[Git][security-tracker-team/security-tracker][master] buster/bullseye triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Jul 31 22:09:17 BST 2022
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
60de9787 by Moritz Muehlenhoff at 2022-07-31T23:08:48+02:00
buster/bullseye triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -8491,6 +8491,7 @@ CVE-2022-33746
RESERVED
CVE-2022-33745 (insufficient TLB flush for x86 PV guests in shadow mode For migration ...)
- xen <unfixed>
+ [bullseye] - xen <postponed> (Minor issue, include in next security round)
[buster] - xen <end-of-life> (DSA 4677-1)
NOTE: https://xenbits.xen.org/xsa/advisory-408.html
NOTE: All versions of Xen with the XSA-401 fixes applied are vulnerable
@@ -30472,6 +30473,7 @@ CVE-2022-25859
RESERVED
CVE-2022-25858 (The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vuln ...)
- node-terser 4.8.1-1
+ [bullseye] - node-terser <no-dsa> (Minor issue)
NOTE: https://snyk.io/vuln/SNYK-JS-TERSER-2806366
NOTE: https://github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76b (v5.14.2)
NOTE: https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012 (v4.8.1)
@@ -42808,6 +42810,8 @@ CVE-2022-0085 (Server-Side Request Forgery (SSRF) in GitHub repository dompdf/do
CVE-2022-0084
RESERVED
- jboss-xnio <unfixed> (bug #1013280)
+ [bullseye] - jboss-xnio <no-dsa> (Minor issue)
+ [buster] - jboss-xnio <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2064226
CVE-2021-46129
RESERVED
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60de9787728bcc3187f4a415516ec02954813c0b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60de9787728bcc3187f4a415516ec02954813c0b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220731/95d6c610/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list