Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
002d7587 by security tracker role at 2020-11-21T08:10:24+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2455,7 +2455,7 @@ CVE-2020-28362 (Go before 1.14.12 and 1.15.x before 
1.15.4 allows Denial of Serv
        [stretch] - golang-1.7 <not-affected> (Vulnerable code introduced later)
        NOTE: 
https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ
        NOTE: https://github.com/golang/go/issues/42552
-CVE-2020-28974 [slab-out-of-bounds Read in fbcon]
+CVE-2020-28974 (A slab-out-of-bounds read in fbcon in the Linux kernel before 
5.9.7 co ...)
        - linux 5.9.9-1
        NOTE: 
https://git.kernel.org/linus/3c4e0dff2095c579b142d5a0693257f1c58b4804
        NOTE: https://www.openwall.com/lists/oss-security/2020/11/09/2
@@ -10330,8 +10330,7 @@ CVE-2020-25727 (The Reset Password add-on before 1.2.0 
for Alfresco suffers from
        NOT-FOR-US: Reset Password add-on for Alfresco
 CVE-2020-25726
        REJECTED
-CVE-2020-25725
-       RESERVED
+CVE-2020-25725 (In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) 
SplashOut ...)
        - xpdf <not-affected> (Debian uses poppler, which is not affected)
        NOTE: https://forum.xpdfreader.com/viewtopic.php?f=3&t=41915
 CVE-2020-25724
@@ -11701,8 +11700,8 @@ CVE-2020-25187
        RESERVED
 CVE-2020-25186 (An XXE vulnerability exists within LeviStudioU Release Build 
2019-09-2 ...)
        NOT-FOR-US: LeviStudioU Release
-CVE-2020-25185
-       RESERVED
+CVE-2020-25185 (The affected product is vulnerable to five post-authentication 
buffer  ...)
+       TODO: check
 CVE-2020-25184
        RESERVED
 CVE-2020-25183
@@ -50792,7 +50791,7 @@ CVE-2020-8825 (index.php?p=/dashboard/settings/branding 
in Vanilla 2.6.3 allows
        NOT-FOR-US: Vanilla Forums
 CVE-2020-8824 (Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed 
Device name ...)
        NOT-FOR-US: Hitron devices
-CVE-2020-8823 (htmlfile in lib/transport/htmlfile.js in SockJS before 3.0 is 
vulnerab ...)
+CVE-2020-8823 (htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is 
vulner ...)
        NOT-FOR-US: SockJS
 CVE-2020-8822 (Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 
devices  ...)
        NOT-FOR-US: Digi TransPort
@@ -58472,8 +58471,8 @@ CVE-2020-5799
        RESERVED
 CVE-2020-5798
        RESERVED
-CVE-2020-5797
-       RESERVED
+CVE-2020-5797 (UNIX Symbolic Link (Symlink) Following in TP-Link Archer 
C9(US)_V1_180 ...)
+       TODO: check
 CVE-2020-5796 (Improper preservation of permissions in Nagios XI 5.7.4 allows 
a local ...)
        NOT-FOR-US: Nagios XI
 CVE-2020-5795 (UNIX Symbolic Link (Symlink) Following in TP-Link Archer 
A7(US)_V5_200 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/002d7587967b8b8c888ec4da9422b581e7bd64f6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/002d7587967b8b8c888ec4da9422b581e7bd64f6
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to