[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 23 12:14:14 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9784d119 by Moritz Muehlenhoff at 2023-08-23T13:13:39+02:00
bullseye/bookworm triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -73177,6 +73177,7 @@ CVE-2022-38350
 	RESERVED
 CVE-2022-38349 (An issue was discovered in Poppler 22.08.0. There is a reachable asser ...)
 	- poppler 22.12.0-2
+	[bullseye] - poppler <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1282
 	NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/4564a002bcb6094cc460bc0d5ddff9423fe6dd28 (poppler-22.09.0)
 CVE-2022-38348
@@ -76566,10 +76567,12 @@ CVE-2022-37053 (TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection vi
 	NOT-FOR-US: Trendnet
 CVE-2022-37052 (A reachable Object::getString assertion in Poppler 22.07.0 allows atta ...)
 	- poppler 22.08.0-2
+	[bullseye] - poppler <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1278
 	NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/8677500399fc2548fa816b619580c2c07915a98c (poppler-22.08.0)
 CVE-2022-37051 (An issue was discovered in Poppler 22.07.0. There is a reachable abort ...)
 	- poppler 22.08.0-2
+	[bullseye] - poppler <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1276
 	NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/4631115647c1e4f0482ffe0491c2f38d2231337b (poppler-22.08.0)
 CVE-2022-37050 (In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers t ...)
@@ -77653,6 +77656,8 @@ CVE-2022-36649
 	RESERVED
 CVE-2022-36648 (The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device ...)
 	- qemu <unfixed>
+	[bookworm] - qemu <postponed> (Minor issue, revisit when fixed upstream)
+	[bullseye] - qemu <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://lists.nongnu.org/archive/html/qemu-devel/2022-06/msg04469.html
 CVE-2022-36647 (PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overfl ...)
 	- davs2 <unfixed> (bug #1019358)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9784d1197bea2444c63c6db292da3f297cffbea8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9784d1197bea2444c63c6db292da3f297cffbea8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230823/bf0675b7/attachment.htm>


More information about the debian-security-tracker-commits mailing list