[Git][security-tracker-team/security-tracker][master] CVE-2022-1325/cimg unfixed #1018941
Neil Williams (@codehelp)
codehelp at debian.org
Fri Sep 2 09:51:03 BST 2022
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f946b3bc by Neil Williams at 2022-09-02T09:50:41+01:00
CVE-2022-1325/cimg unfixed #1018941
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27729,7 +27729,13 @@ CVE-2022-1327 (The Image Gallery WordPress plugin before 1.1.6 does not sanitize
CVE-2022-1326 (The Form - Contact Form WordPress plugin through 1.2.0 does not saniti ...)
NOT-FOR-US: WordPress plugin
CVE-2022-1325 (A flaw was found in Clmg, where with the help of a maliciously crafted ...)
- TODO: check
+ - cimg <unfixed> (bug #1018941)
+ NOTE: https://access.redhat.com/security/cve/CVE-2022-1325
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2074549
+ NOTE: https://github.com/GreycLab/CImg/commit/619cb58dd90b4e03ac68286c70ed98acbefd1c90 (v3.1.0)
+ NOTE: https://github.com/GreycLab/CImg/issues/343
+ NOTE: https://github.com/GreycLab/CImg/pull/348
+ NOTE: https://huntr.dev/bounties/a5e4fc45-8f14-4dd1-811b-740fc50c95d2/
CVE-2022-1324 (The Event Timeline WordPress plugin through 1.1.5 does not sanitize an ...)
NOT-FOR-US: WordPress plugin
CVE-2022-1323 (The Discy WordPress theme before 5.0 lacks authorization checks then p ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f946b3bc56747c2ec0390e1c8af268b677e5caab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f946b3bc56747c2ec0390e1c8af268b677e5caab
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220902/5f05ab4c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list