From 295a2b578e2764252ec6ebb57912dd7b326ea9c8 Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Tue, 17 May 2022 23:04:43 +0200 Subject: buster/bullseye triage --- data/CVE/list | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/data/CVE/list b/data/CVE/list index 973b91196e..25fa582026 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -3,11 +3,10 @@ CVE-2022-30973 CVE-2022-1770 RESERVED CVE-2022-1769 (Buffer Over-read in GitHub repository vim/vim prior to 8.2. ...) - - vim - [bullseye] - vim (Minor issue) - [buster] - vim (Minor issue) + - vim (unimportant) NOTE: https://huntr.dev/bounties/522076b2-96cb-4df6-a504-e6e2f64c171c NOTE: https://github.com/vim/vim/commit/4748c4bd64610cf943a431d215bb1aad51f8d0b4 (v8.2.4974) + NOTE: Crash in CLI tool, no security impact CVE-2022-1768 RESERVED CVE-2022-1767 @@ -259,22 +258,20 @@ CVE-2022-1736 NOTE: service was enabled by default (and not automatically enabled anymore since 42.1.1-2) TODO: check, if we want to threat this as unimportant severity issue CVE-2022-1735 (Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2. ...) - - vim - [bullseye] - vim (Minor issue) - [buster] - vim (Minor issue) + - vim (unimportant) NOTE: https://huntr.dev/bounties/c9f85608-ff11-48e4-933d-53d1759d44d9 NOTE: https://github.com/vim/vim/commit/7ce5b2b590256ce53d6af28c1d203fb3bc1d2d97 (v8.2.4969) + NOTE: Crash in CLI tool, no security impact CVE-2022-1734 RESERVED - linux (unimportant) NOTE: https://git.kernel.org/linus/d270453a0d9ec10bb8a802a142fb1b3601a83098 (5.18-rc6) NOTE: Support for Marvell NFC devices (CONFIG_NFC_MRVL) not enabled CVE-2022-1733 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. ...) - - vim - [bullseye] - vim (Minor issue) - [buster] - vim (Minor issue) + - vim (unimportant) NOTE: https://huntr.dev/bounties/6ff03b27-472b-4bef-a2bf-410fae65ff0a NOTE: https://github.com/vim/vim/commit/60ae0e71490c97f2871a6344aca61cacf220f813 (v8.2.4968) + NOTE: Crash in CLI tool, no security impact CVE-2022-1732 RESERVED CVE-2022-1731 (Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to ...) -- cgit v1.2.3