[Git][security-tracker-team/security-tracker][master] resolve some TODOs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Jun 7 16:23:11 BST 2021
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
baca26fd by Moritz Muehlenhoff at 2021-06-07T17:19:22+02:00
resolve some TODOs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1591,7 +1591,6 @@ CVE-2021-33198
- golang-1.7 <removed>
NOTE: https://github.com/golang/go/issues/44910
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33197
RESERVED
- golang-1.16 1.16.5-1
@@ -1612,7 +1611,6 @@ CVE-2021-33196 [archive/zip: malformed archive may cause panic or memory exhaust
NOTE: https://github.com/golang/go/issues/46242
NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33195
RESERVED
- golang-1.16 1.16.5-1
@@ -1622,7 +1620,6 @@ CVE-2021-33195
- golang-1.7 <removed>
NOTE: https://github.com/golang/go/issues/46241
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33194 (Go through 1.15.12 and 1.16.x through 1.16.4 has a golang.org/x/net/ht ...)
- golang-golang-x-net 1:0.0+git20210119.5f4716e+dfsg-4
- golang-golang-x-net-dev <removed>
@@ -2846,9 +2843,9 @@ CVE-2021-32637 (Authelia is a a single sign-on multi-factor portal for web apps.
CVE-2021-32636
RESERVED
CVE-2021-32635 (### Impact Due to incorrect use of a default URL, `singularity` action ...)
- - singularity-container <undetermined>
+ - singularity-container <not-affected> (Vulnerable code introduced in 3.7.2)
NOTE: https://github.com/hpcng/singularity/security/advisories/GHSA-jq42-hfch-42f3
- TODO: might only affect 3.7.2 and 3.7.3 according to GHSA-jq42-hfch-42f3 and so not-affected
+ NOTE: https://github.com/hpcng/singularity/commit/cd298aaeb7698fb692689e2e1b49972c94bfa440
CVE-2021-32634 (Emissary is a distributed, peer-to-peer, data-driven workflow framewor ...)
NOT-FOR-US: NSA Emissary
CVE-2021-32633 (Zope is an open-source web application server. In Zope versions prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210607/43f7a9db/attachment.htm>
More information about the debian-security-tracker-commits
mailing list