[Git][security-tracker-team/security-tracker][master] bullseye triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 22 16:58:08 BST 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5e95043f by Moritz Muehlenhoff at 2022-08-22T17:57:45+02:00
bullseye triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -682,15 +682,18 @@ CVE-2022-2870 (A vulnerability was found in laravel 5.1 and classified as proble
 	NOTE: Additional misreport for laravel, likely to be rejected
 CVE-2022-2869 (libtiff's tiffcrop tool has a uint32_t underflow which leads to out of ...)
 	- tiff 4.4.0~rc1-1
+	[bullseye] - tiff <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/libtiff/libtiff/-/issues/352
 	NOTE: https://gitlab.com/libtiff/libtiff/-/commit/07d79fcac2ead271b60e32aeb80f7b4f3be9ac8c (v4.4.0rc1)
 CVE-2022-2868 (libtiff's tiffcrop utility has a improper input validation flaw that c ...)
 	- tiff 4.4.0~rc1-1
+	[bullseye] - tiff <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/libtiff/libtiff/-/issues/335
 	NOTE: https://gitlab.com/libtiff/libtiff/-/merge_requests/294
 	NOTE: https://gitlab.com/libtiff/libtiff/-/commit/07d79fcac2ead271b60e32aeb80f7b4f3be9ac8c (v4.4.0rc1)
 CVE-2022-2867 (libtiff's tiffcrop utility has a uint32_t underflow that can lead to o ...)
 	- tiff 4.4.0~rc1-1
+	[bullseye] - tiff <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/libtiff/libtiff/-/issues/350
 	NOTE: https://gitlab.com/libtiff/libtiff/-/issues/351
 	NOTE: https://gitlab.com/libtiff/libtiff/-/commit/07d79fcac2ead271b60e32aeb80f7b4f3be9ac8c (v4.4.0rc1)
@@ -6508,6 +6511,7 @@ CVE-2022-2448
 CVE-2022-2447
 	RESERVED
 	- keystone <unfixed>
+	[bullseye] - keystone <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2105419
 CVE-2017-20143 (A vulnerability, which was classified as critical, has been found in I ...)
 	NOT-FOR-US: Itech Movie Portal Script
@@ -86691,6 +86695,7 @@ CVE-2021-32748 (Nextcloud Richdocuments in an open source self hosted online off
 CVE-2021-32747 (Icinga Web 2 is an open source monitoring web interface, framework, an ...)
 	[experimental] - icingaweb2 2.8.3-1~exp1
 	- icingaweb2 2.8.4-1 (bug #991116)
+	[bullseye] - icingaweb2 <no-dsa> (Minor issue)
 	[buster] - icingaweb2 <no-dsa> (Minor issue)
 	[stretch] - icingaweb2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-2xv9-886q-p7xx
@@ -86698,6 +86703,7 @@ CVE-2021-32747 (Icinga Web 2 is an open source monitoring web interface, framewo
 CVE-2021-32746 (Icinga Web 2 is an open source monitoring web interface, framework and ...)
 	[experimental] - icingaweb2 2.8.3-1~exp1
 	- icingaweb2 2.8.4-1 (bug #991116)
+	[bullseye] - icingaweb2 <no-dsa> (Minor issue)
 	[buster] - icingaweb2 <no-dsa> (Minor issue)
 	[stretch] - icingaweb2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-cmgc-h4cx-3v43
@@ -174030,6 +174036,7 @@ CVE-2020-10689 (A flaw was found in the Eclipse Che up to version 7.8.x, where i
 CVE-2020-10688 (A cross-site scripting (XSS) flaw was found in RESTEasy in versions be ...)
 	- resteasy <unfixed> (bug #970328)
 	- resteasy3.0 <unfixed> (bug #1015001)
+	[bullseye] - resteasy3.0 <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1814974
 	NOTE: https://github.com/quarkusio/quarkus/issues/7248
 	NOTE: https://issues.redhat.com/browse/RESTEASY-2519 (restricted)


=====================================
data/dsa-needed.txt
=====================================
@@ -18,6 +18,8 @@ freecad (aron)
 --
 gdk-pixbuf (carnil)
 --
+libxslt
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more recent v5.10.y versions



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e95043fea4796f62114c98630e3266d1ac6e3ab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5e95043fea4796f62114c98630e3266d1ac6e3ab
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220822/5ed1b33a/attachment.htm>


More information about the debian-security-tracker-commits mailing list