[Git][security-tracker-team/security-tracker][master] After source code analysis it is clear that CVE-2023-298997 through...

Ola Lundqvist (@opal) opal at debian.org
Sun Apr 23 21:22:40 BST 2023

Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker

d13ba436 by Ola Lundqvist at 2023-04-23T22:22:24+02:00
After source code analysis it is clear that CVE-2023-298997 through CVE-2023-29000 applies to pre 3.0 version even though the text tells something else. In any case the severity is similar to many other issues in nextcloud-desktop and they were marked as no-dsa with motivation minor issue. Doing the same for these CVEs as well.

- - - - -

1 changed file:

- data/CVE/list


@@ -5631,21 +5631,29 @@ CVE-2023-29001
 CVE-2023-29000 (The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...)
 	- nextcloud-desktop 3.7.0-1
+	[buster] - nextcloud-desktop <no-dsa> (Minor issue)
 	NOTE: https://github.com/nextcloud/desktop/pull/4949
 	NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h82x-98q3-7534
 	NOTE: https://hackerone.com/reports/1679267
+	NOTE: Source analysis show that the vulnerability exist prior to 3.0 version meaning buster is vulnerable too.
 CVE-2023-28999 (Nextcloud is an open-source productivity platform. In Nextcloud Deskto ...)
 	- nextcloud-desktop <unfixed> (bug #1034184)
+	[buster] - nextcloud-desktop <no-dsa> (Minor issue)
 	NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8875-wxww-3rr8
 	NOTE: https://github.com/nextcloud/desktop/pull/5560
+	NOTE: Indication that the problem appear also in 3.0 version meaning buster is vulnerable too.
 CVE-2023-28998 (The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...)
 	- nextcloud-desktop 3.7.0-1
+	[buster] - nextcloud-desktop <no-dsa> (Minor issue)
 	NOTE: https://github.com/nextcloud/desktop/pull/5323
 	NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jh3g-wpwv-cqgr
+	NOTE: The patch should apply also to pre 3.0 version indicating that buster is vulnerable too.
 CVE-2023-28997 (The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...)
 	- nextcloud-desktop 3.7.0-1
+	[buster] - nextcloud-desktop <no-dsa> (Minor issue)
 	NOTE: https://github.com/nextcloud/desktop/pull/5324
 	NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4p33-rw27-j5fc
+	NOTE: The patch should apply also to pre 3.0 version indicating that buster is vulnerable too.

View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d13ba436836b130648f183416a6b1d4931f31c2b

View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d13ba436836b130648f183416a6b1d4931f31c2b
You're receiving this email because of your account on salsa.debian.org.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230423/cfc84a99/attachment.htm>

More information about the debian-security-tracker-commits mailing list