (An issue was discovered in the lettre crate before 0.9.6 for Rus
 CVE-2021-38188 (An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. ...)
 	NOT-FOR-US: Rust crate iced-x86
 CVE-2021-38187 (An issue was discovered in the anymap crate through 0.12.1 for Rust. I ...)
-	TODO: check
+	- rust-anymap <unfixed> (bug #992046)
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2021-0065.html
 CVE-2021-38186 (An issue was discovered in the comrak crate before 0.10.1 for Rust. It ...)
 	NOT-FOR-US: Rust crate comrak
 CVE-2021-38185 (GNU cpio through 2.13 allows attackers to execute arbitrary code via a ...)
-	- cpio <unfixed>
+	- cpio <unfixed> (bug #992045)
 	NOTE: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b
 	NOTE: https://github.com/fangqyi/cpiopwn
 	NOTE: https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html
@@ -283,7 +284,8 @@ CVE-2021-3689
 CVE-2020-36472 (An issue was discovered in the max7301 crate before 0.2.0 for Rust. Th ...)
 	NOT-FOR-US: Rust crate max7301
 CVE-2020-36471 (An issue was discovered in the generator crate before 0.7.0 for Rust.  ...)
-	TODO: check
+	- rust-generator <unfixed> (bug #992047)
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2020-0151.html
 CVE-2020-36470 (An issue was discovered in the disrustor crate through 2020-12-17 for  ...)
 	NOT-FOR-US: Rust crate disrustor
 CVE-2020-36469 (An issue was discovered in the appendix crate through 2020-11-15 for R ...)
@@ -295,7 +297,8 @@ CVE-2020-36467 (An issue was discovered in the cgc crate through 2020-12-10 for
 CVE-2020-36466 (An issue was discovered in the cgc crate through 2020-12-10 for Rust.  ...)
 	NOT-FOR-US: Rust crate cgc
 CVE-2020-36465 (An issue was discovered in the generic-array crate before 0.13.3 for R ...)
-	TODO: check
+	- rust-generic-array 0.14.4-1
+	NOTE: https://rustsec.org/advisories/RUSTSEC-2020-0146.html
 CVE-2020-36464 (An issue was discovered in the heapless crate before 0.6.1 for Rust. T ...)
 	NOT-FOR-US: Rust crate heapless
 CVE-2020-36463 (An issue was discovered in the multiqueue crate through 2020-12-25 for ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16caa251fae0e90c189fc668c3c2134f75068089

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16caa251fae0e90c189fc668c3c2134f75068089
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210809/4f3c4b69/attachment.htm>


More information about the debian-security-tracker-commits mailing list