From b0a68a46d73b0d0d2fb06ade68d2ad812838b9e1 Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Thu, 13 Jan 2022 13:16:16 +0530 Subject: [PATCH 1/2] changelog: Adapt the securities in accordance to new policies Signed-off-by: Sayan Chowdhury --- .../changelog/security/2021-11-25-CVE-2020-13844.md | 2 +- .../changelog/security/2021-12-01-vim-8.2.3582.md | 9 +-------- .../changelog/security/2021-12-02-edk2-ovmf.md | 5 +---- .../changelog/security/2021-12-09-libarchive-3.5.2.md | 3 +-- .../changelog/security/2021-12-10-libxslt.md | 2 +- 5 files changed, 5 insertions(+), 16 deletions(-) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-11-25-CVE-2020-13844.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-11-25-CVE-2020-13844.md index 31fcfa416f..7aafaea54f 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-11-25-CVE-2020-13844.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-11-25-CVE-2020-13844.md @@ -1 +1 @@ -- [CVE-2020-13844](https://nvd.nist.gov/vuln/detail/CVE-2020-13844) +- gcc ([CVE-2020-13844](https://nvd.nist.gov/vuln/detail/CVE-2020-13844)) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-01-vim-8.2.3582.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-01-vim-8.2.3582.md index 3b2ce37fea..af857a7241 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-01-vim-8.2.3582.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-01-vim-8.2.3582.md @@ -1,8 +1 @@ -- [CVE-2021-3872](https://nvd.nist.gov/vuln/detail/CVE-2021-3872) -- [CVE-2021-3875](https://nvd.nist.gov/vuln/detail/CVE-2021-3875) -- [CVE-2021-3903](https://nvd.nist.gov/vuln/detail/CVE-2021-3903) -- [CVE-2021-3927](https://nvd.nist.gov/vuln/detail/CVE-2021-3927) -- [CVE-2021-3928](https://nvd.nist.gov/vuln/detail/CVE-2021-3928) -- [CVE-2021-3968](https://nvd.nist.gov/vuln/detail/CVE-2021-3968) -- [CVE-2021-3973](https://nvd.nist.gov/vuln/detail/CVE-2021-3973) -- [CVE-2021-3974](https://nvd.nist.gov/vuln/detail/CVE-2021-3974) +- vim ([CVE-2021-3872](https://nvd.nist.gov/vuln/detail/CVE-2021-3872), [CVE-2021-3875](https://nvd.nist.gov/vuln/detail/CVE-2021-3875), [CVE-2021-3903](https://nvd.nist.gov/vuln/detail/CVE-2021-3903), [CVE-2021-3927](https://nvd.nist.gov/vuln/detail/CVE-2021-3927), [CVE-2021-3928](https://nvd.nist.gov/vuln/detail/CVE-2021-3928), [CVE-2021-3968](https://nvd.nist.gov/vuln/detail/CVE-2021-3968), [CVE-2021-3973](https://nvd.nist.gov/vuln/detail/CVE-2021-3973), [CVE-2021-3974](https://nvd.nist.gov/vuln/detail/CVE-2021-3974)) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md index d0e86cea8c..65c58a219a 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md @@ -1,4 +1 @@ -- [CVE-2019-14584](https://nvd.nist.gov/vuln/detail/CVE-2019-14584) -- [CVE-2021-28210](https://nvd.nist.gov/vuln/detail/CVE-2021-28210) -- [CVE-2021-28211](https://nvd.nist.gov/vuln/detail/CVE-2021-28211) -- [CVE-2021-28213](https://nvd.nist.gov/vuln/detail/CVE-2021-28213) +- SDK: edk2-ovmf([CVE-2019-14584](https://nvd.nist.gov/vuln/detail/CVE-2019-14584), [CVE-2021-28210](https://nvd.nist.gov/vuln/detail/CVE-2021-28210), [CVE-2021-28211](https://nvd.nist.gov/vuln/detail/CVE-2021-28211), [CVE-2021-28213](https://nvd.nist.gov/vuln/detail/CVE-2021-28213)) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-09-libarchive-3.5.2.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-09-libarchive-3.5.2.md index ee0584f582..62a6d3ad81 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-09-libarchive-3.5.2.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-09-libarchive-3.5.2.md @@ -1,2 +1 @@ -- [libarchive-1565](https://github.com/libarchive/libarchive/issues/1565) -- [libarchive-1566](https://github.com/libarchive/libarchive/issues/1566) +- libarchive ([libarchive-1565](https://github.com/libarchive/libarchive/issues/1565), [libarchive-1566](https://github.com/libarchive/libarchive/issues/1566)) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-10-libxslt.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-10-libxslt.md index 8bc2b4ea03..cce0ca9157 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-10-libxslt.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-10-libxslt.md @@ -1 +1 @@ -- [CVE-2021-30560](https://nvd.nist.gov/vuln/detail/CVE-2021-30560) +- SDK: libxslt ([CVE-2021-30560](https://nvd.nist.gov/vuln/detail/CVE-2021-30560)) From 6315df39f1f1fb9138f29eb26e3c82eaa5c1f504 Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Thu, 13 Jan 2022 20:01:05 +0530 Subject: [PATCH 2/2] Fix edk2-ovmf to include missing space Co-authored-by: Dongsu Park --- .../portage-stable/changelog/security/2021-12-02-edk2-ovmf.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md index 65c58a219a..22559c9f67 100644 --- a/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md +++ b/sdk_container/src/third_party/portage-stable/changelog/security/2021-12-02-edk2-ovmf.md @@ -1 +1 @@ -- SDK: edk2-ovmf([CVE-2019-14584](https://nvd.nist.gov/vuln/detail/CVE-2019-14584), [CVE-2021-28210](https://nvd.nist.gov/vuln/detail/CVE-2021-28210), [CVE-2021-28211](https://nvd.nist.gov/vuln/detail/CVE-2021-28211), [CVE-2021-28213](https://nvd.nist.gov/vuln/detail/CVE-2021-28213)) +- SDK: edk2-ovmf ([CVE-2019-14584](https://nvd.nist.gov/vuln/detail/CVE-2019-14584), [CVE-2021-28210](https://nvd.nist.gov/vuln/detail/CVE-2021-28210), [CVE-2021-28211](https://nvd.nist.gov/vuln/detail/CVE-2021-28211), [CVE-2021-28213](https://nvd.nist.gov/vuln/detail/CVE-2021-28213))