[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue May 3 21:10:22 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6d22a562 by security tracker role at 2022-05-03T20:10:14+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,233 @@
+CVE-2022-30227
+	RESERVED
+CVE-2022-30226
+	RESERVED
+CVE-2022-30225
+	RESERVED
+CVE-2022-30224
+	RESERVED
+CVE-2022-30223
+	RESERVED
+CVE-2022-30222
+	RESERVED
+CVE-2022-30221
+	RESERVED
+CVE-2022-30220
+	RESERVED
+CVE-2022-30219
+	RESERVED
+CVE-2022-30218
+	RESERVED
+CVE-2022-30217
+	RESERVED
+CVE-2022-30216
+	RESERVED
+CVE-2022-30215
+	RESERVED
+CVE-2022-30214
+	RESERVED
+CVE-2022-30213
+	RESERVED
+CVE-2022-30212
+	RESERVED
+CVE-2022-30211
+	RESERVED
+CVE-2022-30210
+	RESERVED
+CVE-2022-30209
+	RESERVED
+CVE-2022-30208
+	RESERVED
+CVE-2022-30207
+	RESERVED
+CVE-2022-30206
+	RESERVED
+CVE-2022-30205
+	RESERVED
+CVE-2022-30204
+	RESERVED
+CVE-2022-30203
+	RESERVED
+CVE-2022-30202
+	RESERVED
+CVE-2022-30201
+	RESERVED
+CVE-2022-30200
+	RESERVED
+CVE-2022-30199
+	RESERVED
+CVE-2022-30198
+	RESERVED
+CVE-2022-30197
+	RESERVED
+CVE-2022-30196
+	RESERVED
+CVE-2022-30195
+	RESERVED
+CVE-2022-30194
+	RESERVED
+CVE-2022-30193
+	RESERVED
+CVE-2022-30192
+	RESERVED
+CVE-2022-30191
+	RESERVED
+CVE-2022-30190
+	RESERVED
+CVE-2022-30189
+	RESERVED
+CVE-2022-30188
+	RESERVED
+CVE-2022-30187
+	RESERVED
+CVE-2022-30186
+	RESERVED
+CVE-2022-30185
+	RESERVED
+CVE-2022-30184
+	RESERVED
+CVE-2022-30183
+	RESERVED
+CVE-2022-30182
+	RESERVED
+CVE-2022-30181
+	RESERVED
+CVE-2022-30180
+	RESERVED
+CVE-2022-30179
+	RESERVED
+CVE-2022-30178
+	RESERVED
+CVE-2022-30177
+	RESERVED
+CVE-2022-30176
+	RESERVED
+CVE-2022-30175
+	RESERVED
+CVE-2022-30174
+	RESERVED
+CVE-2022-30173
+	RESERVED
+CVE-2022-30172
+	RESERVED
+CVE-2022-30171
+	RESERVED
+CVE-2022-30170
+	RESERVED
+CVE-2022-30169
+	RESERVED
+CVE-2022-30168
+	RESERVED
+CVE-2022-30167
+	RESERVED
+CVE-2022-30166
+	RESERVED
+CVE-2022-30165
+	RESERVED
+CVE-2022-30164
+	RESERVED
+CVE-2022-30163
+	RESERVED
+CVE-2022-30162
+	RESERVED
+CVE-2022-30161
+	RESERVED
+CVE-2022-30160
+	RESERVED
+CVE-2022-30159
+	RESERVED
+CVE-2022-30158
+	RESERVED
+CVE-2022-30157
+	RESERVED
+CVE-2022-30156
+	RESERVED
+CVE-2022-30155
+	RESERVED
+CVE-2022-30154
+	RESERVED
+CVE-2022-30153
+	RESERVED
+CVE-2022-30152
+	RESERVED
+CVE-2022-30151
+	RESERVED
+CVE-2022-30150
+	RESERVED
+CVE-2022-30149
+	RESERVED
+CVE-2022-30148
+	RESERVED
+CVE-2022-30147
+	RESERVED
+CVE-2022-30146
+	RESERVED
+CVE-2022-30145
+	RESERVED
+CVE-2022-30144
+	RESERVED
+CVE-2022-30143
+	RESERVED
+CVE-2022-30142
+	RESERVED
+CVE-2022-30141
+	RESERVED
+CVE-2022-30140
+	RESERVED
+CVE-2022-30139
+	RESERVED
+CVE-2022-30138
+	RESERVED
+CVE-2022-30137
+	RESERVED
+CVE-2022-30136
+	RESERVED
+CVE-2022-30135
+	RESERVED
+CVE-2022-30134
+	RESERVED
+CVE-2022-30133
+	RESERVED
+CVE-2022-30132
+	RESERVED
+CVE-2022-30131
+	RESERVED
+CVE-2022-30130
+	RESERVED
+CVE-2022-30129
+	RESERVED
+CVE-2022-30128
+	RESERVED
+CVE-2022-30127
+	RESERVED
+CVE-2022-1567
+	RESERVED
+CVE-2022-1566
+	RESERVED
+CVE-2022-1565
+	RESERVED
+CVE-2022-1564
+	RESERVED
+CVE-2022-1563
+	RESERVED
+CVE-2022-1562
+	RESERVED
+CVE-2022-1561
+	RESERVED
+CVE-2022-1560
+	RESERVED
+CVE-2022-1559
+	RESERVED
+CVE-2022-1558
+	RESERVED
+CVE-2022-1557
+	RESERVED
+CVE-2022-1556
+	RESERVED
+CVE-2022-1555
+	RESERVED
+CVE-2022-1554 (Path Traversal due to `send_file` call in GitHub repository clinical-g ...)
+	TODO: check
 CVE-2022-30126
 	RESERVED
 CVE-2022-1553
@@ -962,8 +1192,7 @@ CVE-2022-1475 (An integer overflow vulnerability was found in FFmpeg 5.0.1 and i
 	NOTE: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=fa2e4afe8d0a23fac37392ef6506cfc9841f8d3d (n4.3.4)
 CVE-2022-1474
 	RESERVED
-CVE-2022-1473 [Resource leakage when decoding certificates and keys]
-	RESERVED
+CVE-2022-1473 (The OPENSSL_LH_flush() function, which empties a hash table, contains  ...)
 	[experimental] - openssl <unfixed>
 	- openssl <not-affected> (Only affects OpenSSL 3.0)
 	NOTE: https://www.openssl.org/news/secadv/20220503.txt
@@ -1541,8 +1770,7 @@ CVE-2022-1436
 	RESERVED
 CVE-2022-1435
 	RESERVED
-CVE-2022-1434 [Incorrect MAC key used in the RC4-MD5 ciphersuite]
-	RESERVED
+CVE-2022-1434 (The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly  ...)
 	[experimental] - openssl <unfixed>
 	- openssl <not-affected> (Only affects OpenSSL 3.0)
 	NOTE: https://www.openssl.org/news/secadv/20220503.txt
@@ -2638,8 +2866,7 @@ CVE-2022-29158
 	RESERVED
 CVE-2022-1344 (Stored XSS due to no sanitization in the filename in GitHub repository ...)
 	NOT-FOR-US: organizr
-CVE-2022-1343 [OCSP_basic_verify may incorrectly verify the response signing certificate]
-	RESERVED
+CVE-2022-1343 (The function `OCSP_basic_verify` verifies the signer certificate on an ...)
 	[experimental] - openssl <unfixed>
 	- openssl <not-affected> (Only affects OpenSSL 3.0)
 	NOTE: https://www.openssl.org/news/secadv/20220503.txt
@@ -2841,8 +3068,8 @@ CVE-2022-29082
 	RESERVED
 CVE-2022-1332 (One of the API in Mattermost version 6.4.1 and earlier fails to proper ...)
 	- mattermost-server <itp> (bug #823556)
-CVE-2022-1331
-	RESERVED
+CVE-2022-1331 (In four instances DMARS (All versions prior to v2.1.10.24) does not pr ...)
+	TODO: check
 CVE-2022-1330 (stored xss due to unsantized anchor url in GitHub repository alvarotri ...)
 	NOT-FOR-US: fullpage.js
 CVE-2022-1329 (The Elementor Website Builder plugin for WordPress is vulnerable to un ...)
@@ -3091,8 +3318,7 @@ CVE-2022-1294
 	RESERVED
 CVE-2022-1293
 	RESERVED
-CVE-2022-1292 [The c_rehash script allows command injection]
-	RESERVED
+CVE-2022-1292 (The c_rehash script does not properly sanitise shell metacharacters to ...)
 	- openssl <unfixed>
 	NOTE: https://www.openssl.org/news/secadv/20220503.txt
 	NOTE: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2 (openssl-3.0.3)
@@ -3149,8 +3375,8 @@ CVE-2022-29003
 	RESERVED
 CVE-2022-29002
 	RESERVED
-CVE-2022-29001
-	RESERVED
+CVE-2022-29001 (In SpringBootMovie <=1.2, the uploaded file suffix parameter is not ...)
+	TODO: check
 CVE-2022-29000
 	RESERVED
 CVE-2022-28999
@@ -4202,8 +4428,8 @@ CVE-2022-28601
 	RESERVED
 CVE-2022-28600
 	RESERVED
-CVE-2022-28599
-	RESERVED
+CVE-2022-28599 (A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1 ...)
+	TODO: check
 CVE-2022-28598
 	RESERVED
 CVE-2022-28597
@@ -4220,18 +4446,18 @@ CVE-2022-28592
 	RESERVED
 CVE-2022-28591
 	RESERVED
-CVE-2022-28590
-	RESERVED
-CVE-2022-28589
-	RESERVED
-CVE-2022-28588
-	RESERVED
+CVE-2022-28590 (A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 v ...)
+	TODO: check
+CVE-2022-28589 (A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 al ...)
+	TODO: check
+CVE-2022-28588 (In SpringBootMovie <=1.2 when adding movie names, malicious code ca ...)
+	TODO: check
 CVE-2022-28587
 	RESERVED
 CVE-2022-28586 (XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript  ...)
 	NOT-FOR-US: Hoosk
-CVE-2022-28585
-	RESERVED
+CVE-2022-28585 (EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php ...)
+	TODO: check
 CVE-2022-28584
 	RESERVED
 CVE-2022-28583
@@ -4278,10 +4504,10 @@ CVE-2022-28563
 	RESERVED
 CVE-2022-28562
 	RESERVED
-CVE-2022-28561
-	RESERVED
-CVE-2022-28560
-	RESERVED
+CVE-2022-28561 (There is a stack overflow vulnerability in the /goform/setMacFilterCfg ...)
+	TODO: check
+CVE-2022-28560 (There is a stack overflow vulnerability in the goform/fast_setting_wif ...)
+	TODO: check
 CVE-2022-28559
 	RESERVED
 CVE-2022-28558
@@ -4394,8 +4620,8 @@ CVE-2022-28506 (There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScr
 	[buster] - giflib <no-dsa> (Minor issue)
 	[stretch] - giflib <no-dsa> (Minor issue)
 	NOTE: https://sourceforge.net/p/giflib/bugs/159/
-CVE-2022-28505
-	RESERVED
+CVE-2022-28505 (Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system ...)
+	TODO: check
 CVE-2022-28504
 	RESERVED
 CVE-2022-28503
@@ -6062,8 +6288,8 @@ CVE-2022-27964 (Xmanager v7.0.0096 and below contains a binary hijack vulnerabil
 	NOT-FOR-US: NetSarang Xmanager
 CVE-2022-27963 (Xftp 7.0.0088p and below contains a binary hijack vulnerability which  ...)
 	NOT-FOR-US: NetSarang Xftp
-CVE-2022-27962
-	RESERVED
+CVE-2022-27962 (Bluecms 1.6 has a SQL injection vulnerability at cooike. ...)
+	TODO: check
 CVE-2022-27961 (A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in O ...)
 	NOT-FOR-US: OFCMS
 CVE-2022-27960 (Insecure permissions configured in the user_id parameter at SysUserCon ...)
@@ -9150,8 +9376,8 @@ CVE-2022-0918 (A vulnerability was discovered in the 389 Directory Server that a
 	TODO: check details
 CVE-2022-0917
 	RESERVED
-CVE-2022-0916
-	RESERVED
+CVE-2022-0916 (An issue was discovered in Logitech Options. The OAuth 2.0 state param ...)
+	TODO: check
 CVE-2022-0915 (There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerabi ...)
 	NOT-FOR-US: Logitech Sync for Windows
 CVE-2022-0914 (The Export All URLs WordPress plugin before 4.3 does not have CSRF in  ...)
@@ -9597,8 +9823,8 @@ CVE-2022-0884 (The Profile Builder WordPress plugin before 3.6.8 does not saniti
 	NOT-FOR-US: WordPress plugin
 CVE-2022-0883
 	RESERVED
-CVE-2022-0882
-	RESERVED
+CVE-2022-0882 (A bug exists where an attacker can read the kernel log through exposed ...)
+	TODO: check
 CVE-2022-0881 (Insecure Storage of Sensitive Information in GitHub repository chocobo ...)
 	- peertube <itp> (bug #950821)
 CVE-2022-26847 (SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access  ...)
@@ -14772,6 +14998,7 @@ CVE-2022-24803 (Asciidoctor-include-ext is Asciidoctor’s standard include
 CVE-2022-24802 (deepmerge-ts is a typescript library providing functionality to deep m ...)
 	NOT-FOR-US: deepmerge-ts
 CVE-2022-24801 (Twisted is an event-based framework for internet applications, support ...)
+	{DLA-2991-1}
 	- twisted 22.4.0-1 (bug #1009030)
 	[bullseye] - twisted <no-dsa> (Minor issue)
 	[buster] - twisted <no-dsa> (Minor issue)
@@ -15240,7 +15467,7 @@ CVE-2022-24677 (Admin.php in HYBBS2 through 2.3.2 allows remote code execution b
 	NOT-FOR-US: HYBBS2
 CVE-2022-24676 (update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file ...)
 	NOT-FOR-US: HYBBS2
-CVE-2022-24675 (encoding/pem in Go before 1.17.9 and 1.8.x before 1.8.1 has a Decode s ...)
+CVE-2022-24675 (encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode ...)
 	- golang-1.18 1.18.1-1
 	- golang-1.17 1.17.9-1
 	NOTE: https://groups.google.com/g/golang-announce/c/oecdBNLOml8
@@ -15268,6 +15495,7 @@ CVE-2022-24670
 CVE-2022-24669
 	RESERVED
 CVE-2022-0547 (OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass  ...)
+	{DLA-2992-1}
 	- openvpn 2.5.6-1 (bug #1008015)
 	[bullseye] - openvpn <no-dsa> (Minor issue)
 	[buster] - openvpn <no-dsa> (Minor issue)
@@ -16605,8 +16833,8 @@ CVE-2022-24273
 	RESERVED
 CVE-2022-24272
 	REJECTED
-CVE-2022-23400
-	RESERVED
+CVE-2022-23400 (A stack-based buffer overflow vulnerability exists in the IGXMPXMLPars ...)
+	TODO: check
 CVE-2022-0435 (A stack overflow flaw was found in the Linux kernel's TIPC protocol fu ...)
 	{DSA-5096-1 DSA-5092-1 DLA-2941-1 DLA-2940-1}
 	- linux 5.16.10-1
@@ -18309,8 +18537,8 @@ CVE-2021-46442 (In the "webupg" binary of D-Link DIR-825 G1, attackers can bypas
 	NOT-FOR-US: D-Link
 CVE-2021-46441 (In the "webupg" binary of D-Link DIR-825 G1, because of the lack of pa ...)
 	NOT-FOR-US: D-Link
-CVE-2021-46440
-	RESERVED
+CVE-2021-46440 (Storing passwords in a recoverable format in the DOCUMENTATION plugin  ...)
+	TODO: check
 CVE-2021-46439
 	REJECTED
 CVE-2021-46438
@@ -19925,8 +20153,8 @@ CVE-2022-23314 (MCMS v5.2.4 was discovered to contain a SQL injection vulnerabil
 	NOT-FOR-US: MCMS
 CVE-2022-23313
 	RESERVED
-CVE-2022-22137
-	RESERVED
+CVE-2022-22137 (A memory corruption vulnerability exists in the ioca_mys_rgb_allocate  ...)
+	TODO: check
 CVE-2022-21801 (A denial of service vulnerability exists in the netserver recv_command ...)
 	NOT-FOR-US: Reolink
 CVE-2022-21796 (A memory corruption vulnerability exists in the netserver parse_comman ...)
@@ -21097,8 +21325,8 @@ CVE-2022-23065 (In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Store
 	NOT-FOR-US: Vendure
 CVE-2022-23064 (In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Head ...)
 	- snipe-it <itp> (bug #1005172)
-CVE-2022-23063
-	RESERVED
+CVE-2022-23063 (In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Ses ...)
+	TODO: check
 CVE-2022-23062
 	RESERVED
 CVE-2022-23061 (In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently del ...)
@@ -23514,8 +23742,8 @@ CVE-2022-22370
 	RESERVED
 CVE-2022-22369
 	RESERVED
-CVE-2022-22368
-	RESERVED
+CVE-2022-22368 (IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cry ...)
+	TODO: check
 CVE-2022-22367
 	RESERVED
 CVE-2022-22366
@@ -27280,8 +27508,8 @@ CVE-2022-21951
 	RESERVED
 CVE-2022-21950
 	RESERVED
-CVE-2022-21949
-	RESERVED
+CVE-2022-21949 (A Improper Restriction of XML External Entity Reference vulnerability  ...)
+	TODO: check
 CVE-2022-21948
 	RESERVED
 CVE-2022-21947 (A Improper Access Control vulnerability in Rancher Desktop of SUSE all ...)
@@ -39109,8 +39337,8 @@ CVE-2021-42220 (A Cross Site Scripting (XSS) vulnerability exists in Dolibarr be
 	- dolibarr <removed>
 CVE-2021-42219 (Go-Ethereum v1.10.9 was discovered to contain an issue which allows at ...)
 	- golang-github-go-ethereum <itp> (bug #890541)
-CVE-2021-42218
-	RESERVED
+CVE-2021-42218 (OMPL v1.5.2 contains a memory leak in VFRRT.cpp ...)
+	TODO: check
 CVE-2021-42217
 	RESERVED
 CVE-2021-42216 (A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via ...)
@@ -39215,8 +39443,8 @@ CVE-2021-42167
 	RESERVED
 CVE-2021-42166
 	RESERVED
-CVE-2021-42165
-	RESERVED
+CVE-2021-42165 (MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authen ...)
+	TODO: check
 CVE-2021-42164
 	RESERVED
 CVE-2021-42163
@@ -39775,8 +40003,8 @@ CVE-2021-41961
 	RESERVED
 CVE-2021-41960
 	RESERVED
-CVE-2021-41959
-	RESERVED
+CVE-2021-41959 (JerryScript Git version 14ff5bf does not sufficiently track and releas ...)
+	TODO: check
 CVE-2021-41958
 	RESERVED
 CVE-2021-41957
@@ -46093,8 +46321,8 @@ CVE-2021-39392 (The management tool in MyLittleBackup up to and including 1.7 al
 	NOT-FOR-US: MyLittleBackup
 CVE-2021-39391 (Cross Site Scripting (XSS) vulnerability exists in the admin panel in  ...)
 	NOT-FOR-US: Beego
-CVE-2021-39390
-	RESERVED
+CVE-2021-39390 (Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints v ...)
+	TODO: check
 CVE-2021-39389
 	RESERVED
 CVE-2021-39388
@@ -70413,8 +70641,8 @@ CVE-2021-29856 (IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticate
 	NOT-FOR-US: IBM
 CVE-2021-29855 (IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 i ...)
 	NOT-FOR-US: IBM
-CVE-2021-29854
-	RESERVED
+CVE-2021-29854 (IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP  ...)
+	TODO: check
 CVE-2021-29853 (IBM Planning Analytics 2.0 could expose information that could be used ...)
 	NOT-FOR-US: IBM
 CVE-2021-29852 (IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This ...)
@@ -88214,8 +88442,8 @@ CVE-2021-22575
 	RESERVED
 CVE-2021-22574
 	RESERVED
-CVE-2021-22573
-	RESERVED
+CVE-2021-22573 (The vulnerability is that IDToken verifier does not verify if token is ...)
+	TODO: check
 CVE-2021-22572 (On unix-like systems, the system temporary directory is shared between ...)
 	NOT-FOR-US: Google Data Transfer Project
 CVE-2021-22571 (A local attacker could read files from some other users' SA360 reports ...)
@@ -88269,8 +88497,8 @@ CVE-2021-22558
 	RESERVED
 CVE-2021-22557 (SLO generator allows for loading of YAML files that if crafted in a sp ...)
 	NOT-FOR-US: SLO generator
-CVE-2021-22556
-	RESERVED
+CVE-2021-22556 (The Security Team discovered an integer overflow bug that allows an at ...)
+	TODO: check
 CVE-2021-22555 (A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was disco ...)
 	- linux 5.10.38-1
 	[buster] - linux 4.19.194-1
@@ -136228,6 +136456,7 @@ CVE-2020-15080 (In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, s
 CVE-2020-15079 (In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there i ...)
 	NOT-FOR-US: PrestaShop
 CVE-2020-15078 (OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass ...)
+	{DLA-2992-1}
 	- openvpn 2.5.1-2 (bug #987380)
 	[buster] - openvpn 2.4.7-1+deb10u1
 	NOTE: https://github.com/OpenVPN/openvpn/commit/f7b3bf067ffce72e7de49a4174fd17a3a83f0573 (v2.5.2)
@@ -145834,6 +146063,7 @@ CVE-2020-11812 (Rukovoditel 2.5.2 is affected by a SQL injection vulnerability b
 CVE-2020-11811 (In qdPM 9.1, an attacker can upload a malicious .php file to the serve ...)
 	NOT-FOR-US: qdPM
 CVE-2020-11810 (An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can ...)
+	{DLA-2992-1}
 	- openvpn 2.4.9-1 (low)
 	[buster] - openvpn 2.4.7-1+deb10u1
 	[jessie] - openvpn <not-affected> (Vulnerable code introduced in 2.4)
@@ -304090,6 +304320,7 @@ CVE-2017-12168 (The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in t
 CVE-2017-12167 (It was found in EAP 7 before 7.0.9 that properties based files of the  ...)
 	NOT-FOR-US: Red Hat JBoss EAP
 CVE-2017-12166 (OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to ...)
+	{DLA-2992-1}
 	- openvpn 2.4.4-1 (bug #877089)
 	[jessie] - openvpn <no-dsa> (Minor issue)
 	[wheezy] - openvpn <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d22a56296fee6162f8bdf92a888bb63231d4def

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d22a56296fee6162f8bdf92a888bb63231d4def
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220503/11cb9b92/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list