[Git][security-tracker-team/security-tracker][master] Add CVE-2022-2301/chafa

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 4 21:24:18 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7f8c0514 by Salvatore Bonaccorso at 2022-07-04T22:23:49+02:00
Add CVE-2022-2301/chafa

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,7 +13,10 @@ CVE-2022-2303
 CVE-2022-2302
 	RESERVED
 CVE-2022-2301 (Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. ...)
-	TODO: check
+	- chafa 1.10.3-1
+	NOTE: https://huntr.dev/bounties/f6b9114b-671d-4948-b946-ffe5c9aeb816/
+	NOTE: https://github.com/hpjansson/chafa/commit/56fabfa18a6880b4cb66047fa6557920078048d9 (1.12.0)
+	NOTE: https://github.com/hpjansson/chafa/commit/a52325294cc018d4fa9a7f29668faea24362b94c (1.10.3)
 CVE-2022-2300 (Cross-site Scripting (XSS) - Stored in GitHub repository microweber/mi ...)
 	TODO: check
 CVE-2022-2299



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f8c0514e650674d70637e7c9a4da016a0eeac8f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f8c0514e650674d70637e7c9a4da016a0eeac8f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220704/41c5e97f/attachment.htm>


More information about the debian-security-tracker-commits mailing list