[Git][security-tracker-team/security-tracker][master] Track commits which relax fix for CVE-2022-25236

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Mar 5 09:32:20 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c0f6367b by Salvatore Bonaccorso at 2022-03-05T10:30:44+01:00
Track commits which relax fix for CVE-2022-25236

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3302,6 +3302,11 @@ CVE-2022-25236 (xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers
 	NOTE: https://github.com/libexpat/libexpat/commit/6881a4fc8596307ab9ff2e85e605afa2e413ab71
 	NOTE: https://github.com/libexpat/libexpat/commit/a2fe525e660badd64b6c557c2b1ec26ddc07f6e4
 	NOTE: https://github.com/libexpat/libexpat/commit/2de077423fb22750ebea599677d523b53cb93b1d
+	NOTE: Relaxed fix: https://github.com/libexpat/libexpat/pull/577
+	NOTE: https://github.com/libexpat/libexpat/commit/2ba6c76fca21397959145e18c5ef376201209020
+	NOTE: https://github.com/libexpat/libexpat/commit/e0f852db1e3b1e6d34922c68a653c3cc4b85361c
+	NOTE: https://github.com/libexpat/libexpat/commit/5dd52182972a35f2251a07784eda35d3d52d3e07
+	NOTE: https://github.com/libexpat/libexpat/commit/c57bea96b73eee1c6d5e288f0f57efbf5238e49a
 CVE-2022-25235 (xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain valid ...)
 	{DSA-5085-1}
 	- expat 2.4.5-1 (bug #1005894)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0f6367b19004bcba5b744ac668e49da096e859b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0f6367b19004bcba5b744ac668e49da096e859b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220305/a7b2b4df/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list