Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
baca26fd by Moritz Muehlenhoff at 2021-06-07T17:19:22+02:00
resolve some TODOs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1591,7 +1591,6 @@ CVE-2021-33198
- golang-1.7 <removed>
NOTE: https://github.com/golang/go/issues/44910
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33197
RESERVED
- golang-1.16 1.16.5-1
@@ -1612,7 +1611,6 @@ CVE-2021-33196 [archive/zip: malformed archive may cause
panic or memory exhaust
NOTE: https://github.com/golang/go/issues/46242
NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33195
RESERVED
- golang-1.16 1.16.5-1
@@ -1622,7 +1620,6 @@ CVE-2021-33195
- golang-1.7 <removed>
NOTE: https://github.com/golang/go/issues/46241
NOTE: https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI
- TODO: check completeness/correctness of the tracking
CVE-2021-33194 (Go through 1.15.12 and 1.16.x through 1.16.4 has a
golang.org/x/net/ht ...)
- golang-golang-x-net 1:0.0+git20210119.5f4716e+dfsg-4
- golang-golang-x-net-dev <removed>
@@ -2846,9 +2843,9 @@ CVE-2021-32637 (Authelia is a a single sign-on
multi-factor portal for web apps.
CVE-2021-32636
RESERVED
CVE-2021-32635 (### Impact Due to incorrect use of a default URL,
`singularity` action ...)
- - singularity-container <undetermined>
+ - singularity-container <not-affected> (Vulnerable code introduced in
3.7.2)
NOTE:
https://github.com/hpcng/singularity/security/advisories/GHSA-jq42-hfch-42f3
- TODO: might only affect 3.7.2 and 3.7.3 according to
GHSA-jq42-hfch-42f3 and so not-affected
+ NOTE:
https://github.com/hpcng/singularity/commit/cd298aaeb7698fb692689e2e1b49972c94bfa440
CVE-2021-32634 (Emissary is a distributed, peer-to-peer, data-driven workflow
framewor ...)
NOT-FOR-US: NSA Emissary
CVE-2021-32633 (Zope is an open-source web application server. In Zope
versions prior ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/baca26fdddc1510ff3439ab0981d119787ae0fae
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits