[Git][security-tracker-team/security-tracker][master] Update notes for CVE-2021-42343/dask

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Nov 11 07:02:00 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
95e44ad5 by Salvatore Bonaccorso at 2021-11-11T07:53:12+01:00
Update notes for CVE-2021-42343/dask

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4789,8 +4789,9 @@ CVE-2021-42345
 CVE-2021-42344
 	RESERVED
 CVE-2021-42343 (An issue was discovered in the Dask distributed package before 2021.10 ...)
-	- dask <unfixed>
-	TODO: check details if fixed upstream in 2021.10.0
+	- dask.distributed <unfixed>
+	NOTE: https://github.com/dask/distributed/pull/5427
+	NOTE: https://github.com/dask/distributed/security/advisories/GHSA-hwqr-f3v9-hwxr
 CVE-2021-42342 (An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the fi ...)
 	NOT-FOR-US: Embedthis GoAhead
 CVE-2021-42341 (checkpath in OpenRC before 0.44.7 uses the direct output of strlen() t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/95e44ad53194e3611bc264045c330fcf8b52e92a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/95e44ad53194e3611bc264045c330fcf8b52e92a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211111/268f7885/attachment.htm>


More information about the debian-security-tracker-commits mailing list