[Git][security-tracker-team/security-tracker][master] two bogus CVE assignments for clementine
    Moritz Muehlenhoff (@jmm) 
    jmm at debian.org
       
    Thu Dec 16 08:18:24 GMT 2021
    
    
  
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
07f78f25 by Moritz Muehlenhoff at 2021-12-16T09:18:10+01:00
two bogus CVE assignments for clementine
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -14169,9 +14169,15 @@ CVE-2021-40829 (Connections initialized by the AWS IoT Device SDK v2 for Java (v
 CVE-2021-40828 (Connections initialized by the AWS IoT Device SDK v2 for Java (version ...)
 	NOT-FOR-US: AWS IoT Device SDK
 CVE-2021-40827 (Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used)  ...)
-	NOT-FOR-US: Clementine Music Player
+	- clementine <unfixed> (unimportant)
+	NOTE: https://voidsec.com/advisories/cve-2021-40827/
+	NOTE: Bogus report with hardly useful details whether affects clementine/gstreamer, but
+	NOTE: regardless just a crash in a CLI tool
 CVE-2021-40826 (Clementine Music Player through 1.3.1 is vulnerable to a User Mode Wri ...)
-	NOT-FOR-US: Clementine Music Player
+	- clementine <unfixed> (unimportant)
+	NOTE: https://voidsec.com/advisories/cve-2021-40827/
+	NOTE: Bogus report with hardly useful details whether affects clementine/gstreamer, but
+	NOTE: regardless just a crash in a CLI tool
 CVE-2021-40825 (nLight ECLYPSE (nECY) system Controllers running software prior to 1.1 ...)
 	NOT-FOR-US: nLight ECLYPSE (nECY) system Controllers
 CVE-2021-40824 (A logic error in the room key sharing functionality of Element Android ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f78f2511fb0c46384b0288262e9bb73024ea1b
-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f78f2511fb0c46384b0288262e9bb73024ea1b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211216/a0c1eb3e/attachment.htm>
    
    
More information about the debian-security-tracker-commits
mailing list