[Git][security-tracker-team/security-tracker][master] Track some tensorflow CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 17 09:35:04 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
75f96b8e by Salvatore Bonaccorso at 2022-09-17T10:34:18+02:00
Track some tensorflow CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12178,9 +12178,9 @@ CVE-2022-36029
 CVE-2022-36028
 	RESERVED
 CVE-2022-36027 (TensorFlow is an open source platform for machine learning. When conve ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36026 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36025
 	RESERVED
 CVE-2022-36024 (py-cord is a an API wrapper for Discord written in Python. Bots creati ...)
@@ -12194,23 +12194,23 @@ CVE-2022-36021
 CVE-2022-36020 (The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, ...)
 	TODO: check
 CVE-2022-36019 (TensorFlow is an open source platform for machine learning. If `FakeQu ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36018 (TensorFlow is an open source platform for machine learning. If `Ragged ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36017 (TensorFlow is an open source platform for machine learning. If `Requan ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36016 (TensorFlow is an open source platform for machine learning. When `tens ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36015 (TensorFlow is an open source platform for machine learning. When `Rang ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36014 (TensorFlow is an open source platform for machine learning. When `mlir ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36013 (TensorFlow is an open source platform for machine learning. When `mlir ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36012 (TensorFlow is an open source platform for machine learning. When `mlir ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36011 (TensorFlow is an open source platform for machine learning. When `mlir ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36010 (This library allows strings to be parsed as functions and stored as a  ...)
 	NOT-FOR-US: oxyno-zeta
 CVE-2022-36009 (gomatrixserverlib is a Go library for matrix protocol federation. Dend ...)
@@ -12222,59 +12222,59 @@ CVE-2022-36007 (Venice is a Clojure inspired sandboxed Lisp dialect with excelle
 CVE-2022-36006 (Arvados is an open source platform for managing, processing, and shari ...)
 	NOT-FOR-US: Arvados
 CVE-2022-36005 (TensorFlow is an open source platform for machine learning. When `tf.q ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36004 (TensorFlow is an open source platform for machine learning. When `tf.r ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36003 (TensorFlow is an open source platform for machine learning. When `Rand ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36002 (TensorFlow is an open source platform for machine learning. When `Unba ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36001 (TensorFlow is an open source platform for machine learning. When `Draw ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-36000 (TensorFlow is an open source platform for machine learning. When `mlir ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35999 (TensorFlow is an open source platform for machine learning. When `Conv ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35998 (TensorFlow is an open source platform for machine learning. If `EmptyT ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35997 (TensorFlow is an open source platform for machine learning. If `tf.spa ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35996 (TensorFlow is an open source platform for machine learning. If `Conv2D ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35995 (TensorFlow is an open source platform for machine learning. When `Audi ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35994 (TensorFlow is an open source platform for machine learning. When `Coll ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35993 (TensorFlow is an open source platform for machine learning. When `SetS ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35992 (TensorFlow is an open source platform for machine learning. When `Tens ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35991 (TensorFlow is an open source platform for machine learning. When `Tens ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35990 (TensorFlow is an open source platform for machine learning. When `tf.q ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35989 (TensorFlow is an open source platform for machine learning. When `MaxP ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35988 (TensorFlow is an open source platform for machine learning. When `tf.l ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35987 (TensorFlow is an open source platform for machine learning. `DenseBinc ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35986 (TensorFlow is an open source platform for machine learning. If `Ragged ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35985 (TensorFlow is an open source platform for machine learning. If `LRNGra ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35984 (TensorFlow is an open source platform for machine learning. `Parameter ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35983 (TensorFlow is an open source platform for machine learning. If `Save`  ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35982 (TensorFlow is an open source platform for machine learning. If `Sparse ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35981 (TensorFlow is an open source platform for machine learning. `Fractiona ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35980 (OpenSearch Security is a plugin for OpenSearch that offers encryption, ...)
 	NOT-FOR-US: OpenSearch Security plugin for OpenSearch
 CVE-2022-35979 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35978 (Minetest is a free open-source voxel game engine with easy modding and ...)
 	- minetest 5.5.0+dfsg+~1.9.0mt4+dfsg-2 (bug #1017548)
 	[bullseye] - minetest <no-dsa> (Minor issue)
@@ -12288,37 +12288,37 @@ CVE-2022-35976 (The GitOps Tools Extension for VSCode relies on kubeconfigs in o
 CVE-2022-35975 (The GitOps Tools Extension for VSCode can make it easier to manage Flu ...)
 	NOT-FOR-US: GitOps Tools Extension for VSCode
 CVE-2022-35974 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35973 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35972 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35971 (TensorFlow is an open source platform for machine learning. If `FakeQu ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35970 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35969 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35968 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35967 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35966 (TensorFlow is an open source platform for machine learning. If `Quanti ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35965 (TensorFlow is an open source platform for machine learning. If `LowerB ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35964 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35963 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35962 (Zulip is an open source team chat and Zulip Mobile is an app for iOS a ...)
 	NOT-FOR-US: Zulip
 CVE-2022-35961 (OpenZeppelin Contracts is a library for secure smart contract developm ...)
 	NOT-FOR-US: OpenZeppelin
 CVE-2022-35960 (TensorFlow is an open source platform for machine learning. In `core/k ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35959 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35958
 	REJECTED
 CVE-2022-35957
@@ -12332,7 +12332,7 @@ CVE-2022-35954 (The GitHub Actions ToolKit provides a set of packages to make cr
 CVE-2022-35953 (BookWyrm is a social network for tracking your reading, talking about  ...)
 	NOT-FOR-US: BookWyrm
 CVE-2022-35952 (TensorFlow is an open source platform for machine learning. The `Unbat ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35951
 	RESERVED
 CVE-2022-35950
@@ -12361,21 +12361,21 @@ CVE-2022-35943 (Shield is an authentication and authorization framework for Code
 CVE-2022-35942 (Improper input validation on the `contains` LoopBack filter may allow  ...)
 	NOT-FOR-US: PostgreSQL connector for LoopBack
 CVE-2022-35941 (TensorFlow is an open source platform for machine learning. The `AvgPo ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35940 (TensorFlow is an open source platform for machine learning. The `Ragge ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35939 (TensorFlow is an open source platform for machine learning. The `Scatt ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35938 (TensorFlow is an open source platform for machine learning. The `Gathe ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35937 (TensorFlow is an open source platform for machine learning. The `Gathe ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35936 (Ethermint is an Ethereum library. In Ethermint running versions before ...)
 	NOT-FOR-US: Ethermint
 CVE-2022-35935 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35934 (TensorFlow is an open source platform for machine learning. The implem ...)
-	TODO: check
+	- tensorflow <itp> (bug #804612)
 CVE-2022-35933 (This package is a PrestaShop module that allows users to post reviews  ...)
 	NOT-FOR-US: PrestaShop
 CVE-2022-35932 (Nextcloud Talk is a video and audio conferencing app for Nextcloud. Pr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75f96b8ef8b85daa87618fd9a66e04c67d4ee5ce

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75f96b8ef8b85daa87618fd9a66e04c67d4ee5ce
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220917/cb8d7974/attachment.htm>


More information about the debian-security-tracker-commits mailing list