[Git][security-tracker-team/security-tracker][master] resolve some TODOs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jun 7 16:23:11 BST 2021



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
baca26fd by Moritz Muehlenhoff at 2021-06-07T17:19:22+02:00
resolve some TODOs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1591,7 +1591,6 @@ CVE-2021-33198
 	- golang-1.7 <removed>
 	NOTE: https://github.com/golang/go/issues/44910
 	NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
-	TODO: check completeness/correctness of the tracking
 CVE-2021-33197
 	RESERVED
 	- golang-1.16 1.16.5-1
@@ -1612,7 +1611,6 @@ CVE-2021-33196 [archive/zip: malformed archive may cause panic or memory exhaust
 	NOTE: https://github.com/golang/go/issues/46242
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
 	NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
-	TODO: check completeness/correctness of the tracking
 CVE-2021-33195
 	RESERVED
 	- golang-1.16 1.16.5-1
@@ -1622,7 +1620,6 @@ CVE-2021-33195
 	- golang-1.7 <removed>
 	NOTE: https://github.com/golang/go/issues/46241
 	NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
-	TODO: check completeness/correctness of the tracking
 CVE-2021-33194 (Go through 1.15.12 and 1.16.x through 1.16.4 has a golang.org/x/net/ht ...)
 	- golang-golang-x-net 1:0.0+git20210119.5f4716e+dfsg-4
 	- golang-golang-x-net-dev <removed>
@@ -2846,9 +2843,9 @@ CVE-2021-32637 (Authelia is a a single sign-on multi-factor portal for web apps.
 CVE-2021-32636
 	RESERVED
 CVE-2021-32635 (### Impact Due to incorrect use of a default URL, `singularity` action ...)
-	- singularity-container <undetermined>
+	- singularity-container <not-affected> (Vulnerable code introduced in 3.7.2)
 	NOTE: https://github.com/hpcng/singularity/security/advisories/GHSA-jq42-hfch-42f3
-	TODO: might only affect 3.7.2 and 3.7.3 according to GHSA-jq42-hfch-42f3 and so not-affected
+	NOTE: https://github.com/hpcng/singularity/commit/cd298aaeb7698fb692689e2e1b49972c94bfa440
 CVE-2021-32634 (Emissary is a distributed, peer-to-peer, data-driven workflow framewor ...)
 	NOT-FOR-US: NSA Emissary
 CVE-2021-32633 (Zope is an open-source web application server. In Zope versions prior  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210607/43f7a9db/attachment.htm>


More information about the debian-security-tracker-commits mailing list