[Git][security-tracker-team/security-tracker][master] Reserve DLA-3541-1 for w3m
Sylvain Beucler (@beuc)
beuc at debian.org
Thu Aug 24 12:42:39 BST 2023
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
24816548 by Sylvain Beucler at 2023-08-24T13:42:17+02:00
Reserve DLA-3541-1 for w3m
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -73652,7 +73652,6 @@ CVE-2022-38224
CVE-2022-38223 (There is an out-of-bounds write in checkType located in etc.c in w3m 0 ...)
- w3m 0.5.3+git20230121-1 (bug #1019599)
[bullseye] - w3m 0.5.3+git20210102-6+deb11u1
- [buster] - w3m <no-dsa> (Minor issue)
NOTE: https://github.com/tats/w3m/issues/242
NOTE: Initial fix: https://github.com/tats/w3m/commit/419ca82d57c72242817b55e2eaa4cdbf6916e7fa
NOTE: Follow-up fix: https://github.com/tats/w3m/commit/25fb402cea405b263466c627f32513d186a38ade
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[24 Aug 2023] DLA-3541-1 w3m - security update
+ {CVE-2022-38223}
+ [buster] - w3m 0.5.3-37+deb10u1
[23 Aug 2023] DLA-3540-1 mediawiki - security update
{CVE-2023-29141}
[buster] - mediawiki 1:1.31.16-1+deb10u6
=====================================
data/dla-needed.txt
=====================================
@@ -221,9 +221,3 @@ suricata (Adrian Bunk)
NOTE: 20230714: Still reviewing+testing CVEs. (bunk)
NOTE: 20230731: Still reviewing+testing CVEs. (bunk)
--
-w3m (Sylvain Beucler)
- NOTE: 20230812: Added by Front-Desk (Beuc)
- NOTE: 20230812: Experimental issue-based workflow: please self-assign and follow https://salsa.debian.org/lts-team/lts-updates-tasks/-/issues/42
- NOTE: 20230812: Follow fixes from bullseye 11.7 (1 CVE) (Beuc/front-desk)
- NOTE: 20230819: No ASAN errors with the PoCs, but the backported fixes do bring some (!), more testing needed. (Beuc)
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24816548dd2b4d229941c70685e219675f1a742c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24816548dd2b4d229941c70685e219675f1a742c
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230824/cdeb0a61/attachment.htm>
More information about the debian-security-tracker-commits
mailing list