[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 25 17:40:27 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b91c790d by Moritz Muehlenhoff at 2023-08-25T18:39:58+02:00
bullseye/bookworm triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -159586,13 +159586,15 @@ CVE-2021-33391 (An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute a
 	NOTE: https://github.com/htacg/tidy-html5/issues/946
 	NOTE: https://github.com/htacg/tidy-html5/commit/efa61528aa500a1efbd2768121820742d3bb709b
 CVE-2021-33390 (dpic 2021.04.10 has a use-after-free in thedeletestringbox() function  ...)
-	- dpic 2021.11.01-1
+	- dpic 2021.11.01-1 (unimportant)
 	NOTE: https://gitlab.com/aplevich/dpic/-/issues/10
 	NOTE: Fixed by: https://gitlab.com/aplevich/dpic/-/commit/32c26bb3996511662029c961f5e83fb696c087d4
+	NOTE: Crash in CLI tool, no security impact
 CVE-2021-33389
 	RESERVED
 CVE-2021-33388 (dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in ...)
 	- dpic 2021.11.01-1
+	[bullseye] - dpic <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/aplevich/dpic/-/issues/8
 	NOTE: Fixed by: https://gitlab.com/aplevich/dpic/-/commit/32c26bb3996511662029c961f5e83fb696c087d4
 CVE-2021-33387 (Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker t ...)
@@ -162214,15 +162216,18 @@ CVE-2021-32424 (In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session
 CVE-2021-32423
 	RESERVED
 CVE-2021-32422 (dpic 2021.01.01 has a Global buffer overflow in theyylex() function in ...)
-	- dpic 2021.11.01-1
+	- dpic 2021.11.01-1 (unimportant)
 	NOTE: https://gitlab.com/aplevich/dpic/-/issues/6
 	NOTE: Fixed by: https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
+	NOTE: Crash in CLI tool, no security impact
 CVE-2021-32421 (dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() func ...)
-	- dpic 2021.11.01-1
+	- dpic 2021.11.01-1 (unimportant)
 	NOTE: https://gitlab.com/aplevich/dpic/-/issues/7
 	NOTE: Fixed by: https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
+	NOTE: Crash in CLI tool, no security impact
 CVE-2021-32420 (dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring fun ...)
 	- dpic 2021.11.01-1
+	[bullseye] - dpic <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/aplevich/dpic/-/issues/5
 	NOTE: Fixed by: https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
 CVE-2021-32419 (An issue in Schism Tracker v20200412 fixed in v.20200412 allows attack ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -52,6 +52,10 @@ php-horde-turba/oldstable
 --
 py7zr/oldstable
 --
+python3.11/stable
+--
+python3.9/oldstable
+--
 python-glance-store/oldstable
 --
 python-os-brick/oldstable



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b91c790df6aa973246eeb72b286a0bb13255687a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b91c790df6aa973246eeb72b286a0bb13255687a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230825/df5d29aa/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list