[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 12 09:10:23 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2bdb360a by security tracker role at 2022-07-12T08:10:14+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,43 @@
+CVE-2022-35648 (Nautilus treadmills T616 S/N 100672PRO21140001 through 100672PRO211719 ...)
+	TODO: check
+CVE-2022-35647
+	RESERVED
+CVE-2022-35646
+	RESERVED
+CVE-2022-35645
+	RESERVED
+CVE-2022-35644
+	RESERVED
+CVE-2022-35643
+	RESERVED
+CVE-2022-35642
+	RESERVED
+CVE-2022-35641
+	RESERVED
+CVE-2022-35640
+	RESERVED
+CVE-2022-35639
+	RESERVED
+CVE-2022-35638
+	RESERVED
+CVE-2022-35637
+	RESERVED
+CVE-2022-35636
+	RESERVED
+CVE-2022-35635
+	RESERVED
+CVE-2022-35634
+	RESERVED
+CVE-2022-35633
+	RESERVED
+CVE-2022-35632
+	RESERVED
+CVE-2022-35631
+	RESERVED
+CVE-2022-35630
+	RESERVED
+CVE-2022-35629
+	RESERVED
 CVE-2022-35628
 	RESERVED
 CVE-2022-35627
@@ -543,205 +583,205 @@ CVE-2022-2347 [Unchecked Download Size and Direction in U-Boot USB DFU]
 	- u-boot <unfixed>
 	NOTE: https://www.openwall.com/lists/oss-security/2022/07/08/2
 CVE-2022-35399
-	RESERVED
+	REJECTED
 CVE-2022-35398
-	RESERVED
+	REJECTED
 CVE-2022-35397
-	RESERVED
+	REJECTED
 CVE-2022-35396
-	RESERVED
+	REJECTED
 CVE-2022-35395
-	RESERVED
+	REJECTED
 CVE-2022-35394
-	RESERVED
+	REJECTED
 CVE-2022-35393
-	RESERVED
+	REJECTED
 CVE-2022-35392
-	RESERVED
+	REJECTED
 CVE-2022-35391
-	RESERVED
+	REJECTED
 CVE-2022-35390
-	RESERVED
+	REJECTED
 CVE-2022-35389
-	RESERVED
+	REJECTED
 CVE-2022-35388
-	RESERVED
+	REJECTED
 CVE-2022-35387
-	RESERVED
+	REJECTED
 CVE-2022-35386
-	RESERVED
+	REJECTED
 CVE-2022-35385
-	RESERVED
+	REJECTED
 CVE-2022-35384
-	RESERVED
+	REJECTED
 CVE-2022-35383
-	RESERVED
+	REJECTED
 CVE-2022-35382
-	RESERVED
+	REJECTED
 CVE-2022-35381
-	RESERVED
+	REJECTED
 CVE-2022-35380
-	RESERVED
+	REJECTED
 CVE-2022-35379
-	RESERVED
+	REJECTED
 CVE-2022-35378
-	RESERVED
+	REJECTED
 CVE-2022-35377
-	RESERVED
+	REJECTED
 CVE-2022-35376
-	RESERVED
+	REJECTED
 CVE-2022-35375
-	RESERVED
+	REJECTED
 CVE-2022-35374
-	RESERVED
+	REJECTED
 CVE-2022-35373
-	RESERVED
+	REJECTED
 CVE-2022-35372
-	RESERVED
+	REJECTED
 CVE-2022-35371
-	RESERVED
+	REJECTED
 CVE-2022-35370
-	RESERVED
+	REJECTED
 CVE-2022-35369
-	RESERVED
+	REJECTED
 CVE-2022-35368
-	RESERVED
+	REJECTED
 CVE-2022-35367
-	RESERVED
+	REJECTED
 CVE-2022-35366
-	RESERVED
+	REJECTED
 CVE-2022-35365
-	RESERVED
+	REJECTED
 CVE-2022-35364
-	RESERVED
+	REJECTED
 CVE-2022-35363
-	RESERVED
+	REJECTED
 CVE-2022-35362
-	RESERVED
+	REJECTED
 CVE-2022-35361
-	RESERVED
+	REJECTED
 CVE-2022-35360
-	RESERVED
+	REJECTED
 CVE-2022-35359
-	RESERVED
+	REJECTED
 CVE-2022-35358
-	RESERVED
+	REJECTED
 CVE-2022-35357
-	RESERVED
+	REJECTED
 CVE-2022-35356
-	RESERVED
+	REJECTED
 CVE-2022-35355
-	RESERVED
+	REJECTED
 CVE-2022-35354
-	RESERVED
+	REJECTED
 CVE-2022-35353
-	RESERVED
+	REJECTED
 CVE-2022-35352
-	RESERVED
+	REJECTED
 CVE-2022-35351
-	RESERVED
+	REJECTED
 CVE-2022-35350
-	RESERVED
+	REJECTED
 CVE-2022-35349
-	RESERVED
+	REJECTED
 CVE-2022-35348
-	RESERVED
+	REJECTED
 CVE-2022-35347
-	RESERVED
+	REJECTED
 CVE-2022-35346
-	RESERVED
+	REJECTED
 CVE-2022-35345
-	RESERVED
+	REJECTED
 CVE-2022-35344
-	RESERVED
+	REJECTED
 CVE-2022-35343
-	RESERVED
+	REJECTED
 CVE-2022-35342
-	RESERVED
+	REJECTED
 CVE-2022-35341
-	RESERVED
+	REJECTED
 CVE-2022-35340
-	RESERVED
+	REJECTED
 CVE-2022-35339
-	RESERVED
+	REJECTED
 CVE-2022-35338
-	RESERVED
+	REJECTED
 CVE-2022-35337
-	RESERVED
+	REJECTED
 CVE-2022-35336
-	RESERVED
+	REJECTED
 CVE-2022-35335
-	RESERVED
+	REJECTED
 CVE-2022-35334
-	RESERVED
+	REJECTED
 CVE-2022-35333
-	RESERVED
+	REJECTED
 CVE-2022-35332
-	RESERVED
+	REJECTED
 CVE-2022-35331
-	RESERVED
+	REJECTED
 CVE-2022-35330
-	RESERVED
+	REJECTED
 CVE-2022-35329
-	RESERVED
+	REJECTED
 CVE-2022-35328
-	RESERVED
+	REJECTED
 CVE-2022-35327
-	RESERVED
+	REJECTED
 CVE-2022-35326
-	RESERVED
+	REJECTED
 CVE-2022-35325
-	RESERVED
+	REJECTED
 CVE-2022-35324
-	RESERVED
+	REJECTED
 CVE-2022-35323
-	RESERVED
+	REJECTED
 CVE-2022-35322
-	RESERVED
+	REJECTED
 CVE-2022-35321
-	RESERVED
+	REJECTED
 CVE-2022-35320
-	RESERVED
+	REJECTED
 CVE-2022-35319
-	RESERVED
+	REJECTED
 CVE-2022-35318
-	RESERVED
+	REJECTED
 CVE-2022-35317
-	RESERVED
+	REJECTED
 CVE-2022-35316
-	RESERVED
+	REJECTED
 CVE-2022-35315
-	RESERVED
+	REJECTED
 CVE-2022-35314
-	RESERVED
+	REJECTED
 CVE-2022-35313
-	RESERVED
+	REJECTED
 CVE-2022-35312
-	RESERVED
+	REJECTED
 CVE-2022-35311
-	RESERVED
+	REJECTED
 CVE-2022-35310
-	RESERVED
+	REJECTED
 CVE-2022-35309
-	RESERVED
+	REJECTED
 CVE-2022-35308
-	RESERVED
+	REJECTED
 CVE-2022-35307
-	RESERVED
+	REJECTED
 CVE-2022-35306
-	RESERVED
+	REJECTED
 CVE-2022-35305
-	RESERVED
+	REJECTED
 CVE-2022-35304
-	RESERVED
+	REJECTED
 CVE-2022-35303
-	RESERVED
+	REJECTED
 CVE-2022-35302
-	RESERVED
+	REJECTED
 CVE-2022-35301
-	RESERVED
+	REJECTED
 CVE-2022-35300
-	RESERVED
+	REJECTED
 CVE-2022-33939
 	RESERVED
 CVE-2022-2346
@@ -6750,7 +6790,7 @@ CVE-2022-32953
 CVE-2022-32952
 	RESERVED
 CVE-2022-32951
-	RESERVED
+	REJECTED
 CVE-2022-32950
 	RESERVED
 CVE-2022-32949
@@ -11637,10 +11677,10 @@ CVE-2022-31142
 	RESERVED
 CVE-2022-31141
 	RESERVED
-CVE-2022-31140
-	RESERVED
-CVE-2022-31139
-	RESERVED
+CVE-2022-31140 (Valinor is a PHP library that helps to map any input into a strongly-t ...)
+	TODO: check
+CVE-2022-31139 (UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe &am ...)
+	TODO: check
 CVE-2022-31138 (mailcow is a mailserver suite. Prior to mailcow-dockerized version 202 ...)
 	TODO: check
 CVE-2022-31137 (Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Kee ...)
@@ -11801,22 +11841,22 @@ CVE-2022-31081 (HTTP::Daemon is a simple http server class written in perl. Vers
 	NOTE: Fixed by: https://github.com/libwww-perl/HTTP-Daemon/commit/e84475de51d6fd7b29354a997413472a99db70b2
 	NOTE: Fixed by: https://github.com/libwww-perl/HTTP-Daemon/commit/8dc5269d59e2d5d9eb1647d82c449ccd880f7fd0
 	NOTE: Testcase: https://github.com/libwww-perl/HTTP-Daemon/commit/faebad54455c2c2919e234202362570925fb99d1
-CVE-2022-31080
-	RESERVED
-CVE-2022-31079
-	RESERVED
-CVE-2022-31078
-	RESERVED
+CVE-2022-31080 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
+CVE-2022-31079 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
+CVE-2022-31078 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
 CVE-2022-31077 (KubeEdge is built upon Kubernetes and extends native containerized app ...)
 	NOT-FOR-US: KubeEdge
 CVE-2022-31076 (KubeEdge is built upon Kubernetes and extends native containerized app ...)
 	NOT-FOR-US: KubeEdge
-CVE-2022-31075
-	RESERVED
-CVE-2022-31074
-	RESERVED
-CVE-2022-31073
-	RESERVED
+CVE-2022-31075 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
+CVE-2022-31074 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
+CVE-2022-31073 (KubeEdge is an open source system for extending native containerized a ...)
+	TODO: check
 CVE-2022-31072 (Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24 ...)
 	- ruby-octokit <not-affected> (No vulnerable version was uploaded to the archive)
 	NOTE: https://github.com/octokit/octokit.rb/security/advisories/GHSA-g28x-pgr3-qqx6
@@ -113168,20 +113208,20 @@ CVE-2020-35171
 	RESERVED
 CVE-2020-35170 (Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Un ...)
 	NOT-FOR-US: Dell EMC Unisphere for PowerMax
-CVE-2020-35169
-	RESERVED
-CVE-2020-35168
-	RESERVED
-CVE-2020-35167
-	RESERVED
-CVE-2020-35166
-	RESERVED
+CVE-2020-35169 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-35168 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-35167 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-35166 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
 CVE-2020-35165
 	RESERVED
-CVE-2020-35164
-	RESERVED
-CVE-2020-35163
-	RESERVED
+CVE-2020-35164 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-35163 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
 CVE-2020-35162
 	RESERVED
 CVE-2020-35161
@@ -115433,14 +115473,14 @@ CVE-2020-29509 (The encoding/xml package in Go (all versions) does not correctly
 	NOTE: https://github.com/golang/go/issues/43168
 	NOTE: https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
 	NOTE: https://github.com/russellhaering/gosaml2/security/advisories/GHSA-xhqq-x44f-9fgg
-CVE-2020-29508
-	RESERVED
-CVE-2020-29507
-	RESERVED
-CVE-2020-29506
-	RESERVED
-CVE-2020-29505
-	RESERVED
+CVE-2020-29508 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-29507 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSA ...)
+	TODO: check
+CVE-2020-29506 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
+CVE-2020-29505 (Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSA ...)
+	TODO: check
 CVE-2020-29504
 	RESERVED
 CVE-2020-29503 (Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file per ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2bdb360ac14f7cbf6fa9c68b9048c8d070b1088f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2bdb360ac14f7cbf6fa9c68b9048c8d070b1088f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220712/6bc4bd07/attachment.htm>


More information about the debian-security-tracker-commits mailing list