[Git][security-tracker-team/security-tracker][master] Demote CVE-2021-40648 to unimportant

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Oct 20 15:44:55 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b1b6b40f by Salvatore Bonaccorso at 2024-10-20T16:44:26+02:00
Demote CVE-2021-40648 to unimportant

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -242505,11 +242505,9 @@ CVE-2021-40650 (In Connx Version 6.2.0.1269 (20210623), a cookie can be issued b
 CVE-2021-40649 (In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the  ...)
 	NOT-FOR-US: Connx
 CVE-2021-40648 (In man2html 1.6g, a filename can be created to overwrite the previous  ...)
-	- man2html <unfixed> (bug #1062069)
-	[bookworm] - man2html <no-dsa> (Minor issue)
-	[bullseye] - man2html <no-dsa> (Minor issue)
-	[buster] - man2html <no-dsa> (Minor issue)
+	- man2html <unfixed> (bug #1062069; unimportant)
 	NOTE: https://gist.github.com/untaman/cb58123fe89fc65e3984165db5d40933
+	NOTE: Negligible impact and potentially disputed (cf. gist comments)
 CVE-2021-40647 (In man2html 1.6g, a specific string being read in from a file will ove ...)
 	- man2html 1.6g-16 (bug #1021738)
 	[bookworm] - man2html <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b1b6b40fad6a4daa8eeb33267a5bde268eb15f77

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b1b6b40fad6a4daa8eeb33267a5bde268eb15f77
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241020/2375392e/attachment.htm>


More information about the debian-security-tracker-commits mailing list