[Git][security-tracker-team/security-tracker][master] Reserve DLA-3531-1 for open-vm-tools
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Wed Aug 16 18:13:58 BST 2023
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
deb3e9e9 by Utkarsh Gupta at 2023-08-16T22:43:36+05:30
Reserve DLA-3531-1 for open-vm-tools
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -191,7 +191,7 @@ CVE-2023-38898 (An issue in Python cpython v.3.7 allows an attacker to obtain se
NOTE: https://github.com/python/cpython/commit/9e6f8d46150c1a0af09d68ce63c603cf321994aa
NOTE: https://github.com/python/cpython/issues/105987
CVE-2023-38896 (An issue in Harrison Chase langchain v.0.0.194 and before allows a rem ...)
- NOT-FOR-US: Harrison Chase langchain
+ NOT-FOR-US: Harrison Chase langchain
CVE-2023-38889 (An issue in Alluxio v.2.9.3 and before allows an attacker to execute a ...)
NOT-FOR-US: Alluxio
CVE-2023-38866 (COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected ...)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[16 Aug 2023] DLA-3531-1 open-vm-tools - security update
+ {CVE-2023-20867}
+ [buster] - open-vm-tools 2:10.3.10-1+deb10u4
[15 Aug 2023] DLA-3530-1 openssl - security update
{CVE-2023-3446 CVE-2023-3817}
[buster] - openssl 1.1.1n-0+deb10u6
=====================================
data/dla-needed.txt
=====================================
@@ -121,9 +121,6 @@ nvidia-cuda-toolkit
NOTE: 20230610: Details: https://lists.debian.org/debian-lts/2023/06/msg00032.html
NOTE: 20230610: my recommendation would be to put the package on the "not-supported" list. (tobi)
--
-open-vm-tools (Utkarsh)
- NOTE: 20230731: Added by Front-Desk (apo)
---
opendmarc (Chris Lamb)
NOTE: 20230811: Added by Front-Desk (Beuc)
NOTE: 20230810: Experimental issue-based workflow: please self-assign and follow https://salsa.debian.org/lts-team/lts-updates-tasks/-/issues/34
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/deb3e9e990d6bd05c59e35591dad6b69f1bb5919
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/deb3e9e990d6bd05c59e35591dad6b69f1bb5919
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230816/a8abf48b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list