Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 6cc8c247 by security tracker role at 2021-06-29T20:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,21 @@ +CVE-2021-3630 + RESERVED +CVE-2021-3629 + RESERVED +CVE-2021-3628 + RESERVED +CVE-2021-3627 + RESERVED +CVE-2021-35940 + RESERVED +CVE-2021-35939 + RESERVED +CVE-2021-35938 + RESERVED +CVE-2021-35937 + RESERVED +CVE-2021-35936 + RESERVED CVE-2021-3626 RESERVED CVE-2021-3625 @@ -2331,8 +2349,8 @@ CVE-2021-34825 (Quassel through 0.13.1, when --require-ssl is enabled, launches NOTE: https://github.com/quassel/quassel/pull/581 NOTE: https://bugs.quassel-irc.org/issues/1728 NOTE: '--require-ssl' flag added in https://github.com/quassel/quassel/pull/43 -CVE-2021-34824 - RESERVED +CVE-2021-34824 (Istio before 1.9.6 and 1.10.x before 1.10.2 has Incorrect Access Contr ...) + TODO: check CVE-2021-34823 RESERVED CVE-2021-34822 @@ -2975,20 +2993,17 @@ CVE-2021-34552 RESERVED CVE-2021-34551 (PHPMailer before 6.5.0 on Windows allows remote code execution if lang ...) - libphp-phpmailer <not-affected> (Windows-specific) -CVE-2021-34550 [out-of-bounds memory access in v3 onion service descriptor parsing] - RESERVED +CVE-2021-34550 (An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The ...) {DSA-4932-1} - tor 0.4.5.9-1 (bug #990000) [stretch] - tor <end-of-life> (See DSA 4644) NOTE: https://blog.torproject.org/node/2041 -CVE-2021-34549 [hashtable-based CPU denial-of-service attack against relays] - RESERVED +CVE-2021-34549 (An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Has ...) {DSA-4932-1} - tor 0.4.5.9-1 (bug #990000) [stretch] - tor <end-of-life> (See DSA 4644) NOTE: https://blog.torproject.org/node/2041 -CVE-2021-34548 - RESERVED +CVE-2021-34548 (An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An ...) {DSA-4932-1} - tor 0.4.5.9-1 (bug #990000) [stretch] - tor <end-of-life> (See DSA 4644) @@ -4579,6 +4594,7 @@ CVE-2021-33815 (dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-o CVE-2021-33814 RESERVED CVE-2021-33813 (An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to c ...) + {DLA-2696-1} - libjdom2-intellij-java <unfixed> - libjdom2-java <unfixed> - libjdom1-java <undetermined> @@ -5350,8 +5366,7 @@ CVE-2021-33505 RESERVED CVE-2021-33504 RESERVED -CVE-2021-33503 [Catastrophic backtracking in URL authority parser when passed URL containing many @ characters] - RESERVED +CVE-2021-33503 (An issue was discovered in urllib3 before 1.26.5. When provided with a ...) [experimental] - python-urllib3 1.26.5-1~exp1 - python-urllib3 <unfixed> (bug #989848) [buster] - python-urllib3 <no-dsa> (Minor issue) @@ -6522,16 +6537,16 @@ CVE-2021-32994 RESERVED CVE-2021-32993 RESERVED -CVE-2021-32992 - RESERVED +CVE-2021-32992 (FATEK Automation WinProladder Versions 3.30 and prior do not properly ...) + TODO: check CVE-2021-32991 RESERVED -CVE-2021-32990 - RESERVED +CVE-2021-32990 (FATEK Automation WinProladder Versions 3.30 and prior are vulnerable t ...) + TODO: check CVE-2021-32989 RESERVED -CVE-2021-32988 - RESERVED +CVE-2021-32988 (FATEK Automation WinProladder Versions 3.30 and prior are vulnerable t ...) + TODO: check CVE-2021-32987 RESERVED CVE-2021-32986 @@ -7106,8 +7121,8 @@ CVE-2021-32723 (Prism is a syntax highlighting library. Some languages before 1. NOT-FOR-US: Prism CVE-2021-32722 (GlobalNewFiles is a mediawiki extension. All existing versions of Glob ...) NOT-FOR-US: GlobalNewFiles MediaWiki extension -CVE-2021-32721 - RESERVED +CVE-2021-32721 (PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux ...) + TODO: check CVE-2021-32720 (Sylius is an Open Source eCommerce platform on top of Symfony. In vers ...) NOT-FOR-US: Sylius CVE-2021-32719 (RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prio ...) @@ -7502,8 +7517,7 @@ CVE-2021-32566 [Specific sequence of HTTP/2 frames can cause ATS to crash] NOTE: https://github.com/apache/trafficserver/pull/7945 (8.1.x) NOTE: https://github.com/apache/trafficserver/commit/034965e0fd0def114658f0048d953d1c16a95bed (master) NOTE: https://github.com/apache/trafficserver/commit/b82a3d192f995fb9d78e1c44d51d9acca4783277 (8.1.x) -CVE-2021-32565 [HTTP Request Smuggling, content length with invalid charters] - RESERVED +CVE-2021-32565 (Invalid values in the Content-Length header sent to Apache Traffic Ser ...) - trafficserver <unfixed> (bug #990303) NOTE: https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E NOTE: https://github.com/apache/trafficserver/pull/7945 (8.1.x) @@ -9278,8 +9292,8 @@ CVE-2021-31840 (A vulnerability in the preloading mechanism of specific dynamic NOT-FOR-US: McAfee CVE-2021-31839 (Improper privilege management vulnerability in McAfee Agent for Window ...) NOT-FOR-US: McAfee -CVE-2021-31838 - RESERVED +CVE-2021-31838 (A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4. ...) + TODO: check CVE-2021-31837 (Memory corruption vulnerability in the driver file component in McAfee ...) NOT-FOR-US: McAfee CVE-2021-31836 @@ -10054,10 +10068,10 @@ CVE-2021-31533 RESERVED CVE-2021-31532 (NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 ...) NOT-FOR-US: NXP -CVE-2021-31531 - RESERVED -CVE-2021-31530 - RESERVED +CVE-2021-31531 (Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to S ...) + TODO: check +CVE-2021-31530 (Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to I ...) + TODO: check CVE-2021-31529 RESERVED CVE-2021-31528 @@ -10180,30 +10194,30 @@ CVE-2021-3504 (A flaw was found in the hivex library in versions before 1.3.20. CVE-2021-3503 RESERVED - wildfly <itp> (bug #752018) -CVE-2021-31516 - RESERVED -CVE-2021-31515 - RESERVED -CVE-2021-31514 - RESERVED -CVE-2021-31513 - RESERVED -CVE-2021-31512 - RESERVED -CVE-2021-31511 - RESERVED -CVE-2021-31510 - RESERVED -CVE-2021-31509 - RESERVED -CVE-2021-31508 - RESERVED -CVE-2021-31507 - RESERVED -CVE-2021-31506 - RESERVED -CVE-2021-31505 - RESERVED +CVE-2021-31516 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31515 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31514 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31513 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31512 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31511 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31510 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31509 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31508 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31507 (This vulnerability allows remote attackers to execute arbitrary code o ...) + TODO: check +CVE-2021-31506 (This vulnerability allows remote attackers to disclose sensitive infor ...) + TODO: check +CVE-2021-31505 (This vulnerability allows attackers with physical access to escalate p ...) + TODO: check CVE-2021-31504 RESERVED CVE-2021-31503 @@ -10996,8 +11010,8 @@ CVE-2021-31162 (In the standard library in Rust before 1.52.0, a double free can NOTE: https://github.com/rust-lang/rust/pull/83629 CVE-2021-31161 RESERVED -CVE-2021-31160 - RESERVED +CVE-2021-31160 (Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker ...) + TODO: check CVE-2021-31159 (Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a ...) NOT-FOR-US: Zoho ManageEngine CVE-2021-31158 (In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, ...) @@ -15052,8 +15066,8 @@ CVE-2021-29487 RESERVED CVE-2021-29486 (cumulative-distribution-function is an open source npm library used wh ...) NOT-FOR-US: Node cumulative-distribution-function -CVE-2021-29485 - RESERVED +CVE-2021-29485 (Ratpack is a toolkit for creating web applications. In versions prior ...) + TODO: check CVE-2021-29484 (Ghost is a Node.js CMS. An unused endpoint added during the developmen ...) NOT-FOR-US: Ghost CMS CVE-2021-29483 (ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' ...) @@ -15062,12 +15076,12 @@ CVE-2021-29482 (xz is a compression and decompression library focusing on the xz - golang-github-ulikunitz-xz 0.5.6-2 (bug #988243) NOTE: https://github.com/ulikunitz/xz/security/advisories/GHSA-25xm-hr59-7c27 NOTE: https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b -CVE-2021-29481 - RESERVED -CVE-2021-29480 - RESERVED -CVE-2021-29479 - RESERVED +CVE-2021-29481 (Ratpack is a toolkit for creating web applications. In versions prior ...) + TODO: check +CVE-2021-29480 (Ratpack is a toolkit for creating web applications. In versions prior ...) + TODO: check +CVE-2021-29479 (Ratpack is a toolkit for creating web applications. In versions prior ...) + TODO: check CVE-2021-29478 (Redis is an open source (BSD licensed), in-memory data structure store ...) - redis 5:6.0.13-1 (bug #988045) [buster] - redis <not-affected> (Vulnerable code not present) @@ -16711,8 +16725,8 @@ CVE-2021-27851 (A security vulnerability that can lead to local privilege escala NOTE: https://git.savannah.gnu.org/cgit/guix.git/commit/?id=ec7fb669945bfb47c5e1fdf7de3a5d07f7002ccf NOTE: https://guix.gnu.org/en/blog/2021/risk-of-local-privilege-escalation-via-guix-daemon/ NOTE: Neutralised by kernel hardening (fs.protected_hardlinks = 1) -CVE-2021-28830 - RESERVED +CVE-2021-28830 (The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R component ...) + TODO: check CVE-2021-28829 (The Administration GUI component of TIBCO Software Inc.'s TIBCO Admini ...) NOT-FOR-US: TIBCO CVE-2021-28828 (The Administration GUI component of TIBCO Software Inc.'s TIBCO Admini ...) @@ -16997,14 +17011,12 @@ CVE-2021-28692 [inappropriate x86 IOMMU timeout detection / handling] - xen <unfixed> [stretch] - xen <end-of-life> (DSA 4602-1) NOTE: https://xenbits.xen.org/xsa/advisory-373.html -CVE-2021-28691 [Guest triggered use-after-free in Linux xen-netback] - RESERVED +CVE-2021-28691 (Guest triggered use-after-free in Linux xen-netback A malicious or bug ...) - linux 5.10.46-1 [buster] - linux <not-affected> (Vulnerable code introduced later) [stretch] - linux <not-affected> (Vulnerable code introduced later) NOTE: https://xenbits.xen.org/xsa/advisory-374.html -CVE-2021-28690 [x86: TSX Async Abort protections not restored after S3] - RESERVED +CVE-2021-28690 (x86: TSX Async Abort protections not restored after S3 This issue rela ...) {DSA-4931-1} - xen <unfixed> [stretch] - xen <end-of-life> (DSA 4602-1) @@ -19708,8 +19720,7 @@ CVE-2021-27579 (Snow Inventory Agent through 6.7.0 on Windows uses CPUID to repo NOT-FOR-US: Snow Inventory Agent CVE-2021-27578 RESERVED -CVE-2021-27577 [Incorrect handling of url fragment leads to cache poisoning] - RESERVED +CVE-2021-27577 (Incorrect handling of url fragment vulnerability of Apache Traffic Ser ...) - trafficserver <unfixed> (bug #990303) NOTE: https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E NOTE: https://github.com/apache/trafficserver/pull/7945 (8.1.x) @@ -29620,8 +29631,8 @@ CVE-2021-23402 RESERVED CVE-2021-23401 RESERVED -CVE-2021-23400 - RESERVED +CVE-2021-23400 (The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...) + TODO: check CVE-2021-23399 (This affects all versions of package wincred. If attacker-controlled u ...) NOT-FOR-US: wincred CVE-2021-23398 (All versions of package react-bootstrap-table are vulnerable to Cross- ...) @@ -29924,8 +29935,8 @@ CVE-2021-23277 (Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerabl NOT-FOR-US: Eaton Intelligent Power Manager (IPM) CVE-2021-23276 (Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to a ...) NOT-FOR-US: Eaton Intelligent Power Manager (IPM) -CVE-2021-23275 - RESERVED +CVE-2021-23275 (The Windows Installation component of TIBCO Software Inc.'s TIBCO Ente ...) + TODO: check CVE-2021-23274 (The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Ga ...) NOT-FOR-US: TIBCO CVE-2021-23273 (The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire ...) @@ -31586,8 +31597,8 @@ CVE-2021-22547 (In IoT Devices SDK, there is an implementation of calloc() that NOT-FOR-US: Google Cloud IoT Device SDK CVE-2021-22546 RESERVED -CVE-2021-22545 - RESERVED +CVE-2021-22545 (An attacker can craft a specific IdaPro *.i64 file that will cause the ...) + TODO: check CVE-2021-22544 RESERVED CVE-2021-22543 (An issue was discovered in Linux: KVM through Improper handling of VM_ ...) @@ -31801,8 +31812,8 @@ CVE-2021-22441 RESERVED CVE-2021-22440 RESERVED -CVE-2021-22439 - RESERVED +CVE-2021-22439 (There is a deserialization vulnerability in Huawei AnyOffice V200R006C ...) + TODO: check CVE-2021-22438 RESERVED CVE-2021-22437 @@ -31999,12 +32010,12 @@ CVE-2021-22342 (There is an information leak vulnerability in Huawei products. A NOT-FOR-US: Huawei CVE-2021-22341 RESERVED -CVE-2021-22340 - RESERVED +CVE-2021-22340 (There is a multiple threads race condition vulnerability in Huawei pro ...) + TODO: check CVE-2021-22339 (There is a denial of service vulnerability in some versions of ManageO ...) NOT-FOR-US: Huawei -CVE-2021-22338 - RESERVED +CVE-2021-22338 (There is an XXE injection vulnerability in eCNS280 V100R005C00 and V10 ...) + TODO: check CVE-2021-22337 (There is an Information Disclosure vulnerability in Huawei Smartphone. ...) NOT-FOR-US: Huawei CVE-2021-22336 (There is an Improper Control of Generation of Code vulnerability in Hu ...) @@ -32021,8 +32032,8 @@ CVE-2021-22331 (There is a JavaScript injection vulnerability in certain Huawei NOT-FOR-US: Huawei CVE-2021-22330 (There is an out of bounds write vulnerability in Huawei Smartphone HUA ...) NOT-FOR-US: Huawei -CVE-2021-22329 - RESERVED +CVE-2021-22329 (There has a license management vulnerability in some Huawei products. ...) + TODO: check CVE-2021-22328 RESERVED CVE-2021-22327 (There is an arbitrary memory write vulnerability in Huawei smart phone ...) @@ -32501,8 +32512,7 @@ CVE-2021-22121 RESERVED CVE-2021-22120 RESERVED -CVE-2021-22119 - RESERVED +CVE-2021-22119 (Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5 ...) - libspring-security-2.0-java <removed> CVE-2021-22118 (In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x ...) - libspring-java <not-affected> (Introduced in v5.0.0.RC1) @@ -33019,8 +33029,8 @@ CVE-2021-21873 RESERVED CVE-2021-21872 RESERVED -CVE-2021-21871 - RESERVED +CVE-2021-21871 (A memory corruption vulnerability exists in the DMG File Format Handle ...) + TODO: check CVE-2021-21870 RESERVED CVE-2021-21869 @@ -37489,8 +37499,8 @@ CVE-2021-20582 RESERVED CVE-2021-20581 RESERVED -CVE-2021-20580 - RESERVED +CVE-2021-20580 (IBM Planning Analytics 2.0 could be vulnerable to cross-site request f ...) + TODO: check CVE-2021-20579 (IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, ...) NOT-FOR-US: IBM CVE-2021-20578 @@ -37669,8 +37679,8 @@ CVE-2021-20492 (IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java NOT-FOR-US: IBM CVE-2021-20491 (IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based bu ...) NOT-FOR-US: IBM -CVE-2021-20490 - RESERVED +CVE-2021-20490 (IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local us ...) + TODO: check CVE-2021-20489 RESERVED CVE-2021-20488 (IBM Security Identity Manager 6.0.2 could allow an authenticated malic ...) @@ -37695,8 +37705,8 @@ CVE-2021-20479 RESERVED CVE-2021-20478 RESERVED -CVE-2021-20477 - RESERVED +CVE-2021-20477 (IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This ...) + TODO: check CVE-2021-20476 RESERVED CVE-2021-20475 @@ -38836,16 +38846,16 @@ CVE-2021-20107 RESERVED CVE-2021-20106 RESERVED -CVE-2021-20105 - RESERVED -CVE-2021-20104 - RESERVED -CVE-2021-20103 - RESERVED -CVE-2021-20102 - RESERVED -CVE-2021-20101 - RESERVED +CVE-2021-20105 (Machform prior to version 16 is vulnerable to an open redirect in Safa ...) + TODO: check +CVE-2021-20104 (Machform prior to version 16 is vulnerable to unauthenticated remote c ...) + TODO: check +CVE-2021-20103 (Machform prior to version 16 is vulnerable to stored cross-site script ...) + TODO: check +CVE-2021-20102 (Machform prior to version 16 is vulnerable to cross-site request forge ...) + TODO: check +CVE-2021-20101 (Machform prior to version 16 is vulnerable to HTTP host header injecti ...) + TODO: check CVE-2021-20100 (Nessus Agent 8.2.4 and earlier for Windows were found to contain multi ...) TODO: check CVE-2021-20099 (Nessus Agent 8.2.4 and earlier for Windows were found to contain multi ...) @@ -38888,8 +38898,8 @@ CVE-2021-20081 (Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk NOT-FOR-US: ManageEngine ServiceDesk Plus CVE-2021-20080 (Insufficient output sanitization in ManageEngine ServiceDesk Plus befo ...) NOT-FOR-US: ManageEngine ServiceDesk Plus -CVE-2021-20079 - RESERVED +CVE-2021-20079 (Nessus versions 8.13.2 and earlier were found to contain a privilege e ...) + TODO: check CVE-2021-20078 (Manage Engine OpManager builds below 125346 are vulnerable to a remote ...) NOT-FOR-US: Manage Engine OpManager CVE-2021-20077 (Nessus versions 8.13.2 and earlier were found to contain a privilege e ...) @@ -64247,8 +64257,8 @@ CVE-2020-21396 RESERVED CVE-2020-21395 RESERVED -CVE-2020-21394 - RESERVED +CVE-2020-21394 (SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB ma ...) + TODO: check CVE-2020-21393 RESERVED CVE-2020-21392 @@ -70965,8 +70975,8 @@ CVE-2020-18068 RESERVED CVE-2020-18067 RESERVED -CVE-2020-18066 - RESERVED +CVE-2020-18066 (Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName ...) + TODO: check CVE-2020-18065 RESERVED CVE-2020-18064 @@ -98569,14 +98579,14 @@ CVE-2020-7873 RESERVED CVE-2020-7872 RESERVED -CVE-2020-7871 - RESERVED -CVE-2020-7870 - RESERVED -CVE-2020-7869 - RESERVED -CVE-2020-7868 - RESERVED +CVE-2020-7871 (A vulnerability of Helpcom could allow an unauthenticated attacker to ...) + TODO: check +CVE-2020-7870 (A memory corruption vulnerability exists when ezPDF improperly handles ...) + TODO: check +CVE-2020-7869 (An improper input validation vulnerability of ZOOK software (remote ad ...) + TODO: check +CVE-2020-7868 (A remote code execution vulnerability exists in helpUS(remote administ ...) + TODO: check CVE-2020-7867 RESERVED CVE-2020-7866 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cc8c2476ed4a509976acac9e0717bbcaf8dede2 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6cc8c2476ed4a509976acac9e0717bbcaf8dede2 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits