[Git][security-tracker-team/security-tracker][master] buster/bullseye triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue May 17 22:05:07 BST 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
295a2b57 by Moritz Muehlenhoff at 2022-05-17T23:04:43+02:00
buster/bullseye triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,11 +3,10 @@ CVE-2022-30973
 CVE-2022-1770
 	RESERVED
 CVE-2022-1769 (Buffer Over-read in GitHub repository vim/vim prior to 8.2. ...)
-	- vim <unfixed>
-	[bullseye] - vim <no-dsa> (Minor issue)
-	[buster] - vim <no-dsa> (Minor issue)
+	- vim <unfixed> (unimportant)
 	NOTE: https://huntr.dev/bounties/522076b2-96cb-4df6-a504-e6e2f64c171c
 	NOTE: https://github.com/vim/vim/commit/4748c4bd64610cf943a431d215bb1aad51f8d0b4 (v8.2.4974)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2022-1768
 	RESERVED
 CVE-2022-1767
@@ -259,22 +258,20 @@ CVE-2022-1736
 	NOTE: service was enabled by default (and not automatically enabled anymore since 42.1.1-2)
 	TODO: check, if we want to threat this as unimportant severity issue
 CVE-2022-1735 (Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2. ...)
-	- vim <unfixed>
-	[bullseye] - vim <no-dsa> (Minor issue)
-	[buster] - vim <no-dsa> (Minor issue)
+	- vim <unfixed> (unimportant)
 	NOTE: https://huntr.dev/bounties/c9f85608-ff11-48e4-933d-53d1759d44d9
 	NOTE: https://github.com/vim/vim/commit/7ce5b2b590256ce53d6af28c1d203fb3bc1d2d97 (v8.2.4969)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2022-1734
 	RESERVED
 	- linux <unfixed> (unimportant)
 	NOTE: https://git.kernel.org/linus/d270453a0d9ec10bb8a802a142fb1b3601a83098 (5.18-rc6)
 	NOTE: Support for Marvell NFC devices (CONFIG_NFC_MRVL) not enabled
 CVE-2022-1733 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. ...)
-	- vim <unfixed>
-	[bullseye] - vim <no-dsa> (Minor issue)
-	[buster] - vim <no-dsa> (Minor issue)
+	- vim <unfixed> (unimportant)
 	NOTE: https://huntr.dev/bounties/6ff03b27-472b-4bef-a2bf-410fae65ff0a
 	NOTE: https://github.com/vim/vim/commit/60ae0e71490c97f2871a6344aca61cacf220f813 (v8.2.4968)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2022-1732
 	RESERVED
 CVE-2022-1731 (Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/295a2b578e2764252ec6ebb57912dd7b326ea9c8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/295a2b578e2764252ec6ebb57912dd7b326ea9c8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220517/1ba8ec8d/attachment.htm>


More information about the debian-security-tracker-commits mailing list