[Git][security-tracker-team/security-tracker][master] Update association for CVE-2022-0317 with golang-github-google-go-attestation

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 10:37:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a4477ecd by Salvatore Bonaccorso at 2026-09-12T11:36:16+02:00
Update association for CVE-2022-0317 with golang-github-google-go-attestation

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -546598,7 +546598,8 @@ CVE-2022-0318 (Heap-based Buffer Overflow in vim/vim prior to 8.2.)
 	NOTE: https://github.com/vim/vim/commit/57df9e8a9f9ae1aafdde9b86b10ad907627a87dc (v8.2.4151)
 	NOTE: Crash in CLI tool, no security impact
 CVE-2022-0317 (An improper input validation vulnerability in go-attestation before 0. ...)
-	NOT-FOR-US: go-attestation
+	- golang-github-google-go-attestation <not-affected> (Fixed before initial upload to Debian)
+	NOTE: https://github.com/google/go-attestation/security/advisories/GHSA-99cg-575x-774p
 CVE-2022-0316 (The WeStand WordPress theme before 2.1, footysquare WordPress theme, a ...)
 	NOT-FOR-US: WordPress theme
 CVE-2022-0315 (Insecure Temporary File in GitHub repository horovod/horovod prior to  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4477ecd328c07702b7d4dfc0df1f061c91c4794

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4477ecd328c07702b7d4dfc0df1f061c91c4794
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/4158ceba/attachment.htm>


More information about the debian-security-tracker-commits mailing list