From 4da3978e17bbc0e5b784eb6cf8d8ee2a5ae953ce Mon Sep 17 00:00:00 2001 From: "Danilo G. Baio" Date: Sun, 7 Jun 2020 02:20:40 +0000 Subject: [PATCH] security/vuxml: Update CVE-2019-18348 and CVE-2020-8492 entries CVE-2019-18348: Add missing Python packages range CVE-2020-8492: Fix Python 3.7 entrie, it's currently affected. After committing fixes, we'll need to change ranges again. PR: 246984 --- security/vuxml/vuln.xml | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 14b1c35e1604..a5b76a05ebec 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -1549,6 +1549,18 @@ Workaround: python38 3.8.3 + + python37 + 3.7.8 + + + python36 + 3.6.11 + + + python35 + 3.5.10 + @@ -1569,6 +1581,7 @@ Workaround: 2019-10-24 2020-05-09 + 2020-06-07 @@ -2288,7 +2301,7 @@ If successful, a malicious third party could trigger either a crash of VLC or an python37 - 3.7.7 + 3.7.8 python36 @@ -2324,6 +2337,7 @@ If successful, a malicious third party could trigger either a crash of VLC or an 2019-11-17 2020-04-23 + 2020-06-07