From 27139c12b70c4da43c5f0966dea27e14b290b68f Mon Sep 17 00:00:00 2001 From: Sylvain Beucler Date: Fri, 14 Jan 2022 15:59:33 +0100 Subject: CVE-2020-29510,CVE-2020-29511/golang: harmonize stretch status --- data/CVE/list.2020 | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'data/CVE/list.2020') diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index 9590c7766e..22ced3ae31 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -3985,9 +3985,9 @@ CVE-2020-29511 (The encoding/xml package in Go (all versions) does not correctly CVE-2020-29510 (The encoding/xml package in Go versions 1.15 and earlier does not corr ...) - golang-1.15 (unimportant) - golang-1.11 (unimportant) - - golang-1.8 + - golang-1.8 (unimportant) [stretch] - golang-1.8 (deemed unfixable by upstream who shifts responsibility to saml packages we don't ship) - - golang-1.7 + - golang-1.7 (unimportant) [stretch] - golang-1.7 (deemed unfixable by upstream who shifts responsibility to saml packages we don't ship) NOTE: https://github.com/golang/go/issues/43168 NOTE: https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ -- cgit v1.2.3