[Git][security-tracker-team/security-tracker][master] 2 commits: Process NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Nov 30 10:37:31 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
85f3014e by Salvatore Bonaccorso at 2022-11-30T11:34:40+01:00
Process NFUs

- - - - -
bd6a0a02 by Salvatore Bonaccorso at 2022-11-30T11:37:03+01:00
Add CVE-2022-45332/libredwg

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15,7 +15,7 @@ CVE-2022-4224
 CVE-2022-4223
 	RESERVED
 CVE-2022-4222 (A vulnerability was found in SourceCodester Canteen Management System. ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester Canteen Management System
 CVE-2022-4221
 	RESERVED
 CVE-2022-4220
@@ -2297,7 +2297,7 @@ CVE-2022-4036 (The Appointment Hour Booking plugin for WordPress is vulnerable t
 CVE-2022-4035 (The Appointment Hour Booking plugin for WordPress is vulnerable to iFr ...)
 	NOT-FOR-US: Appointment Hour Booking plugin for WordPress
 CVE-2022-4034 (The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV ...)
-	TODO: check
+	NOT-FOR-US: Appointment Hour Booking Plugin for WordPress
 CVE-2022-4033 (The Quiz and Survey Master plugin for WordPress is vulnerable to input ...)
 	NOT-FOR-US: Quiz and Survey Master plugin for WordPress
 CVE-2022-4032 (The Quiz and Survey Master plugin for WordPress is vulnerable to iFram ...)
@@ -2916,7 +2916,7 @@ CVE-2022-45334
 CVE-2022-45333
 	RESERVED
 CVE-2022-45332 (LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow ...)
-	TODO: check
+	- libredwg <itp> (bug #595191)
 CVE-2022-45331 (AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability ...)
 	NOT-FOR-US: AeroCMS
 CVE-2022-45330 (AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability ...)
@@ -2924,7 +2924,7 @@ CVE-2022-45330 (AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnera
 CVE-2022-45329 (AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability ...)
 	NOT-FOR-US: AeroCMS
 CVE-2022-45328 (Church Management System v1.0 was discovered to contain a SQL injectio ...)
-	TODO: check
+	NOT-FOR-US: Church Management System
 CVE-2022-45327
 	RESERVED
 CVE-2022-45326
@@ -3132,13 +3132,13 @@ CVE-2022-45226
 CVE-2022-45225 (Book Store Management System v1.0 was discovered to contain a cross-si ...)
 	NOT-FOR-US: Book Store Management System
 CVE-2022-45224 (Web-Based Student Clearance System v1.0 was discovered to contain a cr ...)
-	TODO: check
+	NOT-FOR-US: Web-Based Student Clearance System
 CVE-2022-45223 (Web-Based Student Clearance System v1.0 was discovered to contain a cr ...)
-	TODO: check
+	NOT-FOR-US: Web-Based Student Clearance System
 CVE-2022-45222
 	RESERVED
 CVE-2022-45221 (Web-Based Student Clearance System v1.0 was discovered to contain a cr ...)
-	TODO: check
+	NOT-FOR-US: Web-Based Student Clearance System
 CVE-2022-45220
 	RESERVED
 CVE-2022-45219
@@ -3152,7 +3152,7 @@ CVE-2022-45216
 CVE-2022-45215
 	RESERVED
 CVE-2022-45214 (A cross-site scripting (XSS) vulnerability in Sanitization Management  ...)
-	TODO: check
+	NOT-FOR-US: Sanitization Management System
 CVE-2022-45213
 	RESERVED
 CVE-2022-45212



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/82ab383d1f75d9ba27ec3d1cf89e7a70c6b2e9c4...bd6a0a021d70f91e3644210a2c185ba24f0b7932

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/82ab383d1f75d9ba27ec3d1cf89e7a70c6b2e9c4...bd6a0a021d70f91e3644210a2c185ba24f0b7932
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221130/99b5b5e4/attachment.htm>


More information about the debian-security-tracker-commits mailing list