[Git][security-tracker-team/security-tracker][master] Update information on CVE-2022-29526
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu May 12 21:09:50 BST 2022
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3f1e3107 by Salvatore Bonaccorso at 2022-05-12T22:09:22+02:00
Update information on CVE-2022-29526
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3109,12 +3109,16 @@ CVE-2022-29526
RESERVED
- golang-1.18 <unfixed>
- golang-1.17 <unfixed>
+ - golang-1.15 <removed>
+ - golang-1.11 <not-affected> (Vulnerable code introduced later)
+ - golang-1.8 <not-affected> (Vulnerable code introduced later)
+ - golang-1.7 <not-affected> (Vulnerable code introduced later)
NOTE: https://go.dev/issue/52313
NOTE: https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU
NOTE: Master : https://github.com/golang/go/commit/f66925e854e71e0c54b581885380a490d7afa30c
NOTE: Branch.go1.17 : https://github.com/golang/go/commit/04781d14d2d33acbaf70f77e3a58ae0f3c90757c (1.17.10)
NOTE: Branch.go1.18 : https://github.com/golang/go/commit/c0599c5b781de023974519194df6b0c4ebb0adff (1.18.2)
- TODO: check older versions
+ NOTE: Introduced by: https://github.com/golang/go/commit/60f78765022a59725121d3b800268adffe78bde3 (go1.15rc1)
CVE-2022-1417 (Improper access control in GitLab CE/EE affecting all versions startin ...)
TODO: check
CVE-2022-1416
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f1e310790dff9bf62ce557c7cd17f874007bec9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f1e310790dff9bf62ce557c7cd17f874007bec9
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220512/f7202c32/attachment.htm>
More information about the debian-security-tracker-commits
mailing list