[Git][security-tracker-team/security-tracker][master] two bogus CVE assignments for clementine

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Dec 16 08:18:24 GMT 2021



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
07f78f25 by Moritz Muehlenhoff at 2021-12-16T09:18:10+01:00
two bogus CVE assignments for clementine

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14169,9 +14169,15 @@ CVE-2021-40829 (Connections initialized by the AWS IoT Device SDK v2 for Java (v
 CVE-2021-40828 (Connections initialized by the AWS IoT Device SDK v2 for Java (version ...)
 	NOT-FOR-US: AWS IoT Device SDK
 CVE-2021-40827 (Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used)  ...)
-	NOT-FOR-US: Clementine Music Player
+	- clementine <unfixed> (unimportant)
+	NOTE: https://voidsec.com/advisories/cve-2021-40827/
+	NOTE: Bogus report with hardly useful details whether affects clementine/gstreamer, but
+	NOTE: regardless just a crash in a CLI tool
 CVE-2021-40826 (Clementine Music Player through 1.3.1 is vulnerable to a User Mode Wri ...)
-	NOT-FOR-US: Clementine Music Player
+	- clementine <unfixed> (unimportant)
+	NOTE: https://voidsec.com/advisories/cve-2021-40827/
+	NOTE: Bogus report with hardly useful details whether affects clementine/gstreamer, but
+	NOTE: regardless just a crash in a CLI tool
 CVE-2021-40825 (nLight ECLYPSE (nECY) system Controllers running software prior to 1.1 ...)
 	NOT-FOR-US: nLight ECLYPSE (nECY) system Controllers
 CVE-2021-40824 (A logic error in the room key sharing functionality of Element Android ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f78f2511fb0c46384b0288262e9bb73024ea1b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f78f2511fb0c46384b0288262e9bb73024ea1b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211216/a0c1eb3e/attachment.htm>


More information about the debian-security-tracker-commits mailing list