Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0d388b13 by Moritz Mühlenhoff at 2024-10-16T15:52:20+02:00
new mysql issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -401,7 +401,7 @@ CVE-2024-21264 (Vulnerability in the PeopleSoft Enterprise 
CC Common Application
 CVE-2024-21263 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
        - virtualbox <unfixed>
 CVE-2024-21262 (Vulnerability in the MySQL Connectors product of Oracle MySQL 
(compone ...)
-       TODO: check
+       - mysql-connector-java <removed>
 CVE-2024-21261 (Vulnerability in Oracle Application Express (component: 
General).  Sup ...)
        NOT-FOR-US: Oracle
 CVE-2024-21260 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
@@ -429,25 +429,25 @@ CVE-2024-21249 (Vulnerability in the PeopleSoft 
Enterprise FIN Expenses product
 CVE-2024-21248 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
        - virtualbox <unfixed>
 CVE-2024-21247 (Vulnerability in the MySQL Client product of Oracle MySQL 
(component:  ...)
-       NOT-FOR-US: MySQL Cluster
+       - mysql-8.0 <unfixed>
 CVE-2024-21246 (Vulnerability in the Oracle Service Bus product of Oracle 
Fusion Middl ...)
        NOT-FOR-US: Oracle
 CVE-2024-21244 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <not-affected> (Only affects 8.4 and later)
 CVE-2024-21243 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <not-affected> (Only affects 8.4 and later)
 CVE-2024-21242 (Vulnerability in the XML Database component of Oracle Database 
Server. ...)
        NOT-FOR-US: Oracle
 CVE-2024-21241 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21239 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21238 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       NOT-FOR-US: MySQL Cluster
+       - mysql-8.0 <unfixed>
 CVE-2024-21237 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21236 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21235 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
        - openjdk-8 <unfixed>
        - openjdk-11 <unfixed>
@@ -458,15 +458,15 @@ CVE-2024-21234 (Vulnerability in the Oracle WebLogic 
Server product of Oracle Fu
 CVE-2024-21233 (Vulnerability in the Oracle Database Core component of Oracle 
Database ...)
        NOT-FOR-US: Oracle
 CVE-2024-21232 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <not-affected> (Only affects 8.4 and later)
 CVE-2024-21231 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21230 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       NOT-FOR-US: MySQL Cluster
+       - mysql-8.0 <unfixed>
 CVE-2024-21219 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21218 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       NOT-FOR-US: MySQL Cluster
+       - mysql-8.0 <unfixed>
 CVE-2024-21217 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
        - openjdk-8 <unfixed>
        - openjdk-11 <unfixed>
@@ -479,9 +479,9 @@ CVE-2024-21215 (Vulnerability in the Oracle WebLogic Server 
product of Oracle Fu
 CVE-2024-21214 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
        NOT-FOR-US: Oracle
 CVE-2024-21213 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21212 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21211 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
        - openjdk-23 <unfixed>
 CVE-2024-21210 (Vulnerability in Oracle Java SE (component: Hotspot).  
Supported versi ...)
@@ -490,42 +490,42 @@ CVE-2024-21210 (Vulnerability in Oracle Java SE 
(component: Hotspot).  Supported
        - openjdk-17 <unfixed>
        - openjdk-21 21.0.5+11-1
 CVE-2024-21209 (Vulnerability in the MySQL Client product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <not-affected> (Only affects 8.4 and later)
 CVE-2024-21208 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
        - openjdk-8 <unfixed>
        - openjdk-11 <unfixed>
        - openjdk-17 <unfixed>
        - openjdk-21 21.0.5+11-1
 CVE-2024-21207 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 8.0.39-1
 CVE-2024-21206 (Vulnerability in the Oracle Enterprise Command Center 
Framework produc ...)
        NOT-FOR-US: Oracle
 CVE-2024-21205 (Vulnerability in the Oracle Service Bus product of Oracle 
Fusion Middl ...)
        NOT-FOR-US: Oracle
 CVE-2024-21204 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <not-affected> (Only affects 8.4 and later)
 CVE-2024-21203 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       NOT-FOR-US: MySQL Cluster
+       - mysql-8.0 <unfixed>
 CVE-2024-21202 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
        NOT-FOR-US: Oracle
 CVE-2024-21201 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21200 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 8.0.36-1
 CVE-2024-21199 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21198 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21197 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21196 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21195 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
        NOT-FOR-US: Oracle
 CVE-2024-21194 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21193 (Vulnerability in the MySQL Server product of Oracle MySQL 
(component:  ...)
-       TODO: check
+       - mysql-8.0 <unfixed>
 CVE-2024-21192 (Vulnerability in the Oracle Enterprise Manager for Fusion 
Middleware p ...)
        NOT-FOR-US: Oracle
 CVE-2024-21191 (Vulnerability in the Oracle Enterprise Manager Fusion 
Middleware Contr ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d388b137f233397d55e598c379e829b7be07022

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d388b137f233397d55e598c379e829b7be07022
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to