From a09c11523791c84acef8a3a91d1099a5af004402 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Thu, 26 Nov 2020 07:39:55 +0100 Subject: Mark CVE-2020-26238 as NFU Please do review, though I have not found the cron-utils Java library in the archive or removed (it is different from src:cronutils). --- data/CVE/list | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index a28ecc5ac1..0b2594a933 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -9538,7 +9538,7 @@ CVE-2020-26240 (Go Ethereum, or "Geth", is the official Golang implementation of CVE-2020-26239 (Scratch Addons is a WebExtension that supports both Chrome and Firefox ...) NOT-FOR-US: Scratch Addons CVE-2020-26238 (Cron-utils is a Java library to parse, validate, migrate crons as well ...) - TODO: check + NOT-FOR-US: cron-utils Java library CVE-2020-26237 (Highlight.js is a syntax highlighter written in JavaScript. Highlight. ...) TODO: check CVE-2020-26236 (In ScratchVerifier before commit a603769, an attacker can hijack the v ...) -- cgit v1.2.3