Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 18cc2dda by Salvatore Bonaccorso at 2020-06-17T19:35:51+02:00 Remove notes from CVE-2020-10747 Red Hat has withdrawn the assigned CVE and REJECTED it because as outlined in <https://bugzilla.redhat.com/show_bug.cgi?id=1810160> the issue is not crossing boundaries and the corresponding update from <https://pagure.io/freeipa/issue/8326> is considered a configuration tightening. In any case the CVE is REJECTED from the assigning CNA (Red Hat) and will be marked as such soon. Remove the unneded references. - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -9954,14 +9954,8 @@ CVE-2020-10749 (A vulnerability was found in all versions of containernetworking NOTE: https://github.com/containernetworking/plugins/commit/219eb9e0464761c47383d239aba206da695e1a43 CVE-2020-10748 RESERVED -CVE-2020-10747 [local account takeover/HBAC rules bypass] - RESERVED - - freeipa <unfixed> - NOTE: https://pagure.io/freeipa/issue/8326 - NOTE: https://pagure.io/freeipa/c/4911a3f05514a7c0ac66e4ef5004581cced8519f (master) - NOTE: https://pagure.io/freeipa/c/930f4b3d1dc03f9e365b007b027d65e146a08f05 (ipa-4-8) - NOTE: https://pagure.io/freeipa/c/62400d6d240c1bb68987a1ff194ee7cd6c6d3cf0 (ipa-4-6) - NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1810160 +CVE-2020-10747 + REJECTED CVE-2020-10746 RESERVED CVE-2020-10745 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
