[Git][security-tracker-team/security-tracker][master] Triage CVE-2022-0240 & CVE-2022-0481 in mruby for stretch LTS.
Chris Lamb (@lamby)
lamby at debian.org
Wed Feb 9 17:03:06 GMT 2022
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a9f01e66 by Chris Lamb at 2022-02-09T09:02:46-08:00
Triage CVE-2022-0240 & CVE-2022-0481 in mruby for stretch LTS.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -937,6 +937,7 @@ CVE-2022-0481 (NULL Pointer Dereference in Homebrew mruby prior to 3.2. ...)
- mruby <unfixed>
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
+ [stretch] - mruby <no-dsa> (Minor issue)
NOTE: https://huntr.dev/bounties/54725c8c-87f4-41b6-878c-01d8e0ee7027
NOTE: https://github.com/mruby/mruby/commit/ae3c99767a27f5c6c584162e2adc6a5d0eb2c54e
TODO: check, possibly only introduced with dccd66f9efecd0a974b735c62836fe566015cf37 in 3.1.0-rc
@@ -4766,6 +4767,7 @@ CVE-2022-0240 (mruby is vulnerable to NULL Pointer Dereference ...)
- mruby <unfixed>
[bullseye] - mruby <no-dsa> (Minor issue)
[buster] - mruby <no-dsa> (Minor issue)
+ [stretch] - mruby <no-dsa> (Minor issue)
NOTE: https://huntr.dev/bounties/5857eced-aad9-417d-864e-0bdf17226cbb/
NOTE: https://github.com/mruby/mruby/commit/31fa3304049fc406a201a72293cce140f0557dca
CVE-2022-0239 (corenlp is vulnerable to Improper Restriction of XML External Entity R ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9f01e6606cade0f885c5ae8706100e3aa4e688f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9f01e6606cade0f885c5ae8706100e3aa4e688f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220209/425cfd7a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list