[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-40159,CVE-2022-40160,libcommons-jxpath-java

Markus Koschany (@apo) apo at debian.org
Mon Dec 5 13:22:55 GMT 2022



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
89f32d7a by Markus Koschany at 2022-12-05T14:21:18+01:00
CVE-2022-40159,CVE-2022-40160,libcommons-jxpath-java

Both CVE are disputed and will probably be rejected.

- - - - -
ae73fb32 by Markus Koschany at 2022-12-05T14:22:12+01:00
Remove libcommons-jxpath-java from dla-needed.txt

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19669,10 +19669,10 @@ CVE-2022-40162
 CVE-2022-40161
 	REJECTED
 CVE-2022-40160 (** DISPUTED ** This record was originally reported by the oss-fuzz pro ...)
-	- libcommons-jxpath-java <unfixed>
+	NOTE: Invalid oss-fuzz report against libcommons-jxpath-java
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47053
 CVE-2022-40159 (** DISPUTED ** This record was originally reported by the oss-fuzz pro ...)
-	- libcommons-jxpath-java <unfixed>
+	NOTE: Invalid oss-fuzz report against libcommons-jxpath-java
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47057
 CVE-2022-40158
 	REJECTED


=====================================
data/dla-needed.txt
=====================================
@@ -104,10 +104,6 @@ lava
 libapreq2
   NOTE: 20221031: Programming language: C.
 --
-libcommons-jxpath-java
-  NOTE: 20221027: Programming language: Java.
-  NOTE: 20221027: Maintainer notes: Wait for the outcome of upstream discussion. See CVE-2022-41852 for pull requests.
---
 libde265
   NOTE: 20221107: Programming language: C++.
   NOTE: 20221107: Most vulnerabilities unfixed upstream, but a handful are fixed, and v1.0.9 (2022-10) is a security release (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/91e19f5866794bbead12dbe104a1a7fa1c5b5cdb...ae73fb32469a0fe588db79a937dc79de2804fcbe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/91e19f5866794bbead12dbe104a1a7fa1c5b5cdb...ae73fb32469a0fe588db79a937dc79de2804fcbe
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221205/fe55d48f/attachment.htm>


More information about the debian-security-tracker-commits mailing list