From 7ae4f8aa0d84443332b80292d2a2cd97af2630ce Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sun, 2 Jul 2023 14:43:41 +0200 Subject: Mark CVE-2017-16516 and CVE-2022-24795 for now as unfixed according to #1040036 --- data/CVE/list | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/data/CVE/list b/data/CVE/list index 8b94cd8259..18a135a320 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -104245,7 +104245,7 @@ CVE-2022-24795 (yajl-ruby is a C binding to the YAJL JSON parsing and generation [bullseye] - ruby-yajl (Minor issue) [buster] - ruby-yajl (Minor issue) [stretch] - ruby-yajl (Minor issue) - - yajl 1.0.5.dfsg-1 (bug #1040036) + - yajl (bug #1040036) NOTE: https://github.com/brianmario/yajl-ruby/security/advisories/GHSA-jj47-x69x-mxrm NOTE: https://github.com/brianmario/yajl-ruby/commit/7168bd79b888900aa94523301126f968a93eb3a6 NOTE: https://github.com/brianmario/yajl-ruby/commit/e8de283a6d64f0902740fd09e858fc3d7d803161 @@ -381971,7 +381971,7 @@ CVE-2017-16516 (In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is - ruby-yajl 1.2.0-3.1 (low; bug #880691) [stretch] - ruby-yajl (Minor issue) [jessie] - ruby-yajl (Minor issue) - - yajl 1.0.5.dfsg-1 (bug #1040036) + - yajl (bug #1040036) NOTE: https://github.com/brianmario/yajl-ruby/issues/176 NOTE: https://github.com/brianmario/yajl-ruby/commit/a8ca8f476655adaa187eedc60bdc770fff3c51ce NOTE: yail: https://github.com/lloyd/yajl/issues/248 -- cgit v1.2.3