[Git][security-tracker-team/security-tracker][master] Track fixed version for older CVE-2013-4363/CVE-2013-4287
Salvatore Bonaccorso
carnil at debian.org
Sun Nov 29 20:08:38 GMT 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3316523f by Salvatore Bonaccorso at 2020-11-29T21:08:05+01:00
Track fixed version for older CVE-2013-4363/CVE-2013-4287
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -325837,7 +325837,7 @@ CVE-2013-4365 (Heap-based buffer overflow in the fcgid_header_bucket_read functi
CVE-2013-4364 ((1) oo-analytics-export and (2) oo-analytics-import in the openshift-o ...)
NOT-FOR-US: OpenShift
CVE-2013-4363 (Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION ...)
- - rubygems <unfixed> (unimportant; bug #722361)
+ - rubygems 3.2.0~rc.1-1 (unimportant; bug #722361)
- libgems-ruby <removed> (unimportant; bug #722361)
NOTE: Non-issue, you trust the site providing the gem with installing arbitrary code, allowing
NOTE: it a potential elevated CPU consumption doesn't add any extra harm
@@ -326131,7 +326131,7 @@ CVE-2013-4288 (Race condition in PolicyKit (aka polkit) allows local users to by
[squeeze] - policykit-1 <no-dsa> (The update only deprecates an API and introduces a new option for pkcheck, no src package uses this API)
[wheezy] - policykit-1 <no-dsa> (The update only deprecates an API and introduces a new option for pkcheck, no src package uses this API)
CVE-2013-4287 (Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN ...)
- - rubygems <unfixed> (unimportant; bug #722361)
+ - rubygems 3.2.0~rc.1-1 (unimportant; bug #722361)
- libgems-ruby <removed> (unimportant; bug #722361)
NOTE: Non-issue, you trust the site providing the gem with installing arbitrary code, allowing
NOTE: it a potential elevated CPU consumption doesn't add any extra harm
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3316523f7c8dc0d1b622b5d0dfcf2ccf41f1f52b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3316523f7c8dc0d1b622b5d0dfcf2ccf41f1f52b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201129/436316f3/attachment.html>
More information about the debian-security-tracker-commits
mailing list