[Git][security-tracker-team/security-tracker][master] Track fixed version for mruby issues via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Dec 15 06:18:09 GMT 2022
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2c454404 by Salvatore Bonaccorso at 2022-12-15T07:17:23+01:00
Track fixed version for mruby issues via unstable
Note, those should be peer reviewed for correctness.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -52076,7 +52076,7 @@ CVE-2022-29567 (The default configuration of a TreeGrid component uses Object::t
CVE-2022-29566 (The Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation bec ...)
NOT-FOR-US: Bulletproofs
CVE-2022-1427 (Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <not-affected> (Vulnerable code not present)
@@ -55564,7 +55564,7 @@ CVE-2022-1203 (The Content Mask WordPress plugin before 1.8.4.1 does not have au
CVE-2022-1202 (The WP-CRM WordPress plugin through 1.2.1 does not validate and saniti ...)
NOT-FOR-US: WordPress plugin
CVE-2022-1201 (NULL Pointer Dereference in mrb_vm_exec with super in GitHub repositor ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <not-affected> (Vulnerable code not present)
@@ -57183,7 +57183,7 @@ CVE-2022-27494 (Aethon TUG Home Base Server versions prior to version 24 are aff
CVE-2022-26423 (Aethon TUG Home Base Server versions prior to version 24 are affected ...)
NOT-FOR-US: Aethon TUG Home Base Server
CVE-2022-1071 (User after free in mrb_vm_exec in GitHub repository mruby/mruby prior ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
NOTE: https://huntr.dev/bounties/6597ece9-07af-415b-809b-919ce0a17cf3
@@ -60318,7 +60318,7 @@ CVE-2022-0891 (A heap buffer overflow in ExtractImageSection function in tiffcro
NOTE: https://gitlab.com/libtiff/libtiff/-/issues/380
NOTE: https://gitlab.com/libtiff/libtiff/-/issues/382
CVE-2022-0890 (NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2 ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <no-dsa> (Minor issue)
@@ -67490,7 +67490,7 @@ CVE-2022-21194 (The following Yokogawa Electric products do not change the passw
CVE-2022-21177 (There is a path traversal vulnerability in CAMS for HIS Log Server con ...)
NOT-FOR-US: Yokogawa Electric products
CVE-2022-0481 (NULL Pointer Dereference in Homebrew mruby prior to 3.2. ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <not-affected> (Vulnerable code not present)
@@ -71617,7 +71617,7 @@ CVE-2022-0242 (Unrestricted Upload of File with Dangerous Type in GitHub reposit
CVE-2022-0241
RESERVED
CVE-2022-0240 (mruby is vulnerable to NULL Pointer Dereference ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <no-dsa> (Minor issue)
@@ -75361,7 +75361,7 @@ CVE-2021-46021 (An Use-After-Free vulnerability in rec_record_destroy() at rec-r
NOTE: https://lists.gnu.org/archive/html/bug-recutils/2021-12/msg00008.html
NOTE: Negligible security impact
CVE-2021-46020 (An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can ...)
- - mruby <unfixed> (bug #1014968)
+ - mruby 3.1.0-1 (bug #1014968)
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
[stretch] - mruby <postponed> (revisit when/if fix is complete)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c454404495ddec692075571d4e5c9d6c891e66f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c454404495ddec692075571d4e5c9d6c891e66f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221215/2d9ff0e5/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list