[Git][security-tracker-team/security-tracker][master] Update information for CVE-2023-34432
    Salvatore Bonaccorso (@carnil) 
    carnil at debian.org
       
    Sun Aug 13 12:00:34 BST 2023
    
    
  
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3d8072c4 by Salvatore Bonaccorso at 2023-08-13T13:00:00+02:00
Update information for CVE-2023-34432
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4904,10 +4904,11 @@ CVE-2023-35697 (Improper Restriction of Excessive Authentication Attempts in the
 CVE-2023-35696 (Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthen ...)
 	NOT-FOR-US: SICK
 CVE-2023-34432 (A heap buffer overflow vulnerability was found in sox, in the lsx_read ...)
-	- sox <unfixed> (bug #1041110)
+	- sox 14.4.2+git20190427-3.2 (bug #1041110)
+	[bullseye] - sox 14.4.2+git20190427-2+deb11u1
+	[buster] - sox 14.4.2+git20190427-1+deb10u1
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2212291
 	NOTE: https://sourceforge.net/p/sox/bugs/367/
-	TODO: needs further investigation, claimed to be fixed with patch applied for CVE-2021-23159 and CVE-2021-23172
 CVE-2023-34347 (Delta Electronics InfraSuite Device Master versions prior to 1.0.7 con ...)
 	NOT-FOR-US: Delta Electronics InfraSuite Device Master
 CVE-2023-34318 (A heap buffer overflow vulnerability was found in sox, in the startrea ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d8072c45ab953fb6283a1a1ec3e74621066f3f2
-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d8072c45ab953fb6283a1a1ec3e74621066f3f2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230813/e0438480/attachment.htm>
    
    
More information about the debian-security-tracker-commits
mailing list