[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 23 21:26:41 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
96142902 by Salvatore Bonaccorso at 2022-09-23T22:26:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1103,25 +1103,25 @@ CVE-2022-40871
 CVE-2022-40870
 	RESERVED
 CVE-2022-40869 (Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulner ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40868 (Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40867 (Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40866 (Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40865 (Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnera ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40864 (Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulner ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40863
 	RESERVED
 CVE-2022-40862 (Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulner ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40861 (Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40860 (Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40859
 	RESERVED
 CVE-2022-40858
@@ -1131,15 +1131,15 @@ CVE-2022-40857
 CVE-2022-40856
 	RESERVED
 CVE-2022-40855 (Tenda W20E router V15.11.0.6 contains a stack overflow in the function ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40854 (Tenda AC18 router contained a stack overflow vulnerability in /goform/ ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40853 (Tenda AC15 router V15.03.05.19 contains a stack overflow via the list  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40852
 	RESERVED
 CVE-2022-40851 (Tenda AC15 V15.03.05.19 contained a stack overflow via the function fr ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40850
 	RESERVED
 CVE-2022-40849
@@ -1357,7 +1357,7 @@ CVE-2022-40750
 CVE-2022-40749
 	RESERVED
 CVE-2022-40748 (IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-40747
 	RESERVED
 CVE-2022-40746
@@ -2892,7 +2892,7 @@ CVE-2022-3146
 CVE-2022-3145
 	RESERVED
 CVE-2022-3144 (The Wordfence Security – Firewall & Malware Scan plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-3143
 	RESERVED
 	NOT-FOR-US: WildFly Elytron
@@ -2961,21 +2961,21 @@ CVE-2022-40109 (TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vuln
 CVE-2022-40108
 	RESERVED
 CVE-2022-40107 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40106 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40105 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40104 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40103 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40102 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40101 (Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow vi ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40100 (Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2022-40099
 	RESERVED
 CVE-2022-40098
@@ -6595,7 +6595,7 @@ CVE-2022-2938 (A flaw was found in the Linux kernel's implementation of Pressure
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/a06247c6804f1a7c86a2e5398a4c1f1db1471848 (5.17-rc2)
 CVE-2022-2937 (The Image Hover Effects Ultimate plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: Image Hover Effects Ultimate plugin for WordPress
 CVE-2022-2936 (The Image Hover Effects Ultimate plugin for WordPress is vulnerable to ...)
 	NOT-FOR-US: Image Hover Effects Ultimate plugin for WordPress
 CVE-2022-2935 (The Image Hover Effects Ultimate plugin for WordPress is vulnerable to ...)
@@ -14324,7 +14324,7 @@ CVE-2022-35723
 CVE-2022-35722
 	RESERVED
 CVE-2022-35721 (IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-si ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-35720
 	RESERVED
 CVE-2022-35719
@@ -18154,7 +18154,7 @@ CVE-2022-34350
 CVE-2022-34349
 	RESERVED
 CVE-2022-34348 (IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML Ex ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-2190
 	RESERVED
 CVE-2022-2189 (The WP Video Lightbox WordPress plugin before 1.9.5 does not escape th ...)
@@ -54234,7 +54234,7 @@ CVE-2022-22425
 CVE-2022-22424 (IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain s ...)
 	NOT-FOR-US: IBM
 CVE-2022-22423 (IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-22422
 	RESERVED
 CVE-2022-22421



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/961429023422bbd610b8dacab7e0d5085bbc2e66

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/961429023422bbd610b8dacab7e0d5085bbc2e66
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220923/5bb43280/attachment.htm>


More information about the debian-security-tracker-commits mailing list