[Git][security-tracker-team/security-tracker][master] Track issues from WSA-2023-0003

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Apr 22 15:55:51 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
18563380 by Salvatore Bonaccorso at 2023-04-22T16:55:03+02:00
Track issues from WSA-2023-0003

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8356,7 +8356,9 @@ CVE-2023-28207
 CVE-2023-28206 (An out-of-bounds write issue was addressed with improved input validat ...)
 	NOT-FOR-US: Apple
 CVE-2023-28205 (A use after free issue was addressed with improved memory management.  ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.40.1-1
+	- wpewebkit <unfixed>
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2023-28204
 	RESERVED
 CVE-2023-28203
@@ -9221,6 +9223,9 @@ CVE-2023-27955
 	RESERVED
 CVE-2023-27954
 	RESERVED
+	- webkit2gtk 2.40.1-1
+	- wpewebkit <unfixed>
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2023-27953
 	RESERVED
 CVE-2023-27952
@@ -9265,6 +9270,9 @@ CVE-2023-27933
 	RESERVED
 CVE-2023-27932
 	RESERVED
+	- webkit2gtk 2.40.1-1
+	- wpewebkit <unfixed>
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2023-27931
 	RESERVED
 CVE-2023-27930
@@ -16657,6 +16665,7 @@ CVE-2023-25358 (A use-after-free vulnerability in WebCore::RenderLayer::addChild
 	- webkit2gtk 2.38.0-1
 	- wpewebkit 2.38.0-1
 	NOTE: https://bugs.webkit.org/show_bug.cgi?id=242683
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2023-25357
 	RESERVED
 CVE-2023-25356 (CoreDial sipXcom up to and including 21.04 is vulnerable to Improper N ...)
@@ -72755,6 +72764,9 @@ CVE-2022-32886 (A buffer overflow issue was addressed with improved memory handl
 	NOTE: https://webkitgtk.org/security/WSA-2022-0009.html
 CVE-2022-32885
 	RESERVED
+	- webkit2gtk 2.40.1-1
+	- wpewebkit <unfixed>
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2022-32884
 	RESERVED
 CVE-2022-32883 (A logic issue was addressed with improved restrictions. This issue is  ...)
@@ -105057,6 +105069,9 @@ CVE-2022-0108 (Inappropriate implementation in Navigation in Google Chrome prior
 	- chromium 97.0.4692.71-0.1
 	[buster] - chromium <end-of-life> (see DSA 5046)
 	[stretch] - chromium <end-of-life> (see DSA 4562)
+	- webkit2gtk 2.40.1-1
+	- wpewebkit <unfixed>
+	NOTE: https://webkitgtk.org/security/WSA-2023-0003.html
 CVE-2022-0107 (Use after free in File Manager API in Google Chrome on Chrome OS prior ...)
 	{DSA-5046-1}
 	- chromium 97.0.4692.71-0.1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/185633808b345e2b277d8356b13afe6690950e46

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/185633808b345e2b277d8356b13afe6690950e46
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230422/444a91eb/attachment.htm>


More information about the debian-security-tracker-commits mailing list