[Git][security-tracker-team/security-tracker][master] NFU / add tinydir references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Dec 22 08:50:18 GMT 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6ba6b1ba by Moritz Muehlenhoff at 2023-12-22T09:49:53+01:00
NFU / add tinydir references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -215,7 +215,7 @@ CVE-2023-50822 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2023-50732 (XWiki Platform is a generic wiki platform offering runtime services fo ...)
NOT-FOR-US: XWiki
CVE-2023-50724 (Resque (pronounced like "rescue") is a Redis-backed library for creati ...)
- TODO: check
+ NOT-FOR-US: Resque
CVE-2023-50481 (An issue was discovered in blinksocks version 3.3.8, allows remote att ...)
NOT-FOR-US: blinksocks
CVE-2023-50477 (An issue was discovered in nos client version 0.6.6, allows remote att ...)
@@ -4102,6 +4102,8 @@ CVE-2023-49287 (TinyDir is a lightweight C directory and file reader. Buffer ove
TODO: potentally affects falcosecurity-libs, gemmi, lwip
NOTE: https://www.openwall.com/lists/oss-security/2023/12/04/1
NOTE: https://github.com/cxong/tinydir/security/advisories/GHSA-jf5r-wgf4-qhxf
+ NOTE: https://github.com/cxong/tinydir/commit/8124807260735a837226fa151493536591f6715d
+ NOTE: https://github.com/hnsecurity/vulns/blob/main/HNS-2023-04-tinydir.txt
CVE-2023-49108 (Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0. ...)
NOT-FOR-US: RakRak Document Plus
CVE-2023-49093 (HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerab ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ba6b1ba8336464c1551490aad6f7332f4ce4382
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ba6b1ba8336464c1551490aad6f7332f4ce4382
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231222/60dd9d51/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list