[Git][security-tracker-team/security-tracker][master] buster/bullseye triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Jul 31 22:09:17 BST 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
60de9787 by Moritz Muehlenhoff at 2022-07-31T23:08:48+02:00
buster/bullseye triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8491,6 +8491,7 @@ CVE-2022-33746
 	RESERVED
 CVE-2022-33745 (insufficient TLB flush for x86 PV guests in shadow mode For migration  ...)
 	- xen <unfixed>
+	[bullseye] - xen <postponed> (Minor issue, include in next security round)
 	[buster] - xen <end-of-life> (DSA 4677-1)
 	NOTE: https://xenbits.xen.org/xsa/advisory-408.html
 	NOTE: All versions of Xen with the XSA-401 fixes applied are vulnerable
@@ -30472,6 +30473,7 @@ CVE-2022-25859
 	RESERVED
 CVE-2022-25858 (The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vuln ...)
 	- node-terser 4.8.1-1
+	[bullseye] - node-terser <no-dsa> (Minor issue)
 	NOTE: https://snyk.io/vuln/SNYK-JS-TERSER-2806366
 	NOTE: https://github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76b (v5.14.2)
 	NOTE: https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012 (v4.8.1)
@@ -42808,6 +42810,8 @@ CVE-2022-0085 (Server-Side Request Forgery (SSRF) in GitHub repository dompdf/do
 CVE-2022-0084
 	RESERVED
 	- jboss-xnio <unfixed> (bug #1013280)
+	[bullseye] - jboss-xnio <no-dsa> (Minor issue)
+	[buster] - jboss-xnio <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2064226
 CVE-2021-46129
 	RESERVED



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60de9787728bcc3187f4a415516ec02954813c0b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60de9787728bcc3187f4a415516ec02954813c0b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220731/95d6c610/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list