[Git][security-tracker-team/security-tracker][master] Process YottaDB CVEs

Neil Williams (@codehelp) codehelp at debian.org
Wed May 25 16:01:32 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
db85f774 by Neil Williams at 2022-05-25T15:59:09+01:00
Process YottaDB CVEs

Confirmed with YottaDB upstream that YottaDB is built around a
fork of FIS GT.M which is maintained separately from FIS.
Only report CVEs against FIS GT.M if the CVE is filed against
FIS GT.M or linked to Release Notes from FIS, not just YottaDB GitLab.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -34112,38 +34112,27 @@ CVE-2021-44492 (An issue was discovered in YottaDB through r1.32 and V7.0-000 an
 	NOTE: http://tinco.pair.com/bhaskar/gtm/doc/articles/GTM_V7.0-002_Release_Notes.html
 	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
 CVE-2021-44491 (An issue was discovered in YottaDB through r1.32 and V7.0-000. Using c ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44490 (An issue was discovered in YottaDB through r1.32 and V7.0-000. Using c ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44489 (An issue was discovered in YottaDB through r1.32 and V7.0-000. Using c ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44488 (An issue was discovered in YottaDB through r1.32 and V7.0-000. Using c ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44487 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44486 (An issue was discovered in YottaDB through r1.32 and V7.0-000. Using c ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44485 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44484 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44483 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44482 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44481 (An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack  ...)
-	NOTE: https://gitlab.com/YottaDB/DB/YDB/-/issues/828
-	TODO: check - unclear if affects only YottaDB
+	NOT-FOR-US: YottaDB
 CVE-2021-44480 (Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who ...)
 	NOT-FOR-US: Wokka Lokka Q50 devices
 CVE-2021-44479 (NXP Kinetis K82 devices have a buffer over-read via a crafted wlength  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db85f774530d1047ed9976c20b0c8ca48a98ce9f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db85f774530d1047ed9976c20b0c8ca48a98ce9f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220525/7d5b988f/attachment.htm>


More information about the debian-security-tracker-commits mailing list