[Git][security-tracker-team/security-tracker][master] Add three mruby issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Feb 22 06:18:56 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1409af1d by Salvatore Bonaccorso at 2022-02-22T07:18:27+01:00
Add three mruby issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -975,11 +975,17 @@ CVE-2022-0634
 CVE-2022-0633 (The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-0632 (NULL Pointer Dereference in Homebrew mruby prior to 3.2. ...)
-	TODO: check
+	- mruby <not-affected> (Vulnerable code introduced later)
+	NOTE: https://huntr.dev/bounties/3e5bb8f6-30fd-4553-86dd-761e9459ce1b
+	NOTE: https://github.com/mruby/mruby/commit/44f591aa8f7091e6ca6cb418e428ae6d4ceaf77d
 CVE-2022-0631 (Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. ...)
-	TODO: check
+	- mruby <not-affected> (Vulnerable code introduced later)
+	NOTE: https://huntr.dev/bounties/9bdc49ca-6697-4adc-a785-081e1961bf40
+	NOTE: https://github.com/mruby/mruby/commit/47068ae07a5fa3aa9a1879cdfe98a9ce0f339299
 CVE-2022-0630 (Out-of-bounds Read in Homebrew mruby prior to 3.2. ...)
-	TODO: check
+	- mruby <not-affected> (Vulnerable code introduced later)
+	NOTE: https://huntr.dev/bounties/f7cdd680-1a7f-4992-b4b8-44b5e4ba3e32
+	NOTE: https://github.com/mruby/mruby/commit/ff3a5ebed6ffbe3e70481531cfb969b497aa73ad
 CVE-2022-0629 (Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. ...)
 	- vim <unfixed>
 	[bullseye] - vim <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1409af1d29193ab00587b4a26bc8f3c8dfea7476

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1409af1d29193ab00587b4a26bc8f3c8dfea7476
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220222/e8c5fcb2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list