[Git][security-tracker-team/security-tracker][master] Add CVE-2021-30475/aom

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jun 4 21:18:48 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
db30e19e by Salvatore Bonaccorso at 2021-06-04T22:18:26+02:00
Add CVE-2021-30475/aom

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7919,7 +7919,9 @@ CVE-2021-3486 (GLPi 9.5.4 does not sanitize the metadata. This way its possible
 	- glpi <removed>
 	NOTE: https://github.com/Kitsun3Sec/exploits/tree/master/cms/GLPI/GLPI-stored-XSS
 CVE-2021-30475 (aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buf ...)
-	TODO: check
+	- aom <unfixed>
+	NOTE: https://aomedia.googlesource.com/aom/+/12adc723acf02633595a4d8da8345742729f46c0
+	NOTE: https://bugs.chromium.org/p/aomedia/issues/detail?id=2999
 CVE-2021-30474 (aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use ...)
 	- aom <unfixed>
 	NOTE: https://aomedia.googlesource.com/aom/+/6e31957b6dc62dbc7d1bb70cd84902dd14c4bf2e



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db30e19e32d297d5bca88d87e2d8c515dfc305e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db30e19e32d297d5bca88d87e2d8c515dfc305e9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210604/a675ce89/attachment.htm>


More information about the debian-security-tracker-commits mailing list