[Git][security-tracker-team/security-tracker][master] Add CVE-2022-23645/swtpm

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Feb 21 08:29:13 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
51dfb1f2 by Salvatore Bonaccorso at 2022-02-21T09:28:49+01:00
Add CVE-2022-23645/swtpm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5955,7 +5955,9 @@ CVE-2022-23647 (Prism is a syntax highlighting library. Starting with version 1.
 CVE-2022-23646 (Next.js is a React framework. Starting with version 10.0.0 and prior t ...)
 	TODO: check
 CVE-2022-23645 (swtpm is a libtpms-based TPM emulator with socket, character device, a ...)
-	TODO: check
+	- swtpm <unfixed>
+	NOTE: https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqw
+	NOTE: https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19
 CVE-2022-23644 (BookWyrm is a decentralized social network for tracking reading habits ...)
 	NOT-FOR-US: BookWyrm
 CVE-2022-23643 (Sourcegraph is a code search and navigation engine. Sourcegraph versio ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51dfb1f2b63775667a41e2e87f06ae4f9d390d7e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/51dfb1f2b63775667a41e2e87f06ae4f9d390d7e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220221/87758338/attachment.htm>


More information about the debian-security-tracker-commits mailing list