[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Oct 18 09:10:19 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d89e58f by security tracker role at 2021-10-18T08:10:10+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,27 @@
+CVE-2021-42562
+	RESERVED
+CVE-2021-42561
+	RESERVED
+CVE-2021-42560
+	RESERVED
+CVE-2021-42559
+	RESERVED
+CVE-2021-42558
+	RESERVED
+CVE-2021-42557
+	RESERVED
+CVE-2021-42556
+	RESERVED
+CVE-2021-42555
+	RESERVED
+CVE-2021-42554
+	RESERVED
+CVE-2021-3892
+	RESERVED
+CVE-2021-26247
+	RESERVED
+CVE-2021-23225
+	RESERVED
 CVE-2022-0005
 	RESERVED
 CVE-2022-0004
@@ -11124,8 +11148,7 @@ CVE-2021-38299 (Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Contr
 	NOT-FOR-US: FIDO2/Webauthn Support for PHP
 CVE-2021-38298 (Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XX ...)
 	NOT-FOR-US: Zoho ManageEngine
-CVE-2021-38297
-	RESERVED
+CVE-2021-38297 (Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via la ...)
 	- golang-1.17 1.17.2-1
 	- golang-1.16 1.16.9-1
 	NOTE: https://github.com/golang/go/commit/77f2750f4398990eed972186706f160631d7dae4
@@ -16305,8 +16328,8 @@ CVE-2021-36099
 	RESERVED
 CVE-2021-36098
 	RESERVED
-CVE-2021-36097
-	RESERVED
+CVE-2021-36097 (Agents are able to lock the ticket without the "Owner" permission. Onc ...)
+	TODO: check
 CVE-2021-36096 (Generated Support Bundles contains private S/MIME and PGP keys if cont ...)
 	- otrs2 <undetermined> (bug #993846)
 	[buster] - otrs2 <no-dsa> (Non-free not supported)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d89e58f29bb47d79815c64483f627fc585386f0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d89e58f29bb47d79815c64483f627fc585386f0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211018/4af45928/attachment.htm>


More information about the debian-security-tracker-commits mailing list