Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9d20d4f3 by Salvatore Bonaccorso at 2026-08-14T06:04:35+02:00
Sync some NOTE format with current practice

- - - - -
783cc5b9 by Salvatore Bonaccorso at 2026-08-14T06:09:51+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,25 +1,25 @@
 CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open 
redirect ...)
-       TODO: check
+       NOT-FOR-US: Saurus CMS
 CVE-2026-73670 (A CMS contains a SQL injection vulnerability in 
admin/db_data.php at l ...)
-       TODO: check
+       NOT-FOR-US: Saurus CMS
 CVE-2026-73653 (Vitest is a testing framework powered by Vite. Prior to 
versions 3.2.7 ...)
-       TODO: check
+       NOT-FOR-US: Vitest
 CVE-2026-73652 (vantage6 is an open-source infrastructure for privacy 
preserving analy ...)
-       TODO: check
+       NOT-FOR-US: vantage6
 CVE-2026-73651 (TypeORM is a TypeScript and JavaScript ORM for Node.js that 
supports P ...)
-       TODO: check
+       NOT-FOR-US: TypeORM
 CVE-2026-73650 (SVGO, short for SVG Optimizer, is a Node.js library and 
command-line a ...)
        TODO: check
 CVE-2026-73649 (Velocity.js is a JavaScript implementation of the Apache 
Velocity temp ...)
-       TODO: check
+       NOT-FOR-US: Velocity.js
 CVE-2026-73648 (rails-html-sanitizer is responsible for sanitizing HTML 
fragments in R ...)
        TODO: check
 CVE-2026-73647 (Quasar Framework is a framework for building high-performance 
Vue.js u ...)
-       TODO: check
+       NOT-FOR-US: Quasar Framework
 CVE-2026-73645 (OpenZeppelin Confidential Contracts is an experimental library 
for dev ...)
-       TODO: check
+       NOT-FOR-US: OpenZeppelin
 CVE-2026-73644 (OpenDJ is an LDAPv3 compliant directory service. Prior to 
5.1.2, the S ...)
-       TODO: check
+       NOT-FOR-US: OpenDJ
 CVE-2026-73643 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 
until 5.2.2 ...)
        TODO: check
 CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request 
forgery vulner ...)
@@ -13086,7 +13086,7 @@ CVE-2026-58041 (A flaw in Node.js node:sqlite allows a 
stale StatementSyncIterat
 CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows 
`nghttp2_session_mem_send()`  ...)
        - nodejs 24.19.0+dfsg+~cs24.13.3-1
        NOTE: 
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
-       NOTE: Fixed by 
https://github.com/nodejs/node/commit/daa6d25e3dceb30edb832a778ec0610c8bc2dd12 
(v22.23.2)
+       NOTE: Fixed by: 
https://github.com/nodejs/node/commit/daa6d25e3dceb30edb832a778ec0610c8bc2dd12 
(v22.23.2)
 CVE-2026-56846 (A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained 
header blo ...)
        - nodejs 24.19.0+dfsg+~cs24.13.3-1
        NOTE: 
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high
@@ -13213,7 +13213,7 @@ CVE-2026-56847 (A flaw in Node.js Permission Model 
enforcement allows `trace_eve
        [bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ 
feature)
        [bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ 
feature)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-trace-events-to-write-outside-the-allowlist-cve-2026-56847---low
-       NOTE: Fixed by 
https://github.com/nodejs/node/commit/0566c3cccdc99b935646e813f71e2380aedee50d 
(v22.23.2)
+       NOTE: Fixed by: 
https://github.com/nodejs/node/commit/0566c3cccdc99b935646e813f71e2380aedee50d 
(v22.23.2)
 CVE-2026-54249 (Pydantic AI is a Python agent framework for building 
Generative AI app ...)
        NOT-FOR-US: Pydantic AI
 CVE-2026-50782 (Jinher OA C6 contains an XML External Entity (XXE) injection 
vulnerabi ...)
@@ -49787,7 +49787,7 @@ CVE-2026-44663 (OpenEXR is the reference implementation 
and specification for th
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-777r-f9x8-7r84
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2403
        NOTE: Introduced by 
https://github.com/AcademySoftwareFoundation/openexr/commit/50ba96b1dbe353a98a626c7fd0ff1e50cc8c188f
 (v3.4-alpha)
-       NOTE: Fixed by 
https://github.com/AcademySoftwareFoundation/openexr/commit/3e2a99a55b1ee3dc5b962bf2cfde86eb24cc6897
 (v3.4.13-rc)
+       NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/3e2a99a55b1ee3dc5b962bf2cfde86eb24cc6897
 (v3.4.13-rc)
 CVE-2026-43994 (Coturn is a free open source implementation of TURN and STUN 
Server. V ...)
        - coturn 4.12.0-1 (bug #1140563)
        [trixie] - coturn <no-dsa> (Minor issue)
@@ -80012,7 +80012,7 @@ CVE-2026-42285 (GoBGP is an open source Border Gateway 
Protocol (BGP) implementa
        [bookworm] - gobgp <not-affected> (Vulnerable code not present, 
introduced in 4.4.0)
        [bullseye] - gobgp <not-affected> (Vulnerable code not present, 
introduced in 4.4.0)
        NOTE: 
https://github.com/osrg/gobgp/security/advisories/GHSA-p3w2-64xm-833j
-       NOTE: Fixed by 
https://github.com/osrg/gobgp/commit/d2d2be3e4e7915d407e662e5d388d9f8ae8a8f7b 
(v4.5.0)
+       NOTE: Fixed by: 
https://github.com/osrg/gobgp/commit/d2d2be3e4e7915d407e662e5d388d9f8ae8a8f7b 
(v4.5.0)
 CVE-2026-42214 (Notepad Next is a cross-platform, reimplementation of 
Notepad++. Prior ...)
        NOT-FOR-US: Notepad Next
 CVE-2026-41906 (FreeScout is a free help desk and shared inbox built with 
PHP's Larave ...)
@@ -210573,7 +210573,7 @@ CVE-2025-50200 (RabbitMQ is a messaging and streaming 
broker. In versions 3.13.7
        [bookworm] - rabbitmq-server <not-affected> (vulnerable code introduced 
later)
        [bullseye] - rabbitmq-server <not-affected> (vulnerable code introduced 
later)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gh3x-4x42-fvq8
-       NOTE: Fixed by https://github.com/rabbitmq/rabbitmq-server/pull/13612
+       NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-server/pull/13612
        NOTE: Introduced with: 
https://github.com/rabbitmq/rabbitmq-server/commit/383ddb16341200f63091e2dd8bb7c0c6346e3ef7
 (v4.1.0-alpha)
        NOTE: Introduced with (backport): 
https://github.com/rabbitmq/rabbitmq-server/commit/a4465d7a728a41dba125c6c0553f124b45dbb6bd
 (v3.13.2-rc.1)
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-server/commit/0a7c86b4807619b1ab52c18f091752d4f711d5b1
 (v4.2.0-beta.1)
@@ -212768,7 +212768,7 @@ CVE-2025-6170 (A flaw was found in the interactive 
shell of the xmllint command-
        [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u3
        NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/941
        NOTE: Crash in CLI tool, no security impact
-       NOTE: Fixed by 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/c340e419505cf4bf1d9ed7019a87cc00ec200434
 (2.14)
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/c340e419505cf4bf1d9ed7019a87cc00ec200434
 (2.14)
 CVE-2025-6137 (A vulnerability classified as critical has been found in 
TOTOLINK T10  ...)
        NOT-FOR-US: TOTOLINK
 CVE-2025-6136 (A vulnerability was found in Projectworlds Life Insurance 
Management S ...)
@@ -224769,7 +224769,7 @@ CVE-2025-27533 (Memory Allocation with Excessive Size 
Value vulnerability in Apa
        - activemq 5.17.6+dfsg-2 (bug #1104933)
        [bookworm] - activemq <postponed> (Minor issue, DoS)
        NOTE: https://issues.apache.org/jira/browse/AMQ-6596
-       NOTE: Fixed by https://github.com/apache/activemq/pull/1399
+       NOTE: Fixed by: https://github.com/apache/activemq/pull/1399
 CVE-2025-4372 (Use after free in WebAudio in Google Chrome prior to 
136.0.7103.92 all ...)
        {DSA-5916-1}
        - chromium 136.0.7103.92-1
@@ -233090,7 +233090,7 @@ CVE-2025-32700 (Exposure of Sensitive Information to 
an Unauthorized Actor vulne
        [bullseye] - mediawiki <not-affected> (Vulnerable code introduced later)
        NOTE: https://phabricator.wikimedia.org/T389235
        NOTE: Introduced by 
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1026560 
(REL1_43)
-       NOTE: Fixed by 
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1135788
+       NOTE: Fixed by: 
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1135788
 CVE-2025-32699 (Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia 
Foundation  ...)
        {DSA-5901-1 DLA-4249-1}
        - mediawiki 1:1.43.1+dfsg-1
@@ -276068,7 +276068,7 @@ CVE-2024-42333 (The researcher is showing that it is 
possible to leak a small am
        - zabbix 1:7.0.5+dfsg-1 (bug #1088689)
        [bookworm] - zabbix <no-dsa> (Minor issue)
        NOTE: https://support.zabbix.com/browse/ZBX-25629
-       NOTE: Fixed by 
https://github.com/zabbix/zabbix/commit/72d2ce61872fcbace8f8dfdabc0568c99980989d
 (7.0.4rc1)
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/72d2ce61872fcbace8f8dfdabc0568c99980989d
 (7.0.4rc1)
        NOTE: Fixed by (merge commit) 
https://github.com/zabbix/zabbix/commit/c4ea57b823cb6a4c2cb0796f500e862fbb6a46ea
 (6.0.35rc1)
 CVE-2024-42332 (The researcher is showing that due to the way the SNMP trap 
log is par ...)
        {DLA-3984-1}
@@ -276118,7 +276118,7 @@ CVE-2024-42326 (There was discovered a use after free 
bug in browser.c in the es
        [bookworm] - zabbix <not-affected> (Vulnerable code introduced later)
        [bullseye] - zabbix <not-affected> (Vulnerable code introduced later)
        NOTE: https://support.zabbix.com/browse/ZBX-25622
-       NOTE: Fixed by 
https://github.com/zabbix/zabbix/commit/0b01b889fc1d47002e1cf9fa50d52a5cca5f1a97
 (7.0.4rc1)
+       NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/0b01b889fc1d47002e1cf9fa50d52a5cca5f1a97
 (7.0.4rc1)
        NOTE: webdriver (browser.c) introduced with commit 
https://github.com/zabbix/zabbix/commit/4d22c15fe4499602e0da5399e3dd6dc9da03277b
 (7.0.0rc1)
 CVE-2024-41126 (Contiki-NG is an open-source, cross-platform operating system 
for IoT  ...)
        NOT-FOR-US: Contiki-NG
@@ -283224,7 +283224,7 @@ CVE-2024-51990 (jj, or Jujutsu, is a Git-compatible 
VCS written in rust. In affe
 CVE-2024-51736 (Symphony process is a module for the Symphony PHP framework 
which exec ...)
        - symfony <not-affected> (Only affects Symfony on Windows)
        NOTE: 
https://github.com/symfony/symfony/security/advisories/GHSA-qq5c-677p-737q
-       NOTE: Fixed by 
https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9
 (v5.4.46, v6.4.14, v7.1.7)
+       NOTE: Fixed by: 
https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9
 (v5.4.46, v6.4.14, v7.1.7)
 CVE-2024-51409 (Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a 
remote at ...)
        NOT-FOR-US: Tenda
 CVE-2024-50345 (symfony/http-foundation is a module for the Symphony PHP 
framework whi ...)
@@ -298931,8 +298931,8 @@ CVE-2024-8443 (A heap-based buffer overflow 
vulnerability was found in the libop
        [bookworm] - opensc 0.23.0-0.3+deb12u2
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2310494
        NOTE: https://github.com/OpenSC/OpenSC/wiki/CVE-2024-8443
-       NOTE: Fixed by 
https://github.com/OpenSC/OpenSC/commit/02e847458369c08421fd2d5e9a16a5f272c2de9e
 (0.26.0-rc1)
-       NOTE: Fixed by 
https://github.com/OpenSC/OpenSC/commit/b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc
 (0.26.0-rc1)
+       NOTE: Fixed by: 
https://github.com/OpenSC/OpenSC/commit/02e847458369c08421fd2d5e9a16a5f272c2de9e
 (0.26.0-rc1)
+       NOTE: Fixed by: 
https://github.com/OpenSC/OpenSC/commit/b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc
 (0.26.0-rc1)
 CVE-2024-8517 (SPIP before 4.3.2, 4.2.16, and  4.1.18 is vulnerable to a 
command inje ...)
        - spip 4.3.2+dfsg-1
        [bullseye] - spip <not-affected> (bigup module not shipped in 3.x)
@@ -309911,7 +309911,7 @@ CVE-2024-41110 (Moby is an open-source project 
created by Docker for software co
        [bookworm] - docker.io 20.10.24+dfsg1-1+deb12u1
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
        NOTE: 
https://www.docker.com/blog/docker-security-advisory-docker-engine-authz-plugin/
-       NOTE: Fixed by 
https://github.com/moby/moby/commit/88c4b7690840044ce15489699294ec7c5dadf5dd 
(20.10 branch)
+       NOTE: Fixed by: 
https://github.com/moby/moby/commit/88c4b7690840044ce15489699294ec7c5dadf5dd 
(20.10 branch)
        NOTE: Follow-up: 
https://github.com/moby/moby/commit/7ff423cc1c991d8dc0a7b5d1d93e1cf3efaac169
 CVE-2024-40575 (An issue in Huawei Technologies opengauss (openGauss 5.0.0 
build) v.7. ...)
        NOT-FOR-US: Huawei Technologies opengauss
@@ -315656,14 +315656,14 @@ CVE-2023-43554 (Memory corruption while processing 
IOCTL handler in FastRPC.)
 CVE-2024-40898 (SSRF in Apache HTTP Server on Windows with mod_rewrite in 
server/vhost ...)
        - apache2 <not-affected> (Windows specific)
        NOTE: 
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-40898
-       NOTE: Fixed by 
https://github.com/apache/httpd/commit/9967bf49599f9be6eaaf9c5de5c84f15bb07df9f
+       NOTE: Fixed by: 
https://github.com/apache/httpd/commit/9967bf49599f9be6eaaf9c5de5c84f15bb07df9f
 CVE-2024-40725 (A partial fix for CVE-2024-39884 in the core of Apache HTTP 
Server 2.4 ...)
        - apache2 2.4.62-1
        [bookworm] - apache2 2.4.62-1~deb12u1
        [bullseye] - apache2 2.4.62-1~deb11u1
        NOTE: 
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-40725
        NOTE: Introduced due to fix for CVE-2024-39884 (this CVE was fixed in 
2.4.60)
-       NOTE: Fixed by 
https://github.com/apache/httpd/commit/a7d24b4ea9a6ea35878fd33075365328caafcf91 
(2.4.62)
+       NOTE: Fixed by: 
https://github.com/apache/httpd/commit/a7d24b4ea9a6ea35878fd33075365328caafcf91 
(2.4.62)
        NOTE: (or svn 
https://svn.apache.org/viewvc?view=revision&revision=1919249)
 CVE-2024-39884 (A regression in the core of Apache HTTP Server 2.4.60 ignores 
some use ...)
        - apache2 2.4.61-1
@@ -315689,7 +315689,7 @@ CVE-2024-38477 (null pointer dereference in mod_proxy 
in Apache HTTP Server 2.4.
        {DSA-5729-1}
        - apache2 2.4.60-1
        NOTE: 
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-38477
-       NOTE: Fixed by 
https://github.com/apache/httpd/commit/1d98d4db186e708f059336fb9342d0adb6925e85 
(2.4.60)
+       NOTE: Fixed by: 
https://github.com/apache/httpd/commit/1d98d4db186e708f059336fb9342d0adb6925e85 
(2.4.60)
        NOTE: (or https://svn.apache.org/viewvc?view=revision&revision=1918607)
        NOTE: Regression identified by Ubuntu 
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2072648
        NOTE: Regression fixed by: 
https://github.com/apache/httpd/commit/4d3a308014be26e5407113b4c827a1ea2882bf38 
(2.4.60)
@@ -315697,8 +315697,8 @@ CVE-2024-38476 (Vulnerability in core of Apache HTTP 
Server 2.4.59 and earlier a
        {DSA-5729-1}
        - apache2 2.4.60-1
        NOTE: 
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-38476
-       NOTE: Fixed by 
https://github.com/apache/httpd/commit/925b6f0ceb8983a11662b5f3a6f2fa75860c2cde 
(trunk)
-       NOTE: Fixed by 
https://github.com/apache/httpd/commit/554554b0ebb14d6578adb70a389c57a0d5f18a3b 
(2.4.60)
+       NOTE: Fixed by: 
https://github.com/apache/httpd/commit/925b6f0ceb8983a11662b5f3a6f2fa75860c2cde 
(trunk)
+       NOTE: Fixed by: 
https://github.com/apache/httpd/commit/554554b0ebb14d6578adb70a389c57a0d5f18a3b 
(2.4.60)
        NOTE: (or https://svn.apache.org/viewvc?view=revision&revision=1918560)
        NOTE: see also regression CVE-2024-39884 and CVE-2024-40725
 CVE-2024-38475 (Improper escaping of output in mod_rewrite in Apache HTTP 
Server 2.4.5 ...)
@@ -340466,7 +340466,7 @@ CVE-2024-31585 (FFmpeg version n5.1 to n6.1 was 
discovered to contain an Off-by-
        - ffmpeg 7:7.0.1-3
        [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
        [buster] - ffmpeg <not-affected> (Vulnerable code not present)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/ab0fdaedd1e7224f7e84ea22fcbfaa4ca75a6c06
 (n7.0)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/ab0fdaedd1e7224f7e84ea22fcbfaa4ca75a6c06
 (n7.0)
        NOTE: Introduced by 
https://github.com/FFmpeg/FFmpeg/commit/81df787b53eb5c6433731f6eaaf7f2a94d8a8c80
 (n5.1)
 CVE-2024-31583 (Pytorch before version v2.2.0 was discovered to contain a 
use-after-fr ...)
        - pytorch 2.4.1-1 (bug #1070379)
@@ -340479,15 +340479,15 @@ CVE-2024-31582 (FFmpeg version n6.1 was discovered 
to contain a heap buffer over
        - ffmpeg 7:7.0.1-3
        [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
        [buster] - ffmpeg <not-affected> (Vulnerable code not present)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/99debe5f823f45a482e1dc08de35879aa9c74bd2
 (n7.0)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/785a6df0e477f408c3e939a043b8608acf071964
 (n5.1.7)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/99debe5f823f45a482e1dc08de35879aa9c74bd2
 (n7.0)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/785a6df0e477f408c3e939a043b8608acf071964
 (n5.1.7)
 CVE-2024-31581 (FFmpeg version n6.1 was discovered to contain an improper 
validation o ...)
        [experimental] - ffmpeg 7:7.0-1
        - ffmpeg 7:7.0.1-3
        [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
        [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
        [buster] - ffmpeg <not-affected> (Vulnerable code not present)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/ce0c178a408d43e71085c28a47d50dc939b60196
 (n7.0)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/ce0c178a408d43e71085c28a47d50dc939b60196
 (n7.0)
 CVE-2024-31580 (PyTorch before v2.2.0 was discovered to contain a heap buffer 
overflow ...)
        - pytorch 2.4.1-1 (bug #1070379)
        [bookworm] - pytorch <ignored> (Minor issue)
@@ -340499,7 +340499,7 @@ CVE-2024-31578 (FFmpeg version n6.1.1 was discovered 
to contain a heap use-after
        - ffmpeg 7:7.0.1-3
        [bookworm] - ffmpeg <postponed> (Pick up when fixed in 5.1.x)
        [buster] - ffmpeg <postponed> (Pick up when fixed in 4.3.x)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7
 (n7.0)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7
 (n7.0)
 CVE-2024-31463 (Ironic-image is an OpenStack Ironic deployment packaged and 
configured ...)
        NOT-FOR-US: ironic-image container image
 CVE-2024-31041 (Null Pointer Dereference vulnerability in topic_filtern 
function in mq ...)
@@ -342703,7 +342703,7 @@ CVE-2023-49528 (Buffer Overflow vulnerability in 
FFmpeg version n6.1-3-g466799d4
        [buster] - ffmpeg <not-affected> (Vulnerable code not present)
        NOTE: https://trac.ffmpeg.org/ticket/10691
        NOTE: Introduced after: 
https://github.com/FFmpeg/FFmpeg/commit/f05c52985cf80d565c6e91fb4749e57dd8977d3e
 (n5.1)
-       NOTE: Fixed by 
https://github.com/ffmpeg/ffmpeg/commit/2d9ed64859c9887d0504cd71dbd5b2c15e14251a
 (n7.0)
+       NOTE: Fixed by: 
https://github.com/ffmpeg/ffmpeg/commit/2d9ed64859c9887d0504cd71dbd5b2c15e14251a
 (n7.0)
 CVE-2023-48865 (An issue discovered in Reportico Till 8.1.0 allows attackers 
to obtain ...)
        NOT-FOR-US: Reportico Till
 CVE-2023-45186 (IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 
through 6 ...)
@@ -375842,7 +375842,7 @@ CVE-2023-33202 (Bouncy Castle for Java before 1.73 
contains a potential Denial o
        [bullseye] - bouncycastle <no-dsa> (Minor issue)
        [buster] - bouncycastle <ignored> (Minor issue)
        NOTE: https://github.com/bcgit/bc-java/wiki/CVE-2023-33202
-       NOTE: Fixed by 
https://github.com/bcgit/bc-java/commit/0c576892862ed41894f49a8f639112e8d66d229c
 (r1rv73)
+       NOTE: Fixed by: 
https://github.com/bcgit/bc-java/commit/0c576892862ed41894f49a8f639112e8d66d229c
 (r1rv73)
 CVE-2023-43123 (On unix-like systems, the temporary directory is shared 
between all us ...)
        NOT-FOR-US: Apache Storm
 CVE-2023-49146 (DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via 
an SVG do ...)
@@ -382755,7 +382755,7 @@ CVE-2018-25091 (urllib3 before 1.24.2 does not remove 
the authorization HTTP hea
        - python-urllib3 1.25.6-4
        NOTE: https://github.com/urllib3/urllib3/issues/1510
        NOTE: This issue exists because of an incomplete fix for CVE-2018-20060 
(which was case-sensitive).
-       NOTE: Fixed by 
https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc
 (1.25)
+       NOTE: Fixed by: 
https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc
 (1.25)
 CVE-2023-5586 (NULL Pointer Dereference in GitHub repository gpac/gpac prior 
to 2.3.0 ...)
        - gpac <removed> (bug #1055124)
        [bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
@@ -421486,7 +421486,7 @@ CVE-2023-0809 (In Mosquitto before 2.0.16, excessive 
memory is allocated based o
        - mosquitto 2.0.17-1
        [buster] - mosquitto <not-affected> (The vulnerable code was introduced 
later)
        NOTE: https://mosquitto.org/blog/2023/08/version-2-0-16-released/
-       NOTE: Fixed by 
https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad
+       NOTE: Fixed by: 
https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad
 CVE-2023-3592 (In Mosquitto before 2.0.16, a memory leak occurs when clients 
send v5  ...)
        {DSA-5511-1}
        - mosquitto 2.0.17-1
@@ -436320,7 +436320,7 @@ CVE-2022-4492 (The undertow client is not checking 
the server identity presented
        [experimental] - undertow 2.3.8-1
        - undertow 2.3.8-2 (bug #1032087)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2153260 has missing 
public details
-       NOTE: Fixed by https://github.com/undertow-io/undertow/pull/1447
+       NOTE: Fixed by: https://github.com/undertow-io/undertow/pull/1447
 CVE-2022-4491 (The WP-Table Reloaded WordPress plugin through 1.9.4 does not 
validate ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-4490
@@ -439391,7 +439391,7 @@ CVE-2022-46393 (An issue was discovered in Mbed TLS 
before 2.28.2 and 3.x before
        [bullseye] - mbedtls <not-affected> (The vulnerable code was introduced 
later)
        [buster] - mbedtls <not-affected> (The vulnerable code was introduced 
later)
        NOTE: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2
-       NOTE: Fixed by 
https://github.com/Mbed-TLS/mbedtls/commit/f385fcebee017973cf4137333628a78248f1f443
+       NOTE: Fixed by: 
https://github.com/Mbed-TLS/mbedtls/commit/f385fcebee017973cf4137333628a78248f1f443
 CVE-2022-46392 (An issue was discovered in Mbed TLS before 2.28.2 and 3.x 
before 3.3.0 ...)
        {DLA-4236-1}
        - mbedtls 2.28.2-1
@@ -455390,7 +455390,7 @@ CVE-2022-41915 (Netty project is an event-driven 
asynchronous network applicatio
        {DSA-5316-1 DLA-3268-1}
        - netty 1:4.1.48-6 (bug #1027180)
        NOTE: 
https://github.com/netty/netty/security/advisories/GHSA-hh82-3pmq-7frp
-       NOTE: Fixed by 
https://github.com/netty/netty/commit/fe18adff1c2b333acb135ab779a3b9ba3295a1c4 
(netty-4.1.86.Final)
+       NOTE: Fixed by: 
https://github.com/netty/netty/commit/fe18adff1c2b333acb135ab779a3b9ba3295a1c4 
(netty-4.1.86.Final)
 CVE-2022-41914 (Zulip is an open-source team collaboration tool. For 
organizations wit ...)
        - zulip-server <itp> (bug #800052)
 CVE-2022-41913 (Discourse-calendar is a plugin for the Discourse messaging 
platform wh ...)
@@ -455484,7 +455484,7 @@ CVE-2022-41881 (Netty project is an event-driven 
asynchronous network applicatio
        {DSA-5316-1 DLA-3268-1}
        - netty 1:4.1.48-6 (bug #1027180)
        NOTE: 
https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985v
-       NOTE: Fixed by 
https://github.com/netty/netty/commit/cd91cf3c99123bd1e53fd6a1de0e3d1922f05bb2 
(netty-4.1.86.Final)
+       NOTE: Fixed by: 
https://github.com/netty/netty/commit/cd91cf3c99123bd1e53fd6a1de0e3d1922f05bb2 
(netty-4.1.86.Final)
 CVE-2022-41880 (TensorFlow is an open source platform for machine learning. 
When the ` ...)
        - tensorflow <not-affected> (Fixed before initial upload to the archive)
 CVE-2022-41879 (Parse Server is an open source backend that can be deployed to 
any inf ...)
@@ -463764,8 +463764,8 @@ CVE-2022-38751 (Using snakeYAML to parse untrusted 
YAML files may be vulnerable
        [bullseye] - snakeyaml 1.28-1+deb11u1
        NOTE: 
https://bitbucket.org/snakeyaml/snakeyaml/issues/530/stackoverflow-oss-fuzz-47039
        NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47039
-       NOTE: Fixed by 
https://bitbucket.org/snakeyaml/snakeyaml/commits/f3ab4e0f54c37ddb10f00b71d04187bb0ef1799c
 (snakeyaml-1.31)
-       NOTE: Fixed by 
https://bitbucket.org/snakeyaml/snakeyaml/commits/6aedd33a811f7347c5dae2940e75940966f59466
 (snakeyaml-1.31)
+       NOTE: Fixed by: 
https://bitbucket.org/snakeyaml/snakeyaml/commits/f3ab4e0f54c37ddb10f00b71d04187bb0ef1799c
 (snakeyaml-1.31)
+       NOTE: Fixed by: 
https://bitbucket.org/snakeyaml/snakeyaml/commits/6aedd33a811f7347c5dae2940e75940966f59466
 (snakeyaml-1.31)
 CVE-2022-38750 (Using snakeYAML to parse untrusted YAML files may be 
vulnerable to Den ...)
        {DLA-3132-1}
        - snakeyaml 1.31-1
@@ -500255,22 +500255,22 @@ CVE-2022-26129 (Buffer overflow vulnerabilities 
exist in FRRouting through 8.1.0
        {DLA-3865-1 DLA-3797-1}
        - frr 8.4.1-1 (bug #1008010)
        NOTE: https://github.com/FRRouting/frr/issues/10503
-       NOTE: Fixed by https://github.com/FRRouting/frr/issues/10504 (together 
with CVE-2022-26128)
+       NOTE: Fixed by: https://github.com/FRRouting/frr/issues/10504 (together 
with CVE-2022-26128)
 CVE-2022-26128 (A buffer overflow vulnerability exists in FRRouting through 
8.1.0 due  ...)
        {DLA-3865-1 DLA-3797-1}
        - frr 8.4.1-1 (bug #1008010)
        NOTE: https://github.com/FRRouting/frr/issues/10502
-       NOTE: Fixed by https://github.com/FRRouting/frr/issues/10504 (together 
with CVE-2022-26129)
+       NOTE: Fixed by: https://github.com/FRRouting/frr/issues/10504 (together 
with CVE-2022-26129)
 CVE-2022-26127 (A buffer overflow vulnerability exists in FRRouting through 
8.1.0 due  ...)
        {DLA-3865-1 DLA-3797-1}
        - frr 8.4.1-1 (bug #1008010)
        NOTE: https://github.com/FRRouting/frr/issues/10487
-       NOTE: Fixed by https://github.com/FRRouting/frr/pull/10494
+       NOTE: Fixed by: https://github.com/FRRouting/frr/pull/10494
 CVE-2022-26126 (Buffer overflow vulnerabilities exist in FRRouting through 
8.1.0 due t ...)
        {DLA-3865-1 DLA-3797-1}
        - frr 8.4.1-1 (bug #1008010)
        NOTE: https://github.com/FRRouting/frr/issues/10505
-       NOTE: Fixed by https://github.com/FRRouting/frr/pull/10566
+       NOTE: Fixed by: https://github.com/FRRouting/frr/pull/10566
 CVE-2022-26125 (Buffer overflow vulnerabilities exist in FRRouting through 
8.1.0 due t ...)
        {DLA-3865-1 DLA-3797-1}
        - frr 8.4.1-1 (bug #1008010)
@@ -500943,7 +500943,7 @@ CVE-2022-21222 (The package css-what before 2.1.3 are 
vulnerable to Regular Expr
        NOTE: https://security.snyk.io/vuln/SNYK-JS-CSSWHAT-3035488
        NOTE: ReDoS issue fixed with rewrite of module to TypeScript
        NOTE: Not fixed in 4.0.0 see 
https://sources.debian.org/src/node-css-what/4.0.0-3/src/parse.ts/#L84
-       NOTE: Fixed by 
https://github.com/fb55/css-what/pull/503/commits/46b0dbd6f38fb375da02208426f93f87f7169b7e
+       NOTE: Fixed by: 
https://github.com/fb55/css-what/pull/503/commits/46b0dbd6f38fb375da02208426f93f87f7169b7e
 CVE-2022-21221 (The package github.com/valyala/fasthttp before 1.34.0 are 
vulnerable t ...)
        NOT-FOR-US: github.com/valyala/fasthttp
 CVE-2022-21213 (This affects all versions of package mout. The deepFillIn 
function can ...)
@@ -510029,7 +510029,7 @@ CVE-2022-23221 (H2 Console before 2.1.210 allows 
remote attackers to execute arb
        {DSA-5076-1 DLA-2923-1}
        - h2database 2.1.210-1
        NOTE: 
https://github.com/h2database/h2database/releases/tag/version-2.1.210
-       NOTE: Fixed by 
https://github.com/h2database/h2database/commit/eb75633d0dfa86341e6ef77a861665c4a0f16ab8
+       NOTE: Fixed by: 
https://github.com/h2database/h2database/commit/eb75633d0dfa86341e6ef77a861665c4a0f16ab8
        NOTE: 
https://github.com/h2database/h2database/issues/3360#issuecomment-1018351050
 CVE-2022-23220 (USBView 2.1 before 2.2 allows some local users (e.g., ones 
logged in v ...)
        {DSA-5052-1}
@@ -513307,7 +513307,7 @@ CVE-2022-0084 (A flaw was found in XNIO, specifically 
in the notifyReadClosed me
        [bullseye] - jboss-xnio <no-dsa> (Minor issue)
        [buster] - jboss-xnio <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2064226
-       NOTE: Fixed by 
https://github.com/xnio/xnio/commit/b05531de0433f498af26f9aec6c0e944c3c1689c
+       NOTE: Fixed by: 
https://github.com/xnio/xnio/commit/b05531de0433f498af26f9aec6c0e944c3c1689c
 CVE-2021-46129
        RESERVED
 CVE-2021-46128
@@ -528573,7 +528573,7 @@ CVE-2021-42392 (The 
org.h2.util.JdbcUtils.getConnection method of the H2 databas
        - h2database 2.1.210-1 (bug #1003894)
        NOTE: 
https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6
        NOTE: 
https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/
-       NOTE: Fixed by 
https://github.com/h2database/h2database/commit/41dd2a4cf89da9dd18239debbf73f88da6184ec7
+       NOTE: Fixed by: 
https://github.com/h2database/h2database/commit/41dd2a4cf89da9dd18239debbf73f88da6184ec7
        NOTE: 
https://github.com/h2database/h2database/commit/956c6241868332c5b440f5d55ea8fdc1e51ae4fd
 CVE-2021-42391 (Divide-by-zero in Clickhouse's Gorilla compression codec when 
parsing  ...)
        - clickhouse <not-affected> (Vulnerable code introduced later)
@@ -530364,7 +530364,7 @@ CVE-2021-41800 (MediaWiki before 1.36.2 allows a 
denial of service (resource con
        [stretch] - mediawiki <not-affected> (The vulnerable code was 
introduced later)
        NOTE: 
https://lists.wikimedia.org/hyperkitty/list/[email protected]/thread/2IFS5CM2YV4VMSODPX3J2LFHKSEWVFV5/
        NOTE: https://phabricator.wikimedia.org/T284419
-       NOTE: Fixed by 
https://github.com/wikimedia/mediawiki/commit/781caf83dba90c18349f930bbaaa0e89f003f874
+       NOTE: Fixed by: 
https://github.com/wikimedia/mediawiki/commit/781caf83dba90c18349f930bbaaa0e89f003f874
 CVE-2021-41799 (MediaWiki before 1.36.2 allows a denial of service (resource 
consumpti ...)
        {DSA-4979-1 DLA-2779-1}
        - mediawiki 1:1.35.4-1
@@ -538487,7 +538487,7 @@ CVE-2021-38576 (A BIOS bug in firmware for a 
particular PC model leaves the Plat
        - edk2 2021.11-1 (bug #1014468)
        [buster] - edk2 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.tianocore.org/show_bug.cgi?id=3499
-       NOTE: Fixed by https://github.com/tianocore/edk2/pull/1968
+       NOTE: Fixed by: https://github.com/tianocore/edk2/pull/1968
 CVE-2021-38575 (NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.)
        {DLA-4207-1}
        - edk2 2021.08-1
@@ -542174,7 +542174,7 @@ CVE-2021-3658 (bluetoothd from bluez incorrectly 
saves adapters' Discoverable st
        [buster] - bluez <not-affected> (Vulnerable code introduced later)
        [stretch] - bluez <not-affected> (Vulnerable code introduced later)
        NOTE: Introduced by 
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=d04eb02f9bad8795297210ef80e262be16ea8f07
 (5.51)
-       NOTE: Fixed by 
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
+       NOTE: Fixed by: 
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
 CVE-2021-37216 (QSAN Storage Manager header page parameters does not filter 
special ch ...)
        NOT-FOR-US: QSAN Storage Manager
 CVE-2021-37215 (The employee management page of Flygo contains an Insecure 
Direct Obje ...)
@@ -546349,7 +546349,7 @@ CVE-2021-35515 (When reading a specially crafted 7Z 
archive, the construction of
        [buster] - libcommons-compress-java <no-dsa> (Minor issue)
        [stretch] - libcommons-compress-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2021/07/13/1
-       NOTE: Fixed by 
https://gitbox.apache.org/repos/asf?p=commons-compress.git;a=commit;h=3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321
+       NOTE: Fixed by: 
https://gitbox.apache.org/repos/asf?p=commons-compress.git;a=commit;h=3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321
 CVE-2021-35514 (Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection 
via the t ...)
        NOT-FOR-US: Narou
 CVE-2021-35513 (Mermaid before 8.11.0 allows XSS when the antiscript feature 
is used.)
@@ -548907,7 +548907,7 @@ CVE-2021-34429 (For Eclipse Jetty versions 
9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1
        [buster] - jetty9 <not-affected> (Vulnerable code was introduced in 
version 9.4.37)
        [stretch] - jetty9 <not-affected> (Vulnerable code was introduced in 
version 9.4.37)
        NOTE: 
https://github.com/eclipse/jetty.project/security/advisories/GHSA-vjv5-gp2w-65vm
-       NOTE: Fixed by https://github.com/eclipse/jetty.project/pull/6477
+       NOTE: Fixed by: https://github.com/eclipse/jetty.project/pull/6477
 CVE-2021-34428 (For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if 
an exce ...)
        {DSA-4949-1}
        - jetty9 9.4.39-2 (bug #990578)
@@ -573107,7 +573107,7 @@ CVE-2021-25220 (BIND 9.11.0 -> 9.11.36 9.12.0 -> 
9.16.26 9.17.0 -> 9.18.0 BIND S
        {DSA-5105-1 DLA-2955-1}
        - bind9 1:9.18.1-1
        NOTE: https://kb.isc.org/docs/cve-2021-25220
-       NOTE: Fixed by 
https://gitlab.isc.org/isc-projects/bind9/-/commit/fc9cb6cf91c1a36b797ffef0a277dbb3989d43dc
+       NOTE: Fixed by: 
https://gitlab.isc.org/isc-projects/bind9/-/commit/fc9cb6cf91c1a36b797ffef0a277dbb3989d43dc
 CVE-2021-25219 (In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 
9.9.3-S1 ->  ...)
        {DSA-4994-1 DLA-2807-1}
        - bind9 1:9.17.19-1
@@ -580494,7 +580494,7 @@ CVE-2021-21996 (An issue was discovered in SaltStack 
Salt before 3003.3. A user
        {DSA-5011-1 DLA-2823-1}
        - salt 3002.7+dfsg1-1 (bug #994016)
        NOTE: 
https://saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/
-       NOTE: Fixed by 
https://github.com/saltstack/salt/commit/0b75ba190fda9c04cc026ad1aa4a6d572f40349b
+       NOTE: Fixed by: 
https://github.com/saltstack/salt/commit/0b75ba190fda9c04cc026ad1aa4a6d572f40349b
        NOTE: 
https://github.com/openSUSE/salt/commit/57ed9c41a177f57e3d56465662750617ac36cc95
 CVE-2021-21995 (OpenSLP as used in ESXi has a denial-of-service vulnerability 
due a he ...)
        NOT-FOR-US: VMware
@@ -603873,7 +603873,7 @@ CVE-2020-25638 (A flaw was found in hibernate-core in 
versions prior to and incl
        {DSA-4908-1 DLA-2512-1}
        - libhibernate3-java 3.6.10.Final-11
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1881353
-       NOTE: Fixed by 
https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78
+       NOTE: Fixed by: 
https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78
 CVE-2020-25637 (A double free memory issue was found to occur in the libvirt 
API, in v ...)
        {DLA-3778-1 DLA-2395-1}
        - libvirt 6.8.0-1 (bug #971555)
@@ -643993,13 +643993,13 @@ CVE-2020-9498 (Apache Guacamole 1.1.0 and older may 
mishandle pointers involved
        - guacamole-server 1.3.0-1 (bug #964195)
        NOTE: https://www.openwall.com/lists/oss-security/2020/07/02/3
        NOTE: https://research.checkpoint.com/2020/apache-guacamole-rce/
-       NOTE: Fixed by 
https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
+       NOTE: Fixed by: 
https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
 CVE-2020-9497 (Apache Guacamole 1.1.0 and older do not properly validate 
datareceived ...)
        {DLA-2435-1}
        - guacamole-server 1.3.0-1 (bug #964195)
        NOTE: https://www.openwall.com/lists/oss-security/2020/07/02/2
        NOTE: https://research.checkpoint.com/2020/apache-guacamole-rce/
-       NOTE: Fixed by 
https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
+       NOTE: Fixed by: 
https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
 CVE-2020-9496 (XML-RPC request are vulnerable to unsafe deserialization and 
Cross-Sit ...)
        NOT-FOR-US: Apache OFBiz
 CVE-2020-9495 (Apache Archiva login service before 2.2.5 is vulnerable to LDAP 
inject ...)
@@ -673477,7 +673477,7 @@ CVE-2019-17571 (Included in Log4j 1.2 is a 
SocketServer class that is vulnerable
        NOTE: CVE-2019-17571 correspond to CVE-2017-5645 for apache-log4j2. 
1.2.x branch
        NOTE: is end-of-life upstream and does not recieve a fix for this 
issue. Users
        NOTE: should upgrade to Log4j 2.x.
-       NOTE: Fixed by 
https://src.fedoraproject.org/rpms/log4j12/c/d4c817c458d69dcc629a7271999d178b0dcb7c74?branch=master
+       NOTE: Fixed by: 
https://src.fedoraproject.org/rpms/log4j12/c/d4c817c458d69dcc629a7271999d178b0dcb7c74?branch=master
 CVE-2019-17570 (An untrusted deserialization was found in the 
org.apache.xmlrpc.parser ...)
        {DSA-4619-1 DLA-2078-1}
        - libxmlrpc3-java <removed> (bug #949089)
@@ -689839,7 +689839,7 @@ CVE-2019-12594 (DOSBox 0.74-2 has Incorrect Access 
Control.)
        NOTE: Fixed in 0.74-3 upstream.
        NOTE: https://github.com/Alexandre-Bartel/CVE-2019-12594
        NOTE: Upstream clarification https://sourceforge.net/p/dosbox/bugs/508/
-       NOTE: Fixed by https://sourceforge.net/p/dosbox/code-0/4246/
+       NOTE: Fixed by: https://sourceforge.net/p/dosbox/code-0/4246/
 CVE-2019-12593 (IceWarp Mail Server through 10.4.4 is prone to a local file 
inclusion  ...)
        NOT-FOR-US: IceWarp Mail Server
 CVE-2019-12592 (A universal Cross-site scripting (UXSS) vulnerability in the 
Evernote  ...)
@@ -690368,7 +690368,7 @@ CVE-2019-12422 (Apache Shiro before 1.4.2, when using 
the default "remember me"
        [stretch] - shiro <no-dsa> (Minor issue)
        [jessie] - shiro <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2019/11/18/1
-       NOTE: Fixed by 
https://github.com/apache/shiro/commit/44f6548b97610cdf661976969d5735c0be14a57b#diff-a8fc9cf5d6f24966aa18cdf0850a730e
+       NOTE: Fixed by: 
https://github.com/apache/shiro/commit/44f6548b97610cdf661976969d5735c0be14a57b#diff-a8fc9cf5d6f24966aa18cdf0850a730e
 CVE-2019-12421 (When using an authentication mechanism other than PKI, when 
the user c ...)
        NOT-FOR-US: Apache NiFi
 CVE-2019-12420 (In Apache SpamAssassin before 3.4.3, a message can be crafted 
in a way ...)
@@ -696485,7 +696485,7 @@ CVE-2019-10219 (A vulnerability was found in 
Hibernate-Validator. The SafeHtml v
        - libhibernate-validator4-java <not-affected> (Vulnerable code was 
introduced later)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1738673
        NOTE: https://hibernate.atlassian.net/browse/HV-1739
-       NOTE: Fixed by 
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
+       NOTE: Fixed by: 
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
 CVE-2019-10218 (A flaw was found in the samba client, all samba versions 
before samba  ...)
        {DLA-3563-1 DLA-2668-1}
        - samba 2:4.11.1+dfsg-2
@@ -698629,7 +698629,7 @@ CVE-2019-9826 (The fulltext search component in phpBB 
before 3.2.6 allows Denial
        {DLA-1775-1}
        - phpbb3 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2019/04/29/3
-       NOTE: Fixed by 
https://github.com/phpbb/phpbb/commit/3075d2fecc9f5bb780bb478c0851a704c7f9b392
+       NOTE: Fixed by: 
https://github.com/phpbb/phpbb/commit/3075d2fecc9f5bb780bb478c0851a704c7f9b392
 CVE-2019-9825 (FeiFeiCMS 4.1.190209 allows remote attackers to upload and 
execute arb ...)
        NOT-FOR-US: FeiFeiCMS
 CVE-2019-9824 (tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 
3.0.0 u ...)
@@ -700504,7 +700504,7 @@ CVE-2019-9210 (In AdvanceCOMP 2.1, png_compress in 
pngex.cc in advpng has an int
        {DLA-2868-1 DLA-1702-1}
        - advancecomp 2.1-2 (low; bug #923416)
        NOTE: https://sourceforge.net/p/advancemame/bugs/277/
-       NOTE: Fixed by 
https://github.com/amadvance/advancecomp/commit/fcf71a89265c78fc26243574dda3a872574a5c02
+       NOTE: Fixed by: 
https://github.com/amadvance/advancecomp/commit/fcf71a89265c78fc26243574dda3a872574a5c02
 CVE-2018-20797 (An issue was discovered in PoDoFo 0.9.6. There is an attempted 
excessi ...)
        - libpodofo <unfixed> (unimportant; bug #923415)
        NOTE: https://sourceforge.net/p/podofo/tickets/34/
@@ -706013,7 +706013,7 @@ CVE-2019-7165 (A buffer overflow in DOSBox 0.74-2 
allows attackers to execute ar
        - dosbox 0.74-3-1 (bug #931222)
        NOTE: Fixed in 0.74-3 upstream.
        NOTE: Upstream clarification https://sourceforge.net/p/dosbox/bugs/508/
-       NOTE: Fixed by https://sourceforge.net/p/dosbox/code-0/3925/
+       NOTE: Fixed by: https://sourceforge.net/p/dosbox/code-0/3925/
 CVE-2019-7164 (SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL 
Injecti ...)
        {DLA-2811-1 DLA-1718-1}
        [experimental] - sqlalchemy 1.3.0~b3+ds1-1
@@ -715702,7 +715702,7 @@ CVE-2018-20482 (GNU Tar through 1.30, when --sparse 
is used, mishandles file shr
        NOTE: https://news.ycombinator.com/item?id=18745431
        NOTE: https://twitter.com/thatcks/status/1076166645708668928
        NOTE: https://lists.gnu.org/archive/html/bug-tar/2018-12/msg00023.html
-       NOTE: Fixed by 
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=c15c42c
+       NOTE: Fixed by: 
https://git.savannah.gnu.org/cgit/tar.git/commit/?id=c15c42c
 CVE-2018-20481 (XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles 
unallocated XRe ...)
        {DLA-2287-1 DLA-1706-1}
        - poppler 0.71.0-4 (low; bug #917325)
@@ -720483,7 +720483,7 @@ CVE-2018-20004 (An issue has been found in Mini-XML 
(aka mxml) 2.12. It is a sta
        - mxml 2.12-2 (low; bug #918007)
        [stretch] - mxml <no-dsa> (Minor issue)
        NOTE: https://github.com/michaelrsweet/mxml/issues/233
-       NOTE: Fixed by 
https://github.com/michaelrsweet/mxml/commit/4f5577dd4672d228e4180f06bdbd66f343ea45e0
+       NOTE: Fixed by: 
https://github.com/michaelrsweet/mxml/commit/4f5577dd4672d228e4180f06bdbd66f343ea45e0
 CVE-2018-20003
        RESERVED
 CVE-2018-20002 (The _bfd_generic_read_minisymbols function in syms.c in the 
Binary Fil ...)
@@ -727001,7 +727001,7 @@ CVE-2018-19105 (LibreCAD 2.1.3 allows remote 
attackers to cause a denial of serv
        [stretch] - librecad 2.1.2-1+deb9u1
        NOTE: https://code610.blogspot.com/2018/11/crashing-librecad-213.html
        NOTE: https://github.com/LibreCAD/LibreCAD/issues/1038
-       NOTE: Fixed by 
https://github.com/LibreCAD/LibreCAD/commit/6da7cc5f7f31afb008f03dbd11e07207ccd82085
+       NOTE: Fixed by: 
https://github.com/LibreCAD/LibreCAD/commit/6da7cc5f7f31afb008f03dbd11e07207ccd82085
        NOTE: Regression fix 
https://github.com/LibreCAD/LibreCAD/commit/8604f171ee380f294102da6154adf77ab754d403
 CVE-2018-19104 (In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability 
that can b ...)
        NOT-FOR-US: BageCMS
@@ -732764,7 +732764,7 @@ CVE-2018-16883 (sssd versions from 1.13.0 to before 
2.0.0 did not properly restr
        [jessie] - sssd <not-affected> (Issue got introduced with 1.13.0)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1659862
        NOTE: Fixed in upstream 2.0.0 while refactoring code
-       NOTE: Fixed by 
https://pagure.io/SSSD/sssd/c/fbe2476a3dd9be83ffa85c29dca26f734618d72d?branch=master
+       NOTE: Fixed by: 
https://pagure.io/SSSD/sssd/c/fbe2476a3dd9be83ffa85c29dca26f734618d72d?branch=master
 CVE-2018-16882 (A use-after-free issue was found in the way the Linux kernel's 
KVM hyp ...)
        - linux 4.19.13-1
        [stretch] - linux <not-affected> (Vulnerable code not present)
@@ -744348,7 +744348,7 @@ CVE-2018-12495 (The quoteblock function in markdown.c 
in libmarkdown.a in DISCOU
        {DSA-4293-1 DLA-1499-1}
        - discount 2.2.4-1 (bug #901912)
        NOTE: https://github.com/Orc/discount/issues/189#issuecomment-397541501
-       NOTE: Fixed by 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+       NOTE: Fixed by: 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
 CVE-2018-12494 (An issue was discovered in PublicCMS V4.0.20180210. There is a 
"Direct ...)
        NOT-FOR-US: PublicCMS
 CVE-2018-12493 (An issue was discovered in PublicCMS V4.0.20180210. There is a 
"Direct ...)
@@ -747312,13 +747312,13 @@ CVE-2018-11504 (The islist function in markdown.c 
in libmarkdown.a in DISCOUNT 2
        - discount 2.2.4-1 (bug #901912)
        NOTE: https://github.com/Orc/discount/issues/189#issuecomment-392247798
        NOTE: POC: 
https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue3_testcase
-       NOTE: Fixed by 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+       NOTE: Fixed by: 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
 CVE-2018-11503 (The isfootnote function in markdown.c in libmarkdown.a in 
DISCOUNT 2.2 ...)
        {DSA-4293-1 DLA-1499-1}
        - discount 2.2.4-1 (bug #901912)
        NOTE: https://github.com/Orc/discount/issues/189#issuecomment-392247798
        NOTE: POC: 
https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue2_testcase
-       NOTE: Fixed by 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+       NOTE: Fixed by: 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
 CVE-2018-11502 (An issue was discovered in the Moderator Log Notes plugin 1.1 
for MyBB ...)
        NOT-FOR-US: MyBB plugin
 CVE-2018-11501 (PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via 
user_submit. ...)
@@ -747413,7 +747413,7 @@ CVE-2018-11468 (The __mkd_trim_line function in 
mkdio.c in libmarkdown.a in DISC
        - discount 2.2.4-1 (bug #901912)
        NOTE: https://github.com/Orc/discount/issues/189
        NOTE: POC: 
https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue1_testcase
-       NOTE: Fixed by 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+       NOTE: Fixed by: 
https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
 CVE-2018-11467
        RESERVED
 CVE-2018-11466 (A vulnerability has been identified in SINUMERIK 808D V4.7 
(All versio ...)
@@ -761722,7 +761722,7 @@ CVE-2016-10711 (Apsis Pound before 2.8a allows 
request smuggling via crafted hea
        [stretch] - pound 2.7-1.3+deb9u1
        NOTE: 
http://www.apsis.ch/pound/pound_list/archive/2016/2016-10/1477235279000
        NOTE: https://www.suse.com/de-de/security/cve/CVE-2016-10711/
-       NOTE: Fixed by https://build.opensuse.org/request/show/571084
+       NOTE: Fixed by: https://build.opensuse.org/request/show/571084
        NOTE: Confirmed that the SUSE patch is the security relevant diff 
between
        NOTE: version 2.7 and 2.8a
        NOTE: an additional fix of the fix is needed to avoid that pound uses 
100% CPU
@@ -777393,7 +777393,7 @@ CVE-2018-1067 (In Undertow before versions 7.1.2.CR1, 
7.1.2.GA it was found that
        - undertow 1.4.25-1 (bug #900323)
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1302
        NOTE: Issue is incomplete fix for CVE-2016-4993
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/85d4478e598105fe94ac152d3e11e388374e8b86
 (1.4.25.Final)
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/85d4478e598105fe94ac152d3e11e388374e8b86
 (1.4.25.Final)
 CVE-2018-1066 (The Linux kernel before version 4.11 is vulnerable to a NULL 
pointer d ...)
        {DSA-4188-1 DSA-4187-1 DLA-1422-1}
        - linux 4.11.6-1
@@ -777529,19 +777529,19 @@ CVE-2018-1048 (It was found that the AJP connector 
in undertow, as shipped in Jb
        - undertow 1.4.22-1 (bug #891928)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1534343
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1245
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/1bc0c275aadf5835abfbd3835d5d78095c2f1cf5
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/1bc0c275aadf5835abfbd3835d5d78095c2f1cf5
 CVE-2018-1047 (A flaw was found in Wildfly 9.x. A path traversal vulnerability 
throug ...)
        - wildfly <itp> (bug #752018)
        NOTE: https://issues.jboss.org/browse/WFLY-9620
        NOTE: https://developer.jboss.org/thread/276826
-       NOTE: Fixed by https://github.com/wildfly/wildfly/pull/10748
+       NOTE: Fixed by: https://github.com/wildfly/wildfly/pull/10748
 CVE-2018-1046 (pdns before version 4.1.2 is vulnerable to a buffer overflow in 
dnsrep ...)
        - pdns 4.1.2-1 (bug #898255)
        [stretch] - pdns 4.0.3-1+deb9u3
        [jessie] - pdns <not-affected> (Vulnerable code not present)
        [wheezy] - pdns <not-affected> (Vulnerable code not present)
        NOTE: 
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2018-02.html
-       NOTE: Fixed by 
https://github.com/PowerDNS/pdns/commit/f9c57c98da1b1007a51680629b667d57d9b702b8
+       NOTE: Fixed by: 
https://github.com/PowerDNS/pdns/commit/f9c57c98da1b1007a51680629b667d57d9b702b8
 CVE-2018-1045 (In Moodle 3.x, there is XSS via a calendar event name.)
        - moodle <removed>
 CVE-2018-1044 (In Moodle 3.x, quiz web services allow students to see quiz 
results wh ...)
@@ -785069,14 +785069,14 @@ CVE-2017-15602 (In GNU Libextractor 1.4, there is 
an integer signedness error fo
        [stretch] - libextractor 1:1.3-4+deb9u1
        [jessie] - libextractor 1:1.3-2+deb8u1
        NOTE: 
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00005.html
-       NOTE: Fixed by 
https://git.gnunet.org/libextractor.git/commit/?id=ffab889c1710c7646af9ed360c796a2a0a619efc
+       NOTE: Fixed by: 
https://git.gnunet.org/libextractor.git/commit/?id=ffab889c1710c7646af9ed360c796a2a0a619efc
 CVE-2017-15601 (In GNU Libextractor 1.4, there is a heap-based buffer overflow 
in the  ...)
        {DLA-1198-1}
        - libextractor 1:1.6-1 (low)
        [stretch] - libextractor 1:1.3-4+deb9u1
        [jessie] - libextractor 1:1.3-2+deb8u1
        NOTE: 
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00006.html
-       NOTE: Fixed by 
https://git.gnunet.org/libextractor.git/commit/?id=f813535dad4ad860b989952a46266a1469801091
+       NOTE: Fixed by: 
https://git.gnunet.org/libextractor.git/commit/?id=f813535dad4ad860b989952a46266a1469801091
 CVE-2017-15600 (In GNU Libextractor 1.4, there is a NULL Pointer Dereference 
in the EX ...)
        {DLA-1198-1}
        - libextractor 1:1.6-1 (low)
@@ -785084,7 +785084,7 @@ CVE-2017-15600 (In GNU Libextractor 1.4, there is a 
NULL Pointer Dereference in
        [jessie] - libextractor 1:1.3-2+deb8u1
        NOTE: 
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00004.html
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1501695
-       NOTE: Fixed by 
https://git.gnunet.org/libextractor.git/commit/?id=38e8933539ee9d044057b18a971c2eae3c21aba7
+       NOTE: Fixed by: 
https://git.gnunet.org/libextractor.git/commit/?id=38e8933539ee9d044057b18a971c2eae3c21aba7
 CVE-2017-15599
        RESERVED
 CVE-2017-15598
@@ -789233,7 +789233,7 @@ CVE-2017-14266 (tcprewrite in Tcpreplay 3.4.4 has a 
Heap-Based Buffer Overflow v
        - tcpreplay 3.4.4-3
        [jessie] - tcpreplay 3.4.4-2+deb8u1
        [wheezy] - tcpreplay 3.4.3-2+wheezy2
-       NOTE: Fixed by 
http://launchpadlibrarian.net/270778908/tcpreplay_3.4.4-2_3.4.4-3.diff.gz
+       NOTE: Fixed by: 
http://launchpadlibrarian.net/270778908/tcpreplay_3.4.4-2_3.4.4-3.diff.gz
        NOTE: Not a duplicate of CVE-2016-6160 the detailed MITRE description, 
but both issues
        NOTE: are addressed with the same patch:
        NOTE: Patch enforce-maxpacket.patch addresses the issue
@@ -789971,7 +789971,7 @@ CVE-2016-10510 (Cross-site scripting (XSS) 
vulnerability in the Security compone
        - libkohana2-php <removed>
        [jessie] - libkohana2-php <ignored> (Minor issue)
        NOTE: https://github.com/kohana/kohana/issues/107
-       NOTE: Fixed by https://github.com/kohana/core/pull/697
+       NOTE: Fixed by: https://github.com/kohana/core/pull/697
 CVE-2016-10509 (SQL injection vulnerability in the updateAmazonOrderTracking 
function  ...)
        NOT-FOR-US: OpenCart
 CVE-2016-10508 (Multiple cross-site scripting (XSS) vulnerabilities in 
phpThumb() befo ...)
@@ -790734,7 +790734,7 @@ CVE-2017-13748 (There are lots of memory leaks in 
JasPer 2.0.12, triggered in th
        [wheezy] - jasper <ignored> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1485287
        NOTE: https://github.com/mdadams/jasper/issues/168
-       NOTE: Fixed by https://github.com/mdadams/jasper/pull/159 but still no 
upstream comment.
+       NOTE: Fixed by: https://github.com/mdadams/jasper/pull/159 but still no 
upstream comment.
 CVE-2017-13747 (There is a reachable assertion abort in the function 
jpc_floorlog2() i ...)
        - jasper <removed> (unimportant)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1485282
@@ -791087,7 +791087,7 @@ CVE-2017-13672 (QEMU (aka Quick Emulator), when built 
with the VGA display emula
        - qemu-kvm <removed>
        [wheezy] - qemu-kvm <postponed> (Can be fixed along in a future DSA)
        NOTE: 
https://lists.gnu.org/archive/html/qemu-devel/2017-08/msg04684.html
-       NOTE: Fixed by 
https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=3d90c6254863693a6b13d918d2b8682e08bbc681
+       NOTE: Fixed by: 
https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=3d90c6254863693a6b13d918d2b8682e08bbc681
        NOTE: CentOS7 has a backport/upgrade(?) for their frankenstein version
        NOTE: 
http://vault.centos.org/7.6.1810/updates/Source/SPackages/qemu-kvm-1.5.3-160.el7_6.3.src.rpm
 CVE-2017-13671 (app/View/Helper/CommandHelper.php in MISP before 2.4.79 has 
persistent ...)
@@ -795466,7 +795466,7 @@ CVE-2017-12197 (It was found that libpam4j up to and 
including 1.8 did not prope
 CVE-2017-12196 (undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final 
was fou ...)
        - undertow 1.4.25-1
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1503055
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/facb33a5cedaf4b7b96d3840a08210370a806870
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/facb33a5cedaf4b7b96d3840a08210370a806870
        NOTE: See also 
https://github.com/undertow-io/undertow/commit/8804170ce3186bdd83b486959399ec7ac0f59d0f
 CVE-2017-12195 (A flaw was found in all Openshift Enterprise versions using 
the opensh ...)
        NOT-FOR-US: OpenShift
@@ -796893,7 +796893,7 @@ CVE-2017-11684 (There is an illegal address access in 
the build_table function i
        [jessie] - libav 6:11.11-1~deb8u1
        - ffmpeg 7:2.3.1-1
        NOTE: https://bugzilla.libav.org/show_bug.cgi?id=1073
-       NOTE: Fixed by 
https://github.com/libav/libav/commit/ec683ed527cef9aad208d1daeb10d0e7fb63e75e.patch
+       NOTE: Fixed by: 
https://github.com/libav/libav/commit/ec683ed527cef9aad208d1daeb10d0e7fb63e75e.patch
 CVE-2017-11683 (There is a reachable assertion in the 
Internal::TiffReader::visitDirec ...)
        {DLA-3186-1 DLA-1147-1}
        - exiv2 0.27.2-6 (unimportant)
@@ -797095,7 +797095,7 @@ CVE-2017-11628 (In PHP before 5.6.31, 7.x before 
7.0.21, and 7.1.x before 7.1.7,
        - php5 <removed> (low)
        NOTE: https://bugs.php.net/bug.php?id=74603
        NOTE: Fixed in 7.1.7, 7.0.21, 5.6.31
-       NOTE: Fixed by 
https://git.php.net/?p=php-src.git;a=commit;h=05255749139b3686c8a6a58ee01131ac0047465e
+       NOTE: Fixed by: 
https://git.php.net/?p=php-src.git;a=commit;h=05255749139b3686c8a6a58ee01131ac0047465e
 CVE-2017-11627 (A stack-consumption vulnerability was found in libqpdf in QPDF 
6.0.0,  ...)
        [experimental] - qpdf 7.0~b1-1
        - qpdf 7.0.0-1 (low; bug #871320)
@@ -807161,7 +807161,7 @@ CVE-2017-8314 (Directory Traversal in Zip Extraction 
built-in function in Kodi 1
        [jessie] - xbmc <no-dsa> (Minor issue)
        NOTE: http://blog.checkpoint.com/2017/05/23/hacked-in-translation/
        NOTE: 
https://kodi.tv/article/kodi-v172-minor-bug-fix-and-security-release
-       NOTE: Fixed by 
https://github.com/xbmc/xbmc/commit/35cfe35608b15335ef21d798947fceab3f47c8d7
+       NOTE: Fixed by: 
https://github.com/xbmc/xbmc/commit/35cfe35608b15335ef21d798947fceab3f47c8d7
 CVE-2017-8313 (Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 
due to ...)
        {DSA-3899-1}
        - vlc 2.2.5-1
@@ -809741,7 +809741,7 @@ CVE-2017-7559 (In Undertow 2.x before 2.0.0.Alpha2, 
1.4.x before 1.4.17.Final, a
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1165
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1295
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1481665#c7
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/3436b03eda8b0b62c1855698c4d7c358add836c2
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/3436b03eda8b0b62c1855698c4d7c358add836c2
 CVE-2017-7558 (A kernel data leak due to an out-of-bound read was found in the 
Linux  ...)
        - linux 4.12.13-1
        [stretch] - linux 4.9.30-2+deb9u5
@@ -814890,7 +814890,7 @@ CVE-2017-5953 (vim before patch 8.0.0322 does not 
properly validate values for t
        {DSA-3786-1 DLA-822-1}
        - vim 2:8.0.0197-2 (bug #854969)
        - neovim 0.1.7-4
-       NOTE: Fixed by 
https://github.com/vim/vim/commit/399c297aa93afe2c0a39e2a1b3f972aebba44c9d
+       NOTE: Fixed by: 
https://github.com/vim/vim/commit/399c297aa93afe2c0a39e2a1b3f972aebba44c9d
 CVE-2017-5952
        RESERVED
 CVE-2017-5951 (The mem_get_bits_rectangle function in base/gdevmem.c in 
Artifex Softw ...)
@@ -820971,7 +820971,7 @@ CVE-2016-10074 (The mail transport (aka 
Swift_Transport_MailTransport) in Swift
        - libphp-swiftmailer 5.4.2-1.1 (bug #849626)
        NOTE: 
https://legalhackers.com/advisories/SwiftMailer-Exploit-Remote-Code-Exec-CVE-2016-10074-Vuln.html
        NOTE: https://github.com/swiftmailer/swiftmailer/issues/844
-       NOTE: Fixed by 
https://github.com/swiftmailer/swiftmailer/commit/e6ccf40d856af9598b76eb313b215eed25ae9e86
+       NOTE: Fixed by: 
https://github.com/swiftmailer/swiftmailer/commit/e6ccf40d856af9598b76eb313b215eed25ae9e86
 CVE-2016-10073 (The from method in library/core/class.email.php in Vanilla 
Forums befo ...)
        NOT-FOR-US: Vanilla Forums
 CVE-2016-10072 (WampServer 3.0.6 has two files called 'wampmanager.exe' and 
'unins000. ...)
@@ -825048,7 +825048,7 @@ CVE-2017-2671 (The ping_unhash function in 
net/ipv4/ping.c in the Linux kernel t
 CVE-2017-2670 (It was found in Undertow before 1.3.28 that with non-clean TCP 
close,  ...)
        {DSA-3906-1}
        - undertow 1.4.18-1 (bug #864405)
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/9bfe9fbbb595d51157b61693f072895f7dbadd1d
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/9bfe9fbbb595d51157b61693f072895f7dbadd1d
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1035
 CVE-2017-2669 (Dovecot before version 2.2.29 is vulnerable to a denial of 
service. Wh ...)
        - dovecot 1:2.2.27-3 (bug #860049)
@@ -825067,7 +825067,7 @@ CVE-2017-2666 (It was discovered in Undertow that the 
code that parsed the HTTP
        {DSA-3906-1}
        - undertow 1.4.18-1 (bug #864405)
        NOTE: https://issues.jboss.org/browse/UNDERTOW-1101
-       NOTE: Fixed by 
https://github.com/undertow-io/undertow/commit/1e72647818c9fb31b693a953b1ae595a6c82eb7f
+       NOTE: Fixed by: 
https://github.com/undertow-io/undertow/commit/1e72647818c9fb31b693a953b1ae595a6c82eb7f
 CVE-2017-2665 (The skyring-setup command creates random password for mongodb 
skyring  ...)
        NOT-FOR-US: Red Hat Storage / skyring
 CVE-2017-2664 (CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x 
before 5.8. ...)
@@ -825332,11 +825332,11 @@ CVE-2017-2588
 CVE-2017-2587 (A memory allocation vulnerability was found in netpbm before 
10.61. A  ...)
        - netpbm-free <not-affected> (vulnerable code not present)
        NOTE: Debian uses an old fork of netpbm
-       NOTE: Fixed by 
http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
+       NOTE: Fixed by: 
http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
 CVE-2017-2586 (A null pointer dereference vulnerability was found in netpbm 
before 10 ...)
        - netpbm-free <not-affected> (vulnerable code not present)
        NOTE: Debian uses an old fork of netpbm
-       NOTE: Fixed by 
http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
+       NOTE: Fixed by: 
http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
 CVE-2017-2585 (Red Hat Keycloak before version 2.5.1 has an implementation of 
HMAC ve ...)
        - keycloak <itp> (bug #1088287)
 CVE-2017-2584 (arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows 
local  ...)
@@ -829193,7 +829193,7 @@ CVE-2017-0842 (An elevation of privilege 
vulnerability in the Android system (bl
        NOT-FOR-US: Fluoride Bluetooth stack in Android
 CVE-2017-0841 (A remote code execution vulnerability in the Android system 
(libutils) ...)
        - android-platform-system-core <removed> (unimportant)
-       NOTE: Fixed by 
https://android.googlesource.com/platform/system/core/+/47efc676c849e3abf32001d66e2d6eb887e83c48%5E!/
+       NOTE: Fixed by: 
https://android.googlesource.com/platform/system/core/+/47efc676c849e3abf32001d66e2d6eb887e83c48%5E!/
 CVE-2017-0840 (An information disclosure vulnerability in the Android media 
framework ...)
        NOT-FOR-US: Android media framework
 CVE-2017-0839 (An information disclosure vulnerability in the Android media 
framework ...)
@@ -829232,7 +829232,7 @@ CVE-2017-0823 (An information disclosure 
vulnerability in the Android system (ri
        NOT-FOR-US: Android (rild)
 CVE-2017-0822 (An elevation of privilege vulnerability in the Android system 
(camera) ...)
        - android-framework-23 <unfixed> (unimportant)
-       NOTE: Fixed by 
https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a
+       NOTE: Fixed by: 
https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a
 CVE-2017-0821
        RESERVED
 CVE-2017-0820 (A vulnerability in the Android media framework (n/a). Product: 
Android ...)
@@ -829382,7 +829382,7 @@ CVE-2017-0753 (A remote code execution vulnerability 
in the Android libraries (l
        NOT-FOR-US: Android (libgdx)
 CVE-2017-0752 (A elevation of privilege vulnerability in the Android framework 
(windo ...)
        - android-framework-23 <unfixed> (unimportant)
-       NOTE: Fixed by 
https://android.googlesource.com/platform/frameworks/base/+/6ca2eccdbbd4f11698bd5312812b4d171ff3c8ce%5E%21/
+       NOTE: Fixed by: 
https://android.googlesource.com/platform/frameworks/base/+/6ca2eccdbbd4f11698bd5312812b4d171ff3c8ce%5E%21/
 CVE-2017-0751 (An elevation of privilege vulnerability in the Qualcomm QCE 
driver. Pr ...)
        NOT-FOR-US: Google drivers for Android
 CVE-2017-0750 (A elevation of privilege vulnerability in the Upstream Linux 
file syst ...)
@@ -830772,7 +830772,7 @@ CVE-2016-9584 (libical allows remote attackers to 
cause a denial of service (use
 CVE-2016-9583 (An out-of-bounds heap read vulnerability was found in the 
jpc_pi_nextp ...)
        - jasper <removed> (unimportant)
        NOTE: https://github.com/mdadams/jasper/issues/103
-       NOTE: Fixed by 
https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27
+       NOTE: Fixed by: 
https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27
        NOTE: The issue exists due to an overflow check which is not present
        NOTE: in Wheezy and Jessie. However it makes sense to implement this 
check.
        NOTE: This can be done when more important issues are found [wheezy].
@@ -831795,9 +831795,9 @@ CVE-2016-9427 (Integer overflow vulnerability in 
bdwgc before 2016-09-27 allows
        - libgc 1:7.6.4-0.3 (bug #844771)
        [jessie] - libgc <no-dsa> (Minor issue)
        NOTE: https://github.com/ivmai/bdwgc/issues/135
-       NOTE: Fixed by 
https://github.com/ivmai/bdwgc/commit/4e1a6f9d8f2a49403bbd00b8c8e5324048fb84d4
-       NOTE: Fixed by 
https://github.com/ivmai/bdwgc/commit/7292c02fac2066d39dd1bcc37d1a7054fd1e32ee
-       NOTE: Fixed by 
https://github.com/ivmai/bdwgc/commit/552ad0834672fed86ada6430150ef9ebdd3f54d7
+       NOTE: Fixed by: 
https://github.com/ivmai/bdwgc/commit/4e1a6f9d8f2a49403bbd00b8c8e5324048fb84d4
+       NOTE: Fixed by: 
https://github.com/ivmai/bdwgc/commit/7292c02fac2066d39dd1bcc37d1a7054fd1e32ee
+       NOTE: Fixed by: 
https://github.com/ivmai/bdwgc/commit/552ad0834672fed86ada6430150ef9ebdd3f54d7
 CVE-2016-9426 (An issue was discovered in the Tatsuya Kinoshita w3m fork 
before 0.5.3 ...)
        - w3m 0.5.3-30
        [jessie] - w3m 0.5.3-19+deb8u1
@@ -833713,11 +833713,11 @@ CVE-2016-XXXX [sendmail: Privilege escalation from 
group smmsp to root]
 CVE-2016-8885 (The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 
before 1 ...)
        - jasper <not-affected> (Incomplete fix for CVE-2016-8690 not applied)
        NOTE: 
https://blogs.gentoo.org/ago/2016/10/18/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c-incomplete-fix-for-cve-2016-8690
-       NOTE: Fixed by 
https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
+       NOTE: Fixed by: 
https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
 CVE-2016-8884 (The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 
1.900.5  ...)
        - jasper <not-affected> (Incomplete fix for CVE-2016-8690 not applied)
        NOTE: 
https://blogs.gentoo.org/ago/2016/10/18/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c-incomplete-fix-for-cve-2016-8690
-       NOTE: Fixed by 
https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
+       NOTE: Fixed by: 
https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
 CVE-2016-8883 (The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 
1.900.8  ...)
        {DLA-739-1}
        - jasper <removed> (unimportant)
@@ -837786,22 +837786,22 @@ CVE-2016-7449 (The TIFFGetField function in 
coders/tiff.c in GraphicsMagick 1.3.
        NOTE: http://hg.code.sf.net/p/graphicsmagick/code/rev/eb58028dacf5
        NOTE: 
https://blogs.gentoo.org/ago/2016/08/23/graphicsmagick-two-heap-based-buffer-overflow-in-readtiffimage-tiff-c/
        NOTE: 
https://blogs.gentoo.org/ago/2016/09/07/graphicsmagick-null-pointer-dereference-in-magickstrlcpy-utility-c/
-       NOTE: Fixed by 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/eb58028dacf5
+       NOTE: Fixed by: 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/eb58028dacf5
 CVE-2016-7448 (The Utah RLE reader in GraphicsMagick before 1.3.25 allows 
remote atta ...)
        {DLA-1401-1 DLA-683-1}
        - graphicsmagick 1.3.25-1
-       NOTE: Fixed by 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/30043afadb10
-       NOTE: Fixed by 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d972c761b55d
+       NOTE: Fixed by: 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/30043afadb10
+       NOTE: Fixed by: 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d972c761b55d
 CVE-2016-7447 (Heap-based buffer overflow in the EscapeParenthesis function in 
Graphi ...)
        {DLA-1401-1 DLA-651-1}
        - graphicsmagick 1.3.25-1
-       NOTE: Fixed by 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d580e3c3c034
+       NOTE: Fixed by: 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d580e3c3c034
 CVE-2016-7446 (Buffer overflow in the MVG and SVG rendering code in 
GraphicsMagick 1. ...)
        {DLA-1401-1 DLA-651-1}
        - graphicsmagick 1.3.25-1
        NOTE: For the http://www.graphicsmagick.org/NEWS.html#september-5-2016 
case
        NOTE: which remained present in the 1.3.24 release (and was not fixed 
until 1.3.25)
-       NOTE: Fixed by 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/6071b5820215
+       NOTE: Fixed by: 
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/6071b5820215
 CVE-2016-7445 (convert.c in OpenJPEG before 2.1.2 allows remote attackers to 
cause a  ...)
        - openjpeg2 2.1.2-1 (unimportant; bug #838690)
        NOTE: https://github.com/uclouvain/openjpeg/issues/843
@@ -842121,7 +842121,7 @@ CVE-2016-6209 (Cross-site scripting (XSS) 
vulnerability in Nagios.)
        - icinga <not-affected> (Vulnerable code not present)
        NOTE: http://seclists.org/fulldisclosure/2016/Jun/20
        NOTE: https://github.com/NagiosEnterprises/nagioscore/issues/297
-       NOTE: Fixed by 
https://github.com/NagiosEnterprises/nagioscore/commit/78b7bdde3ab4dec265879ff1b4d49a398bf3ba9c
+       NOTE: Fixed by: 
https://github.com/NagiosEnterprises/nagioscore/commit/78b7bdde3ab4dec265879ff1b4d49a398bf3ba9c
 CVE-2016-6206 (Huawei AR3200 routers with software before V200R007C00SPC600 
allow rem ...)
        NOT-FOR-US: Huawei
 CVE-2016-6205
@@ -842369,8 +842369,8 @@ CVE-2016-6171 (Knot DNS before 2.3.0 allows remote 
DNS servers to cause a denial
 CVE-2016-6170 (ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x 
throug ...)
        - bind9 1:9.10.6+dfsg-1 (unimportant; bug #830810)
        NOTE: Not fixed upstream, proposed patches below are unofficial:
-       NOTE: Fixed by 
https://github.com/sischkg/xfer-limit/blob/master/bind-9.10.3-xfer-limit-0.0.1.patch
-       NOTE: Fixed by 
https://github.com/sischkg/xfer-limit/blob/master/bind-9.9.9-P1-xfer-limit-0.0.1.patch
+       NOTE: Fixed by: 
https://github.com/sischkg/xfer-limit/blob/master/bind-9.10.3-xfer-limit-0.0.1.patch
+       NOTE: Fixed by: 
https://github.com/sischkg/xfer-limit/blob/master/bind-9.9.9-P1-xfer-limit-0.0.1.patch
        NOTE: Negligible security impact
 CVE-2016-6163 (The rsvg_pattern_fix_fallback function in rsvg-paint_server.c 
in librs ...)
        - librsvg 2.40.9-2
@@ -844453,18 +844453,18 @@ CVE-2016-5421 (Use-after-free vulnerability in 
libcurl before 7.50.1 allows atta
        - curl 7.50.1-1
        [wheezy] - curl <not-affected> (introduced in 7.32.0)
        NOTE: https://curl.haxx.se/docs/adv_20160803C.html
-       NOTE: Fixed by https://curl.haxx.se/CVE-2016-5421.patch
+       NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5421.patch
 CVE-2016-5420 (curl and libcurl before 7.50.1 do not check the client 
certificate whe ...)
        {DSA-3638-1 DLA-586-1}
        - curl 7.50.1-1
        NOTE: https://curl.haxx.se/docs/adv_20160803B.html
-       NOTE: Fixed by https://curl.haxx.se/CVE-2016-5420.patch
+       NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5420.patch
        NOTE: Wheezy: vulnerable code is in lib/sslgen.c
 CVE-2016-5419 (curl and libcurl before 7.50.1 do not prevent TLS session 
resumption w ...)
        {DSA-3638-1 DLA-586-1}
        - curl 7.50.1-1
        NOTE: https://curl.haxx.se/docs/adv_20160803A.html
-       NOTE: Fixed by https://curl.haxx.se/CVE-2016-5419.patch
+       NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5419.patch
        NOTE: Wheezy: vulnerable code is in lib/sslgen.c
 CVE-2016-5418 (The sandboxing code in libarchive 3.2.0 and earlier mishandles 
hardlin ...)
        {DSA-3677-1 DLA-657-1}
@@ -844976,54 +844976,54 @@ CVE-2015-8928 (The process_add_entry function in 
archive_read_support_format_mtr
        - libarchive 3.2.0-2
        [wheezy] - libarchive <not-affected> (vulnerable code not present)
        NOTE: https://github.com/libarchive/libarchive/issues/550
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/64d5628
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/64d5628
 CVE-2015-8927 (The trad_enc_decrypt_update function in 
archive_read_support_format_zi ...)
        - libarchive 3.2.0-2
        [jessie] - libarchive <not-affected> (vulnerable code not present)
        [wheezy] - libarchive <not-affected> (vulnerable code not present)
        NOTE: https://github.com/libarchive/libarchive/issues/523
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/eff35d4
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/eff35d4
 CVE-2015-8926 (The archive_read_format_rar_read_data function in 
archive_read_support ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/518
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/aab73938
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/aab73938
 CVE-2015-8925 (The readline function in archive_read_support_format_mtree.c in 
libarc ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/516
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/1e18cbb71
+       NOTE: Fixed by: 
https://github.com/libarchive/libarchive/commit/1e18cbb71
 CVE-2015-8924 (The archive_read_format_tar_read_header function in 
archive_read_suppo ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/515
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/bb9b157
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/bb9b157
 CVE-2015-8923 (The process_extra function in libarchive before 3.2.0 uses the 
size fi ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/514
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/9e0689c
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/9e0689c
 CVE-2015-8922 (The read_CodersInfo function in 
archive_read_support_format_7zip.c in  ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/513
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/d094dc
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/d094dc
 CVE-2015-8921 (The ae_strtofflags function in archive_entry.c in libarchive 
before 3. ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/512
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/1cbc76f
-       NOTE: Fixed by 
https://github.com/libarchive/libarchive/commit/05a875fdb876e7a2f56a2937f756927cbed919e0
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1cbc76f
+       NOTE: Fixed by: 
https://github.com/libarchive/libarchive/commit/05a875fdb876e7a2f56a2937f756927cbed919e0
 CVE-2015-8920 (The _ar_read_header function in 
archive_read_support_format_ar.c in li ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/511
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/97f964e
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/97f964e
 CVE-2015-8919 (The lha_read_file_extended_header function in 
archive_read_support_for ...)
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/510
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/e8a2e4d
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/e8a2e4d
 CVE-2015-8918 (The archive_string_append function in archive_string.c in 
libarchive b ...)
        - libarchive <not-affected> (Vulnerable code not in a released version)
        NOTE: Introduced in 
https://github.com/libarchive/libarchive/commit/cf8e67ffc8a2227b63fc6d3d1569b0214f160f54
@@ -845033,13 +845033,13 @@ CVE-2015-8917 (bsdtar in libarchive before 3.2.0 
allows remote attackers to caus
        {DSA-3657-1 DLA-554-1}
        - libarchive 3.2.0-2
        NOTE: https://github.com/libarchive/libarchive/issues/505
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/b2e2abb
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/b2e2abb
 CVE-2015-8916 (bsdtar in libarchive before 3.2.0 returns a success code 
without filli ...)
        {DSA-3657-1}
        - libarchive 3.2.0-2
        [wheezy] - libarchive <not-affected> (no segfault, not reproducible 
with reproducer)
        NOTE: https://github.com/libarchive/libarchive/issues/504
-       NOTE: Fixed by https://github.com/libarchive/libarchive/commit/b2e2abb
+       NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/b2e2abb
 CVE-2015-8915 (bsdcpio in libarchive before 3.2.0 allows remote attackers to 
cause a  ...)
        {DLA-1600-1 DLA-617-1}
        - libarchive 3.2.0-2 (low; bug #784213)
@@ -845152,7 +845152,7 @@ CVE-2016-5286
        RESERVED
 CVE-2016-5285 (A Null pointer dereference vulnerability exists in Mozilla 
Network Sec ...)
        - nss 2:3.25-1
-       NOTE: Fixed by https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
+       NOTE: Fixed by: https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
        NOTE: Upstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1306103
 CVE-2016-5284 (Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and 
Thunder ...)
        {DSA-3674-1 DLA-636-1}
@@ -846418,7 +846418,7 @@ CVE-2016-5017 (Buffer overflow in the C cli shell in 
Apache Zookeeper before 3.4
        NOTE: The C cli shell is intended as a sample/example of how to use the 
C
        NOTE: client interface, not as a production tool
        NOTE: https://zookeeper.apache.org/security.html#CVE-2016-5017
-       NOTE: Fixed by 
https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;h=27ecf981a15554dc8e64a28630af7a5c9e2bdf4f
+       NOTE: Fixed by: 
https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;h=27ecf981a15554dc8e64a28630af7a5c9e2bdf4f
 CVE-2016-5016 (Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account 
and Authe ...)
        NOT-FOR-US: Pivotal Cloud Foundry
 CVE-2016-5015
@@ -847269,7 +847269,7 @@ CVE-2016-4793 (The clientIp function in CakePHP 3.2.4 
and earlier allows remote
        [jessie] - cakephp <no-dsa> (Minor issue)
        NOTE: 
http://legalhackers.com/advisories/CakePHP-IP-Spoofing-Vulnerability.txt
        NOTE: 
https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html
-       NOTE: Fixed by 
https://github.com/cakephp/cakephp/commit/48af49ddde16c8b99edb701f1c31283455b2b0b6
+       NOTE: Fixed by: 
https://github.com/cakephp/cakephp/commit/48af49ddde16c8b99edb701f1c31283455b2b0b6
 CVE-2016-4792 (Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote 
attackers to ...)
        NOT-FOR-US: Pulse Connect Secure
 CVE-2016-4791 (The administrative user interface in Pulse Connect Secure (PCS) 
8.2 be ...)
@@ -851917,7 +851917,7 @@ CVE-2016-3092 (The MultipartStream class in Apache 
Commons Fileupload before 1.3
        - tomcat7 7.0.70-1
        - tomcat8 8.0.36-1
        - tomcat9 <not-affected> (Fixed before initial upload to Debian)
-       NOTE: Fixed by https://svn.apache.org/r1743480
+       NOTE: Fixed by: https://svn.apache.org/r1743480
        NOTE: Upstream advisory http://markmail.org/message/oyxfv73jb2g7rjg3
        NOTE: 
https://mail-archives.us.apache.org/mod_mbox/www-announce/201606.mbox/%[email protected]%3E
 CVE-2016-3091 (Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote 
attackers  ...)
@@ -852605,7 +852605,7 @@ CVE-2016-2848 (ISC BIND 9.1.0 through 9.8.4-P2 and 
9.9.0 through 9.9.2-P2 allows
        {DLA-672-1}
        - bind9 1:9.9.3.dfsg.P2-1 (bug #839051)
        NOTE: https://kb.isc.org/article/AA-01433
-       NOTE: Fixed by 
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4
+       NOTE: Fixed by: 
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4
 CVE-2016-2846 (Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote 
attackers  ...)
        NOT-FOR-US: Siemens SIMATIC S7-1200 CPU devices
 CVE-2016-2845 (The Content Security Policy (CSP) implementation in Blink, as 
used in  ...)
@@ -855631,7 +855631,7 @@ CVE-2016-2091 (The dwarf_read_cie_fde_prefix function 
in dwarf_frame2.c in libdw
        - dwarfutils 20160507-1 (bug #813148)
        [jessie] - dwarfutils 20120410-2+deb8u1
        NOTE: https://www.openwall.com/lists/oss-security/2016/01/19/3
-       NOTE: Fixed by 
http://sourceforge.net/p/libdwarf/code/ci/9565964f26966d8391fe2cfa8e6e8e59278c5f91
+       NOTE: Fixed by: 
http://sourceforge.net/p/libdwarf/code/ci/9565964f26966d8391fe2cfa8e6e8e59278c5f91
 CVE-2016-2090 (Off-by-one vulnerability in the fgetwln function in libbsd 
before 0.8. ...)
        {DLA-2052-1}
        - libbsd 0.8.2-1
@@ -856389,7 +856389,7 @@ CVE-2016-2050 (The get_abbrev_array_info function in 
libdwarf-20151114 allows re
        - dwarfutils 20160507+git20160523.9086738-1 (unimportant)
        [jessie] - dwarfutils 20120410-2+deb8u1
        NOTE: https://www.openwall.com/lists/oss-security/2016/01/19/9
-       NOTE: Fixed by 
http://sourceforge.net/p/libdwarf/code/ci/a05f5e2ae6a5f34daa566975894fc2803d6ec684
+       NOTE: Fixed by: 
http://sourceforge.net/p/libdwarf/code/ci/a05f5e2ae6a5f34daa566975894fc2803d6ec684
        NOTE: Reasoning for "unimportant" severity: The affected source code is 
present
        NOTE: in dwarfdump/, but in the binary package is installed dwarfdump2/ 
.
        NOTE: dwarfdump2 (the C++ implentation) has been abandoned again by 
upstream in
@@ -862222,7 +862222,7 @@ CVE-2015-8504 (Qemu, when built with VNC display 
driver support, allows remote a
        [squeeze] - qemu <end-of-life> (Not supported in Squeeze LTS)
        - qemu-kvm <removed>
        [squeeze] - qemu-kvm <end-of-life> (Not supported in Squeeze LTS)
-       NOTE: Fixed by 
http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4c65fed8bdf96780735dbdb92a8bd0d6b6526cc3
 (v2.5.0-rc3)
+       NOTE: Fixed by: 
http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4c65fed8bdf96780735dbdb92a8bd0d6b6526cc3
 (v2.5.0-rc3)
        NOTE: Issue possibly introduced after 
http://git.qemu.org/?p=qemu.git;a=commitdiff;h=6cec5487990bf3f1f22b3fcb871978255e92ae0d
 (v0.10.0)
        NOTE: https://www.openwall.com/lists/oss-security/2015/12/08/4
 CVE-2016-0200 (Microsoft Internet Explorer 9 through 11 allows remote 
attackers to ex ...)
@@ -870365,7 +870365,7 @@ CVE-2015-8384 (PCRE before 8.38 mishandles the 
/(?J)(?'d'(?'d'\g{d}))/ pattern a
        NOTE: https://bugs.exim.org/show_bug.cgi?id=1636
        NOTE: related issue to CVE-2015-8392 and CVE-2015-8395
        NOTE: Fixed in 8.38
-       NOTE: Fixed by http://vcs.pcre.org/pcre?view=revision&revision=1558
+       NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1558
        NOTE: Same fixing commit as CVE-2015-3210 but different issues
 CVE-2015-8383 (PCRE before 8.38 mishandles certain repeated conditional 
groups, which ...)
        - pcre3 2:8.38-1
@@ -870374,7 +870374,7 @@ CVE-2015-8383 (PCRE before 8.38 mishandles certain 
repeated conditional groups,
        [squeeze] - pcre3 <not-affected> (vulnerable code introduced in 8.34)
        NOTE: Fixed in 8.38
        NOTE: https://www.openwall.com/lists/oss-security/2015/11/29/1
-       NOTE: Fixed by http://vcs.pcre.org/pcre?view=revision&revision=1557
+       NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1557
        NOTE: Introduced by/first bad commit: 
http://vcs.pcre.org/pcre?view=revision&revision=1365
 CVE-2015-8382 (The match function in pcre_exec.c in PCRE before 8.37 
mishandles the / ...)
        - pcre3 2:8.35-7.2 (bug #794589)
@@ -870399,7 +870399,7 @@ CVE-2015-XXXX [Sidekiq::Web lacks CSRF protection]
        - ruby-sidekiq 3.4.2~dfsg-3
        [jessie] - ruby-sidekiq <no-dsa> (Minor issue)
        NOTE: https://github.com/mperham/sidekiq/pull/2422
-       NOTE: Fixed by 
https://github.com/mperham/sidekiq/commit/cf3c43b2410c4573e05ac119494e41115f4140ad
+       NOTE: Fixed by: 
https://github.com/mperham/sidekiq/commit/cf3c43b2410c4573e05ac119494e41115f4140ad
        NOTE: Fix released in sidekiq 3.4.2
        NOTE: Follow-up fix: 
https://github.com/mperham/sidekiq/commit/75a3524c919857aac16e0541b0cb107f48d00694
        NOTE: Follow-up commit not included in 3.4.2~dfsg-1
@@ -870408,14 +870408,14 @@ CVE-2015-XXXX [XSS via job arguments display class 
in Sidekiq::Web]
        - ruby-sidekiq 3.4.2~dfsg-3
        [jessie] - ruby-sidekiq <no-dsa> (Minor issue)
        NOTE: https://github.com/mperham/sidekiq/pull/2309
-       NOTE: Fixed by 
https://github.com/mperham/sidekiq/commit/54766f336620ca0ce3b0b87a7a56382496e64b61
+       NOTE: Fixed by: 
https://github.com/mperham/sidekiq/commit/54766f336620ca0ce3b0b87a7a56382496e64b61
        NOTE: Fix released in sidekiq 3.4.0
        NOTE: CVE Request: 
https://www.openwall.com/lists/oss-security/2015/08/01/2
 CVE-2015-XXXX [XSS via queue name in Sidekiq::Web]
        - ruby-sidekiq 3.4.2~dfsg-3
        [jessie] - ruby-sidekiq <no-dsa> (Minor issue)
        NOTE: https://github.com/mperham/sidekiq/issues/2330
-       NOTE: Fixed by 
https://github.com/mperham/sidekiq/commit/2178d66b6686fbf4430223c34c184a64c9906828
+       NOTE: Fixed by: 
https://github.com/mperham/sidekiq/commit/2178d66b6686fbf4430223c34c184a64c9906828
        NOTE: Fix released in sidekiq 3.4.0
        NOTE: CVE Request: 
https://www.openwall.com/lists/oss-security/2015/08/01/2
 CVE-2015-5707 (Integer overflow in the sg_start_req function in 
drivers/scsi/sg.c in  ...)
@@ -870424,8 +870424,8 @@ CVE-2015-5707 (Integer overflow in the sg_start_req 
function in drivers/scsi/sg.
        - linux-2.6 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2015/08/01/6
        NOTE: Probably introduced in 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10db10d144c0248f285242f79daf6b9de6b00a62
 (v2.6.28-rc1)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81
 (v4.1-rc1)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee
 (v4.1-rc1)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81
 (v4.1-rc1)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee
 (v4.1-rc1)
 CVE-2015-5706 (Use-after-free vulnerability in the path_openat function in 
fs/namei.c ...)
        - linux 4.0.4-1
        [jessie] - linux 3.16.7-ckt11-1+deb8u3
@@ -871851,7 +871851,7 @@ CVE-2015-5244 (The NSSCipherSuite option with 
ciphersuites enabled in mod_nss be
        [jessie] - libapache2-mod-nss <not-affected> (Vulnerability introduced 
in 1.0.11)
        [wheezy] - libapache2-mod-nss <not-affected> (Vulnerability introduced 
in 1.0.11)
        NOTE: Introduced in 
https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=2d1650900f4d47dc43400d826c0f7e1a7c5229b8
 (1.0.11)
-       NOTE: Fixed by 
https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=34e1ccecb4a7d5054dba2f92b403af9b6ae1e110
 (1.0.12)
+       NOTE: Fixed by: 
https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=34e1ccecb4a7d5054dba2f92b403af9b6ae1e110
 (1.0.12)
 CVE-2015-5243 (phpWhois allows remote attackers to execute arbitrary code via 
a craft ...)
        NOT-FOR-US: phpWhois
 CVE-2015-5242 (OpenStack Swift-on-File (aka Swiftonfile) does not properly 
restrict u ...)
@@ -871935,7 +871935,7 @@ CVE-2015-5221 (Use-after-free vulnerability in the 
mif_process_cmpt function in
        [wheezy] - jasper <no-dsa> (Minor issue)
        [squeeze] - jasper <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2015/08/20/4
-       NOTE: Fixed by 
https://github.com/mdadams/jasper/commit/df5d2867e8004e51e18b89865bc4aa69229227b3
+       NOTE: Fixed by: 
https://github.com/mdadams/jasper/commit/df5d2867e8004e51e18b89865bc4aa69229227b3
 CVE-2015-5220 (The Web Console in Red Hat Enterprise Application Platform 
(EAP) befor ...)
        NOT-FOR-US: JBoss EAP
 CVE-2015-5219 (The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not 
proper ...)
@@ -880395,7 +880395,7 @@ CVE-2015-2666 (Stack-based buffer overflow in the 
get_matching_model_microcode f
        [wheezy] - linux <not-affected> (Introduced in 3.9)
        - linux-2.6 <not-affected> (Introduced in 3.9)
        NOTE: Introduced by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ec400ddeff200b068ddc6c70f7321f49ecf32ed5
 (v3.9-rc1)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4
 (v4.0-rc1)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4
 (v4.0-rc1)
        NOTE: https://www.openwall.com/lists/oss-security/2015/03/18/7
 CVE-2015-2684 (Shibboleth Service Provider (SP) before 2.5.4 allows remote 
authentica ...)
        {DSA-3207-1 DLA-259-1}
@@ -880405,7 +880405,7 @@ CVE-2015-2672 (The xsave/xrstor implementation in 
arch/x86/include/asm/xsave.h i
        - linux <not-affected> (Vulnerable code not present)
        - linux-2.6 <not-affected> (Vulnerable code not present)
        NOTE: Introduced by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f31a9f7c71691569359fa7fb8b0acaa44bce0324
 (v3.17-rc1)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=06c8173eb92bbfc03a0fe8bb64315857d0badd06
 (v4.0-rc3)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=06c8173eb92bbfc03a0fe8bb64315857d0badd06
 (v4.0-rc3)
        NOTE: https://www.openwall.com/lists/oss-security/2015/03/18/6
 CVE-2015-2331 (Integer overflow in the _zip_cdir_new function in zip_dirent.c 
in libz ...)
        {DSA-3198-1 DLA-212-1}
@@ -880582,7 +880582,7 @@ CVE-2014-9701 (Cross-site scripting (XSS) 
vulnerability in MantisBT before 1.2.1
        - mantis <removed> (bug #780875)
        [wheezy] - mantis <no-dsa> (Minor issue)
        [squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)
-       NOTE: Fixed by https://github.com/mantisbt/mantisbt/commit/d95f070d 
(1.2.x)
+       NOTE: Fixed by: https://github.com/mantisbt/mantisbt/commit/d95f070d 
(1.2.x)
        NOTE: http://article.gmane.org/gmane.comp.security.oss.general/15022
        NOTE: https://www.mantisbt.org/bugs/view.php?id=19493
 CVE-2014-9697 (Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote 
attack ...)
@@ -882939,7 +882939,7 @@ CVE-2014-9679 (Integer underflow in the 
cupsRasterReadPixels function in filter/
        NOTE: https://www.openwall.com/lists/oss-security/2015/02/10/15
 CVE-2015-1573 (The nft_flush_table function in net/netfilter/nf_tables_api.c 
in the L ...)
        - linux <not-affected> (Vulnerable code introduced in v3.18-rc1, never 
in the archive outside of experimental)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/pablo/nf.git/commit/?id=a2f18db0c68fec96631c10cad9384c196e9008ac
 (v3.19-rc5)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/pablo/nf.git/commit/?id=a2f18db0c68fec96631c10cad9384c196e9008ac
 (v3.19-rc5)
        NOTE: Introduced by 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9ac12ef099707f405d7478009564302d7ed8393
 (v3.18-rc1)
        NOTE: https://bugzilla.kernel.org/show_bug.cgi?id=91441
 CVE-2015-2046 (Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and 
later  ...)
@@ -888906,7 +888906,7 @@ CVE-2015-0274 (The XFS implementation in the Linux 
kernel before 3.15 improperly
        - linux 3.11.5-1
        [wheezy] - linux <not-affected> (Introduced in v3.11-rc1)
        - linux-2.6 <not-affected> (Introduced in v3.11-rc1)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59
 (v3.15-rc5)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59
 (v3.15-rc5)
        NOTE: Introduced by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e461fcb194172b3f709e0b478d2ac1bdac7ab9a3
 (v3.11-rc1)
 CVE-2015-0273 (Multiple use-after-free vulnerabilities in ext/date/php_date.c 
in PHP  ...)
        {DSA-3195-1}
@@ -890511,7 +890511,7 @@ CVE-2014-8709 (The ieee80211_fragment function in 
net/mac80211/tx.c in the Linux
        - linux 3.14.2-1
        [wheezy] - linux 3.2.57-1
        - linux-2.6 <removed>
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=338f977f4eb441e69bb9a46eaa0ac715c931a67f
 (v3.14-rc3)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=338f977f4eb441e69bb9a46eaa0ac715c931a67f
 (v3.14-rc3)
        NOTE: Introduced by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2de8e0d999b8790861cd3749bec2236ccc1c8110
 (v2.6.30-rc1)
 CVE-2014-8650 (python-requests-Kerberos through 0.5 does not handle mutual 
authentica ...)
        - python-requests-kerberos 0.5-2 (bug #768408)
@@ -892851,7 +892851,7 @@ CVE-2014-7826 (kernel/trace/trace_syscalls.c in the 
Linux kernel through 3.17.2
        - linux 3.16.7-ckt2-1
        [wheezy] - linux <not-affected> (Vulnerable code introduced later)
        - linux-2.6 <not-affected> (Vulnerable code introduced later)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9
 (v3.18-rc3)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9
 (v3.18-rc3)
        NOTE: Support for SOFT_DISABLE to syscall events was added in 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d562aff93bfb530b0992141500a402d17081189d
 (v3.13-rc1)
 CVE-2014-7825 (kernel/trace/trace_syscalls.c in the Linux kernel through 
3.17.2 does  ...)
        - linux 3.16.7-ckt2-1
@@ -892859,7 +892859,7 @@ CVE-2014-7825 (kernel/trace/trace_syscalls.c in the 
Linux kernel through 3.17.2
        - linux-2.6 <removed>
        [squeeze] - linux-2.6 <not-affected> (Affected feature not enabled)
        NOTE: CONFIG_FTRACE_SYSCALL not enabled in squeeze
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9
 (v3.18-rc3)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9
 (v3.18-rc3)
 CVE-2014-7824 (D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, 
and 1.9. ...)
        {DSA-3099-1}
        - dbus 1.8.10-1
@@ -892870,7 +892870,7 @@ CVE-2014-7823 (The virDomainGetXMLDesc API in Libvirt 
before 1.2.11 allows remot
        [wheezy] - libvirt <not-affected> (Introduced in v1.0.0)
        [squeeze] - libvirt <not-affected> (Introduced in v1.0.0)
        NOTE: Introduced in 
http://libvirt.org/git/?p=libvirt.git;a=commit;h=28f8dfdcccd4c0f69063ef741545b37d8a7f7935
 (v1.0.0)
-       NOTE: Fixed by 
http://libvirt.org/git/?p=libvirt.git;a=commit;h=b1674ad5a97441b7e1bd5f5ebaff498ef2fbb11b
+       NOTE: Fixed by: 
http://libvirt.org/git/?p=libvirt.git;a=commit;h=b1674ad5a97441b7e1bd5f5ebaff498ef2fbb11b
 CVE-2014-7822 (The implementation of certain splice_write file operations in 
the Linu ...)
        {DSA-3170-1 DLA-155-1}
        - linux 3.16.2-1
@@ -898974,7 +898974,7 @@ CVE-2014-5207 (fs/namespace.c in the Linux kernel 
through 3.16.1 does not proper
        - linux 3.16.2-1
        [wheezy] - linux <not-affected> (User namespaces only usable in later 
kernels)
        - linux-2.6 <not-affected> (User namespaces only usable in later 
kernels)
-       NOTE: Fixed by 
https://git.kernel.org/cgit/linux/kernel/git/ebiederm/user-namespace.git/commit/?h=for-linus&id=9566d6742852c527bf5af38af5cbb878dad75705
 (v3.17-rc1)
+       NOTE: Fixed by: 
https://git.kernel.org/cgit/linux/kernel/git/ebiederm/user-namespace.git/commit/?h=for-linus&id=9566d6742852c527bf5af38af5cbb878dad75705
 (v3.17-rc1)
        NOTE: and: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ffbc6f0ead47fa5a1dc9642b0331cb75c20a640e
 (v3.17-rc1)
        NOTE: Introduced by: 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0c55cfc4166d9a0f38de779bd4d75a90afbe7734
 (v3.8)
        NOTE: Thread starting at 
https://www.openwall.com/lists/oss-security/2014/08/12/6
@@ -902797,7 +902797,7 @@ CVE-2014-3631 (The assoc_array_gc function in the 
associative-array implementati
        [wheezy] - linux <not-affected> (Vulnerable code introduced later)
        - linux-2.6 <not-affected> (Vulnerable code introduced later)
        NOTE: Introduced by 
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b2a4df200d570b2c33a57e1ebfa5896e4bc81b69
 (v3.13)
-       NOTE: Fixed by 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=95389b08d93d5c06ec63ab49bd732b0069b7c35e
+       NOTE: Fixed by: 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=95389b08d93d5c06ec63ab49bd732b0069b7c35e
 CVE-2014-3630 (XML external entity (XXE) vulnerability in the Java XML 
processing fun ...)
        NOT-FOR-US: Play framework
 CVE-2014-3629 (XML external entity (XXE) vulnerability in the XML Exchange 
module in  ...)
@@ -904821,7 +904821,7 @@ CVE-2014-3122 (The try_to_unmap_cluster function in 
mm/rmap.c in the Linux kerne
        - linux-2.6 <removed>
        [squeeze] - linux-2.6 2.6.32-48squeeze8
        NOTE: Introduced by 
https://git.kernel.org/linus/b291f000393f5a0b679012b39d79fbc85c018233
-       NOTE: Fixed by 
https://git.kernel.org/linus/57e68e9cd65b4b8eb4045a1e0d0746458502554c 
(v3.15-rc1)
+       NOTE: Fixed by: 
https://git.kernel.org/linus/57e68e9cd65b4b8eb4045a1e0d0746458502554c 
(v3.15-rc1)
 CVE-2014-3985 (The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 
allows remo ...)
        - miniupnpc 1.6-4 (low; bug #748913)
        [wheezy] - miniupnpc <not-affected> (Vulnerable code not present)
@@ -907401,7 +907401,7 @@ CVE-2014-2038 (The nfs_can_extend_write function in 
fs/nfs/write.c in the Linux
        [wheezy] - linux <not-affected> (Introduced in 3.11)
        - linux-2.6 <not-affected> (Introduced in 3.11)
        NOTE: Introduced by 
https://git.kernel.org/linus/c7559663e42f4294ffe31fe159da6b6a66b35d61
-       NOTE: Fixed by 
https://git.kernel.org/linus/263b4509ec4d47e0da3e753f85a39ea12d1eff24
+       NOTE: Fixed by: 
https://git.kernel.org/linus/263b4509ec4d47e0da3e753f85a39ea12d1eff24
 CVE-2014-2036
        RESERVED
 CVE-2014-2035 (Cross-site scripting (XSS) vulnerability in xhr.php in 
InterWorx Web C ...)
@@ -907737,7 +907737,7 @@ CVE-2014-1878 (Stack-based buffer overflow in the 
cmd_submitf function in cgi/cm
        {DSA-2956-1 DLA-1615-1 DLA-461-1 DLA-60-1}
        - icinga 1.10.3-1
        - nagios3 <removed> (bug #823721)
-       NOTE: Fixed by 
https://github.com/Icinga/icinga-core/commit/eedf4f7d88cdc50843572224eb38a2f5c78a2dc5
+       NOTE: Fixed by: 
https://github.com/Icinga/icinga-core/commit/eedf4f7d88cdc50843572224eb38a2f5c78a2dc5
 CVE-2014-1873
        RESERVED
 CVE-2014-1872
@@ -911876,7 +911876,7 @@ CVE-2013-7205 (Off-by-one error in the 
process_cgivars function in contrib/daemo
        [squeeze] - nagios3 <no-dsa> (Minor issue)
        [wheezy] - nagios3 <no-dsa> (Minor issue)
        NOTE: additional changed files for nagios3, cf. CVE-2013-7108
-       NOTE: Fixed by 
https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
+       NOTE: Fixed by: 
https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
        NOTE: See also https://github.com/Icinga/icinga-core/issues/1399
 CVE-2013-7203 (gitolite before commit fa06a34 might allow local users to read 
arbitra ...)
        - gitolite3 3.5.3.1-1
@@ -912035,7 +912035,7 @@ CVE-2013-7108 (Multiple off-by-one errors in Nagios 
Core 3.5.1, 4.0.2, and earli
        [wheezy] - nagios3 <no-dsa> (Minor issue)
        NOTE: https://dev.icinga.org/issues/5251
        NOTE: separate CVE requested for nagios, 
https://www.openwall.com/lists/oss-security/2013/12/23/4
-       NOTE: Fixed by 
https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
+       NOTE: Fixed by: 
https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
 CVE-2013-7107 (Cross-site request forgery (CSRF) vulnerability in cmd.cgi in 
Icinga 1 ...)
        {DSA-2956-1}
        - icinga 1.10.2-1 (low)
@@ -920688,7 +920688,7 @@ CVE-2013-4270 (The net_ctl_permissions function in 
net/sysctl_net.c in the Linux
        - linux 3.11.5-1
        [wheezy] - linux <not-affected> (Introduced in 3.8)
        NOTE: Introduced with 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cff109768b2d9c03095848f4cd4b0754117262aa
-       NOTE: Fixed by 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2433c8f094a008895e66f25bd1773cdb01c91d01
+       NOTE: Fixed by: 
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2433c8f094a008895e66f25bd1773cdb01c91d01
 CVE-2013-4269
        REJECTED
 CVE-2013-4268



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/02a6602450210cc78e77e917a9e03faecc7a980d...783cc5b965982aebe09e745d77a7864048cf4f37

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/02a6602450210cc78e77e917a9e03faecc7a980d...783cc5b965982aebe09e745d77a7864048cf4f37
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to