summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMartin Pitt <martin@piware.de>2022-01-25 08:32:07 +0100
committerMartin Pitt <martin@piware.de>2022-01-25 08:36:53 +0100
commite47311e001e25fc0c80696f2f17a861d1061e789 (patch)
treea698b7e5905187dba13ab1a55ac31888f6fa9831
parentb804dc5df5919c47a69c7041684e816b70323dbe (diff)
Track fixed version for CVE-2021-3698/cockpit
The fix also needs sssd 2.6.1, which is also in bookworm now.
-rw-r--r--data/CVE/2021.list4
1 files changed, 3 insertions, 1 deletions
diff --git a/data/CVE/2021.list b/data/CVE/2021.list
index 7aea5792af..14dbb36ed8 100644
--- a/data/CVE/2021.list
+++ b/data/CVE/2021.list
@@ -20386,10 +20386,12 @@ CVE-2021-38365 (Winner (aka ToneWinner) desktop speakers through 2021-08-09 allo
NOT-FOR-US: Winner (aka ToneWinner) desktop speakers
CVE-2021-3698 [authenticates with revoked certificates]
RESERVED
- - cockpit <unfixed>
+ - cockpit 260-1
[bullseye] - cockpit <no-dsa> (Minor issue)
[buster] - cockpit <not-affected> (Vulnerable code not present, introduced in 208)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1992149
+ NOTE: Needs sssd 2.6.1
+ NOTE: https://cockpit-project.org/blog/cockpit-260.html
CVE-2021-3697
RESERVED
CVE-2021-3696

© 2014-2024 Faster IT GmbH | imprint | privacy policy