Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 742833e0 by Salvatore Bonaccorso at 2020-11-21T08:54:30+01:00 Add CVE-2020-27748//xdg-utils - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -5459,8 +5459,13 @@ CVE-2020-27750 RESERVED CVE-2020-27749 RESERVED -CVE-2020-27748 +CVE-2020-27748 [local file inclusion vulnerability] RESERVED + - xdg-utils <unfixed> + NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1899769 + NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1613425 + NOTE: Proposed change: https://gitlab.freedesktop.org/Mic92/xdg-utils/-/commit/1f199813e0eb0246f63b54e9e154970e609575af + NOTE: https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/177 CVE-2020-27747 (An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973 ...) NOT-FOR-US: Click Studios Passwordstate CVE-2020-27746 [X11 forwarding - avoid unsafe use of magic cookie as arg to xauth command] View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/742833e0c84026d14a406c51ba28e1bfa3c9a0b9 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/742833e0c84026d14a406c51ba28e1bfa3c9a0b9 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits