[Git][security-tracker-team/security-tracker][master] MITRE assigned separate CVE for tcmu issue (related to CVE-2020-28374)
Salvatore Bonaccorso
carnil at debian.org
Wed Jan 13 20:23:28 GMT 2021
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
63e32712 by Salvatore Bonaccorso at 2021-01-13T21:22:47+01:00
MITRE assigned separate CVE for tcmu issue (related to CVE-2020-28374)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,16 @@
CVE-2021-3140
RESERVED
CVE-2021-3139 (In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy ...)
- TODO: check
+ - tcmu <unfixed> (bug #980007)
+ NOTE: https://www.openwall.com/lists/oss-security/2021/01/12/12
+ NOTE: https://www.openwall.com/lists/oss-security/2021/01/13/5
+ NOTE: https://github.com/open-iscsi/tcmu-runner/issues/645
+ NOTE: https://github.com/open-iscsi/tcmu-runner/pull/644
+ NOTE: Fixed by: https://github.com/open-iscsi/tcmu-runner/commit/2b16e96e6b63d0419d857f53e4cc67f0adb383fd
+ NOTE: Some followup fixes: https://github.com/open-iscsi/tcmu-runner/pull/646
+ NOTE: https://github.com/open-iscsi/tcmu-runner/commit/b202dc06ef391c6ab9a7561856238a258de04663
+ NOTE: https://github.com/open-iscsi/tcmu-runner/commit/170bfa63288a399b38c35eb646b2835d4ba7c08a
+ NOTE: https://github.com/open-iscsi/tcmu-runner/commit/01685b2ab8c430c0fb9ce397e7e76b60fe6cbde5
CVE-2021-24002
RESERVED
CVE-2021-24001
@@ -16447,16 +16456,8 @@ CVE-2020-28375
RESERVED
CVE-2020-28374 (In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10. ...)
- linux <unfixed>
- - tcmu <unfixed> (bug #980007)
NOTE: https://git.kernel.org/linus/2896c93811e39d63a4d9b63ccf12a8fbc226e5e4
NOTE: https://www.openwall.com/lists/oss-security/2021/01/12/12
- NOTE: https://github.com/open-iscsi/tcmu-runner/issues/645
- NOTE: https://github.com/open-iscsi/tcmu-runner/pull/644
- NOTE: Fixed by: https://github.com/open-iscsi/tcmu-runner/commit/2b16e96e6b63d0419d857f53e4cc67f0adb383fd
- NOTE: Some followup fixes: https://github.com/open-iscsi/tcmu-runner/pull/646
- NOTE: https://github.com/open-iscsi/tcmu-runner/commit/b202dc06ef391c6ab9a7561856238a258de04663
- NOTE: https://github.com/open-iscsi/tcmu-runner/commit/170bfa63288a399b38c35eb646b2835d4ba7c08a
- NOTE: https://github.com/open-iscsi/tcmu-runner/commit/01685b2ab8c430c0fb9ce397e7e76b60fe6cbde5
CVE-2020-28373 (upnpd on certain NETGEAR devices allows remote (LAN) attackers to exec ...)
NOT-FOR-US: Netgear
CVE-2020-28372
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63e327127872a3a51d2c3c1a0a19de5229d761ae
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63e327127872a3a51d2c3c1a0a19de5229d761ae
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210113/543f3243/attachment.html>
More information about the debian-security-tracker-commits
mailing list