[Git][security-tracker-team/security-tracker][master] Various expat issues fixed in unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jan 17 06:18:27 GMT 2022
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
013016ea by Salvatore Bonaccorso at 2022-01-17T07:17:55+01:00
Various expat issues fixed in unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1504,27 +1504,27 @@ CVE-2022-0156 (vim is vulnerable to Use After Free ...)
NOTE: https://huntr.dev/bounties/47dded34-3767-4725-8c7c-9dcb68c70b36
NOTE: https://github.com/vim/vim/commit/9f1a39a5d1cd7989ada2d1cb32f97d84360e050f (v8.2.4040)
CVE-2022-22827 (storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an in ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22826 (nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 ha ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22825 (lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integ ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22824 (defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22823 (build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22822 (addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an i ...)
- - expat <unfixed> (bug #1003474)
+ - expat 2.4.3-1 (bug #1003474)
NOTE: https://github.com/libexpat/libexpat/pull/539
NOTE: https://github.com/libexpat/libexpat/commit/9f93e8036e842329863bf20395b8fb8f73834d9e
CVE-2022-22821 (NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in wh ...)
@@ -2025,7 +2025,7 @@ CVE-2022-0130 (Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a
CVE-2021-46145 (The keyfob subsystem in Honda Civic 2012 vehicles allows a replay atta ...)
NOT-FOR-US: keyfob subsystem in Honda Civic 2012 vehicles
CVE-2021-46143 (In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an int ...)
- - expat <unfixed>
+ - expat 2.4.3-1
NOTE: https://github.com/libexpat/libexpat/issues/532
NOTE: https://github.com/libexpat/libexpat/pull/538
NOTE: https://github.com/libexpat/libexpat/commit/85ae9a2d7d0e9358f356b33977b842df8ebaec2b
@@ -3448,7 +3448,7 @@ CVE-2022-0080 (mruby is vulnerable to Heap-based Buffer Overflow ...)
NOTE: https://huntr.dev/bounties/59a70392-4864-4ce3-8e35-6ac2111d1e2e/
NOTE: https://github.com/mruby/mruby/commit/28ccc664e5dcd3f9d55173e9afde77c4705a9ab6
CVE-2021-45960 (In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) pla ...)
- - expat <unfixed> (bug #1002994)
+ - expat 2.4.3-1 (bug #1002994)
[bullseye] - expat <no-dsa> (Minor issue; can be fixed via point release)
[buster] - expat <no-dsa> (Minor issue; can be fixed via point release)
[stretch] - expat <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/013016ea180846b28e2158bdd69fe8b247161dc4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/013016ea180846b28e2158bdd69fe8b247161dc4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220117/a94decd0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list