[Git][security-tracker-team/security-tracker][master] 3 commits: Triage CVE-2021-3622 in hivex for stretch LTS.

Chris Lamb (@lamby) lamby at debian.org
Fri Aug 6 10:04:09 BST 2021



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a6eaadfb by Chris Lamb at 2021-08-06T10:02:25+01:00
Triage CVE-2021-3622 in hivex for stretch LTS.

- - - - -
9f9018ac by Chris Lamb at 2021-08-06T10:02:48+01:00
Triage CVE-2021-38115 in libgd2 for stretch LTS.

- - - - -
e1f56a4d by Chris Lamb at 2021-08-06T10:03:16+01:00
Triage CVE-2021-37832 & CVE-2021-37833 in hoteldruid for stretch LTS.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -72,6 +72,7 @@ CVE-2021-38115 (read_header_tga in gd_tga.c in the GD Graphics Library (aka LibG
 	- libgd2 <unfixed> (bug #991912)
 	[bullseye] - libgd2 <no-dsa> (Minor issue)
 	[buster] - libgd2 <no-dsa> (Minor issue)
+	[stretch] - libgd2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/libgd/libgd/issues/697
 	NOTE: https://github.com/libgd/libgd/commit/8b111b2b4a4842179be66db68d84dda91a246032
 CVE-2021-38114 (libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of ...)
@@ -681,11 +682,13 @@ CVE-2021-37833 (A reflected cross-site scripting (XSS) vulnerability exists in m
 	- hoteldruid <unfixed> (bug #991910)
 	[bullseye] - hoteldruid <no-dsa> (Minor issue)
 	[buster] - hoteldruid <no-dsa> (Minor issue)
+	[stretch] - hoteldruid <no-dsa> (Minor issue)
 	NOTE: https://github.com/dievus/CVE-2021-37833
 CVE-2021-37832 (A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid w ...)
 	- hoteldruid <unfixed> (bug #991910)
 	[bullseye] - hoteldruid <no-dsa> (Minor issue)
 	[buster] - hoteldruid <no-dsa> (Minor issue)
+	[stretch] - hoteldruid <no-dsa> (Minor issue)
 	NOTE: https://github.com/dievus/CVE-2021-37832
 CVE-2021-37831
 	RESERVED
@@ -5894,6 +5897,7 @@ CVE-2021-3622
 	- hivex <unfixed> (bug #991860)
 	[bullseye] - hivex <no-dsa> (Minor issue)
 	[buster] - hivex <no-dsa> (Minor issue)
+	[stretch] - hivex <no-dsa> (Minor issue)
 	NOTE: https://listman.redhat.com/archives/libguestfs/2021-August/msg00002.html
 	NOTE: https://github.com/libguestfs/hivex/commit/771728218dac2fbf6997a7e53225e75a4c6b7255
 CVE-2021-35501 (PandoraFMS <=7.54 allows Stored XSS by placing a payload in the nam ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/72a0612b3cec2f059aa81f4cc35b203775bdf7bf...e1f56a4d5649631e449c662474e9cb90b0c29622

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/72a0612b3cec2f059aa81f4cc35b203775bdf7bf...e1f56a4d5649631e449c662474e9cb90b0c29622
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210806/ff280427/attachment.htm>


More information about the debian-security-tracker-commits mailing list