[Git][security-tracker-team/security-tracker][master] 2 commits: Process an NFU

Neil Williams (@codehelp) codehelp at debian.org
Mon May 9 10:51:57 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9ae24504 by Neil Williams at 2022-05-09T10:43:35+01:00
Process an NFU

- - - - -
08254e3e by Neil Williams at 2022-05-09T10:51:25+01:00
CVE-2021-42218/opml unfixed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -40228,7 +40228,9 @@ CVE-2021-42220 (A Cross Site Scripting (XSS) vulnerability exists in Dolibarr be
 CVE-2021-42219 (Go-Ethereum v1.10.9 was discovered to contain an issue which allows at ...)
 	- golang-github-go-ethereum <itp> (bug #890541)
 CVE-2021-42218 (OMPL v1.5.2 contains a memory leak in VFRRT.cpp ...)
-	TODO: check
+	- ompl <unfixed>
+	NOTE: https://github.com/ompl/ompl/issues/839
+	NOTE: https://github.com/ompl/ompl/commit/abb4fadcb4e4fe4c9cf41e5e7706143a66948eb7
 CVE-2021-42217
 	RESERVED
 CVE-2021-42216 (A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via ...)
@@ -48972,7 +48974,7 @@ CVE-2021-38694 (SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection. ...)
 CVE-2020-36473 (UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and th ...)
 	NOT-FOR-US: UCWeb UC
 CVE-2021-38693 (A path traversal vulnerability has been reported to affect QNAP device ...)
-	TODO: check
+	NOT-FOR-US: QNAP
 CVE-2021-38692 (A stack buffer overflow vulnerability has been reported to affect QNAP ...)
 	NOT-FOR-US: QNAP
 CVE-2021-38691 (A stack buffer overflow vulnerability has been reported to affect QNAP ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cd09e50dee4a0b66e173af9175c83c49dbc38f7c...08254e3e98eb81c558cd89d493ec280341da6ac0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cd09e50dee4a0b66e173af9175c83c49dbc38f7c...08254e3e98eb81c558cd89d493ec280341da6ac0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220509/1c37d3f4/attachment.htm>


More information about the debian-security-tracker-commits mailing list