[Git][security-tracker-team/security-tracker][master] Add fixed version for curl issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Oct 28 06:08:04 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b20f0937 by Salvatore Bonaccorso at 2022-10-28T07:06:44+02:00
Add fixed version for curl issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4026,7 +4026,7 @@ CVE-2022-42917
 	RESERVED
 CVE-2022-42916 [HSTS bypass via IDN]
 	RESERVED
-	- curl <unfixed>
+	- curl 7.86.0-1
 	[buster] - curl <not-affected> (Vulnerable code not present)
 	NOTE: https://curl.se/docs/CVE-2022-42916.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/7385610d0c74c6a254fea5e4cd6e1d559d848c8c (curl-7_74_0)
@@ -4034,7 +4034,7 @@ CVE-2022-42916 [HSTS bypass via IDN]
 	NOTE: Fixed by: https://github.com/curl/curl/commit/53bcf55b4538067e6dc36242168866becb987bb7 (curl-7_86_0)
 CVE-2022-42915 [HTTP proxy double-free]
 	RESERVED
-	- curl <unfixed>
+	- curl 7.86.0-1
 	[bullseye] - curl <not-affected> (Vulnerable code not present)
 	[buster] - curl <not-affected> (Vulnerable code not present)
 	NOTE: https://curl.se/docs/CVE-2022-42915.html
@@ -23613,7 +23613,7 @@ CVE-2022-35261 (A denial of service vulnerability exists in the web_server hashF
 	TODO: check
 CVE-2022-35260 [.netrc parser out-of-bounds access]
 	RESERVED
-	- curl <unfixed>
+	- curl 7.86.0-1
 	[bullseye] - curl <not-affected> (Vulnerable code not present)
 	[buster] - curl <not-affected> (Vulnerable code not present)
 	NOTE: https://curl.se/docs/CVE-2022-35260.html
@@ -31751,7 +31751,7 @@ CVE-2022-32222 (A cryptographic vulnerability exists on Node.js on linux in vers
 	NOTE: https://github.com/nodejs/node/commit/a5fc2deb43f85dc2195a1fe1683b9c2e7443b001
 CVE-2022-32221 [POST following PUT confusion]
 	RESERVED
-	- curl <unfixed>
+	- curl 7.86.0-1
 	NOTE: https://curl.se/docs/CVE-2022-32221.html
 	NOTE: https://github.com/curl/curl/issues/9507
 	NOTE: Fixed by: https://github.com/curl/curl/commit/a64e3e59938abd7d667e4470a18072a24d7e9de9 (curl-7_86_0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b20f0937215a9045292e2de200e6cc640d1f3a51

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b20f0937215a9045292e2de200e6cc640d1f3a51
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221028/7b2188c7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list