[Git][security-tracker-team/security-tracker][master] Remove information from CVE-2021-28421

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 13 18:16:24 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
98d0a73e by Salvatore Bonaccorso at 2021-07-13T19:15:58+02:00
Remove information from CVE-2021-28421

Asked MITRE to reject the duplicate CVE, which was confirmed and updated
already on their database. Thus gone ahead and removed all referencing
notes already (or could have waited the automatic update later on this
day).

- - - - -


2 changed files:

- data/CVE/list
- data/DLA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -19645,12 +19645,8 @@ CVE-2021-28423 (Multiple SQL Injection vulnerabilities in Teachers Record Manage
 	NOT-FOR-US: Teachers Record Management
 CVE-2021-28422
 	RESERVED
-CVE-2021-28421 (FluidSynth 2.1.7 contains a use after free vulnerability in sfloader/f ...)
-	{DLA-2697-1}
-	- fluidsynth 2.1.7-1.1 (bug #987168)
-	[buster] - fluidsynth 1.1.11-1+deb10u1
-	NOTE: https://github.com/FluidSynth/fluidsynth/issues/808
-	NOTE: https://github.com/FluidSynth/fluidsynth/pull/810
+CVE-2021-28421
+	REJECTED
 CVE-2021-28420 (A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote at ...)
 	NOT-FOR-US: Seo Panel
 CVE-2021-28419 (The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnera ...)
@@ -37279,7 +37275,6 @@ CVE-2021-21417 (fluidsynth is a software synthesizer based on the SoundFont 2 sp
 	[buster] - fluidsynth 1.1.11-1+deb10u1
 	NOTE: https://github.com/FluidSynth/fluidsynth/issues/808
 	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-6fcq-pxhc-jxc9
-	NOTE: Duplicate of CVE-2021-28421
 CVE-2021-21416 (django-registration is a user registration package for Django. The dja ...)
 	- python-django-registration <unfixed> (bug #987366)
 	[stretch] - python-django-registration <no-dsa> (Minor issue)


=====================================
data/DLA/list
=====================================
@@ -28,7 +28,7 @@
 	{CVE-2020-8244}
 	[stretch] - node-bl 1.1.2-1+deb9u1
 [29 Jun 2021] DLA-2697-1 fluidsynth - security update
-	{CVE-2021-21417 CVE-2021-28421}
+	{CVE-2021-21417}
 	[stretch] - fluidsynth 1.1.6-4+deb9u1
 [29 Jun 2021] DLA-2696-1 libjdom2-java - security update
 	{CVE-2021-33813}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/98d0a73edeb428b9661676fe52fb5eefea1b45a3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/98d0a73edeb428b9661676fe52fb5eefea1b45a3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210713/f0d7ea2b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list