[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3978/cfrpki

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jan 30 13:54:30 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a9cd0fb2 by Salvatore Bonaccorso at 2025-01-30T14:52:52+01:00
Add CVE-2021-3978/cfrpki

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -261564,7 +261564,8 @@ CVE-2021-44020 (An unnecessary privilege vulnerability in Trend Micro Worry-Free
 CVE-2021-44019 (An unnecessary privilege vulnerability in Trend Micro Worry-Free Busin ...)
 	NOT-FOR-US: Trend Micro
 CVE-2021-3978 (When copying files with rsync, octorpki uses the "-a" flag 0, which fo ...)
-	TODO: check
+	- cfrpki 1.4.2-1
+	NOTE: https://github.com/cloudflare/cfrpki/security/advisories/GHSA-3pqh-p72c-fj85
 CVE-2021-3977 (invoiceninja is vulnerable to Improper Neutralization of Input During  ...)
 	NOT-FOR-US: invoiceninja
 CVE-2021-44018 (A vulnerability has been identified in JT2Go (All versions < V13.2.0.7 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9cd0fb289d80a5b044fee6cec2c97d9e188e9f8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9cd0fb289d80a5b044fee6cec2c97d9e188e9f8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250130/d1a78922/attachment.htm>


More information about the debian-security-tracker-commits mailing list