[Git][security-tracker-team/security-tracker][master] buster/bullseye triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon May 23 08:39:36 BST 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
209bdb15 by Moritz Muehlenhoff at 2022-05-23T09:39:23+02:00
buster/bullseye triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -626,10 +626,10 @@ CVE-2022-30977
 CVE-2022-29496
 	RESERVED
 CVE-2022-1796 (Use After Free in GitHub repository vim/vim prior to 8.2.4979. ...)
-	- vim <unfixed>
-	[stretch] - vim <no-dsa> (Minor issue)
+	- vim <unfixed> (unimportant)
 	NOTE: https://huntr.dev/bounties/f6739b58-49f9-4056-a843-bf76bbc1253e
 	NOTE: https://github.com/vim/vim/commit/28d032cc688ccfda18c5bbcab8b50aba6e18cde5 (v8.2.4979)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2022-1795 (Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. ...)
 	- gpac <unfixed>
 	[stretch] - gpac <end-of-life> (No longer supported in LTS)
@@ -657,6 +657,8 @@ CVE-2022-1786
 	RESERVED
 CVE-2022-1785 (Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977. ...)
 	- vim <unfixed>
+	[bullseye] - vim <no-dsa> (Minor issue)
+	[buster] - vim <no-dsa> (Minor issue)
 	[stretch] - vim <no-dsa> (Minor issue)
 	NOTE: https://huntr.dev/bounties/8c969cba-eef2-4943-b44a-4e3089599109
 	NOTE: https://github.com/vim/vim/commit/e2bd8600b873d2cd1f9d667c28cba8b1dba18839 (v8.2.4977)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/209bdb150e515717c4bc003ff75a5638aa46aae3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/209bdb150e515717c4bc003ff75a5638aa46aae3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220523/5139e875/attachment.htm>


More information about the debian-security-tracker-commits mailing list