[Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2023-289{97,98,99}, VE-2023-29000
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Apr 24 05:59:38 BST 2023
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
71689fd1 by Salvatore Bonaccorso at 2023-04-24T06:59:16+02:00
Remove notes from CVE-2023-289{97,98,99}, VE-2023-29000
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5636,25 +5636,21 @@ CVE-2023-29000 (The Nextcloud Desktop Client is a tool to synchronize files from
NOTE: https://github.com/nextcloud/desktop/pull/4949
NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h82x-98q3-7534
NOTE: https://hackerone.com/reports/1679267
- NOTE: Source analysis show that the vulnerability exist prior to 3.0 version meaning buster is vulnerable too.
CVE-2023-28999 (Nextcloud is an open-source productivity platform. In Nextcloud Deskto ...)
- nextcloud-desktop <unfixed> (bug #1034184)
[buster] - nextcloud-desktop <no-dsa> (Minor issue)
NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8875-wxww-3rr8
NOTE: https://github.com/nextcloud/desktop/pull/5560
- NOTE: Indication that the problem appear also in 3.0 version meaning buster is vulnerable too.
CVE-2023-28998 (The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...)
- nextcloud-desktop 3.7.0-1
[buster] - nextcloud-desktop <no-dsa> (Minor issue)
NOTE: https://github.com/nextcloud/desktop/pull/5323
NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jh3g-wpwv-cqgr
- NOTE: The patch should apply also to pre 3.0 version indicating that buster is vulnerable too.
CVE-2023-28997 (The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...)
- nextcloud-desktop 3.7.0-1
[buster] - nextcloud-desktop <no-dsa> (Minor issue)
NOTE: https://github.com/nextcloud/desktop/pull/5324
NOTE: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4p33-rw27-j5fc
- NOTE: The patch should apply also to pre 3.0 version indicating that buster is vulnerable too.
CVE-2023-28996
RESERVED
CVE-2023-28995
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71689fd111aab9c183586761c36061d2965bb0d7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71689fd111aab9c183586761c36061d2965bb0d7
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230424/76acdfd6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list