Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
27bec0a8 by security tracker role at 2020-12-13T20:10:30+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2020-35219
+ RESERVED
+CVE-2020-35218
+ RESERVED
+CVE-2020-35217
+ RESERVED
CVE-2020-XXXX [lxml sanitisng in math/svg, similar to CVE-2020-27783]
- lxml 4.6.2-1
[buster] - lxml 4.3.2-1+deb10u1
@@ -8978,7 +8984,7 @@ CVE-2020-27785
CVE-2020-27784
RESERVED
CVE-2020-27783 (A XSS vulnerability was discovered in python-lxml's clean
module. The ...)
- {DLA-2467-1}
+ {DSA-4810-1 DLA-2467-1}
- lxml 4.6.1-1
NOTE:
https://github.com/lxml/lxml/commit/89e7aad6e7ff9ecd88678ff25f885988b184b26e
(lxml-4.6.1)
CVE-2020-27782
@@ -33054,10 +33060,12 @@ CVE-2020-16590 (A double free vulnerability exists in
the Binary File Descriptor
NOTE:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c98a4545dc7bf2bcaf1de539c4eb84784680eaa4
NOTE: binutils not covered by security support
CVE-2020-16589 (A head-based buffer overflow exists in Academy Software
Foundation Ope ...)
+ {DLA-2491-1}
- openexr 2.5.3-2
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/6bb36714528a9563dd3b92720c5063a1284b86f8
(v2.4.0-beta.1)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/issues/494
CVE-2020-16588 (A Null Pointer Deference issue exists in Academy Software
Foundation O ...)
+ {DLA-2491-1}
- openexr 2.5.3-2
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/74504503cff86e986bac441213c403b0ba28d58f
(v2.4.0-beta.1)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/issues/493
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27bec0a80d7d9309b4dc165470349305c7aabcea
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/27bec0a80d7d9309b4dc165470349305c7aabcea
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits