[Git][security-tracker-team/security-tracker][master] 5 commits: Triage CVE-2023-48795 in filezilla for buster LTS.
Chris Lamb (@lamby)
lamby at debian.org
Sun Dec 31 12:28:55 GMT 2023
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d2baea94 by Chris Lamb at 2023-12-31T12:16:40+00:00
Triage CVE-2023-48795 in filezilla for buster LTS.
- - - - -
36f36cc3 by Chris Lamb at 2023-12-31T12:17:05+00:00
Triage CVE-2023-51714 in qtbase-opensource-src for buster LTS.
- - - - -
7d3d77b8 by Chris Lamb at 2023-12-31T12:18:19+00:00
data/dla-needed.txt: Triage tiff for buster LTS (CVE-2023-3576)
- - - - -
7de46bd4 by Chris Lamb at 2023-12-31T12:22:16+00:00
Add upstream commit references for CVE-2023-49093 in htmlunit & jenkins-htmlunit-core-js
- - - - -
46294fe9 by Chris Lamb at 2023-12-31T12:27:45+00:00
data/dla-needed.txt: Triage jenkins-htmlunit-core-js for buster LTS (CVE-2023-49093)
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -803,6 +803,7 @@ CVE-2023-51714 (An issue was discovered in the HTTP2 implementation in Qt before
- qtbase-opensource-src <unfixed>
[bookworm] - qtbase-opensource-src <no-dsa> (Minor issue)
[bullseye] - qtbase-opensource-src <no-dsa> (Minor issue)
+ [buster] - qtbase-opensource-src <no-dsa> (Minor issue)
- qtbase-opensource-src-gles <unfixed>
[bookworm] - qtbase-opensource-src-gles <no-dsa> (Minor issue)
[bullseye] - qtbase-opensource-src-gles <no-dsa> (Minor issue)
@@ -2147,6 +2148,7 @@ CVE-2023-48795 (The SSH transport protocol with certain OpenSSH extensions, foun
- filezilla 3.66.4-1
[bookworm] - filezilla <no-dsa> (Minor issue)
[bullseye] - filezilla <no-dsa> (Minor issue)
+ [buster] - filezilla <no-dsa> (Minor issue)
- golang-go.crypto <unfixed> (bug #1059003)
- jsch <not-affected> (ChaCha20-Poly1305 support introduced in 0.1.61; *-EtM support introduced in 0.1.58)
- libssh 0.10.6-1 (bug #1059004)
@@ -5284,6 +5286,8 @@ CVE-2023-49093 (HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vu
- jenkins-htmlunit-core-js <removed>
- htmlunit <removed>
NOTE: https://github.com/HtmlUnit/htmlunit/security/advisories/GHSA-37vq-hr2f-g7h7
+ NOTE: https://github.com/HtmlUnit/htmlunit/commit/e015082aa909fd9e1c2b5f9b26553ddc0ddbbcab
+ NOTE: https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b
CVE-2023-47701 (IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5 ...)
NOT-FOR-US: IBM
CVE-2023-46167 (IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 ...)
=====================================
data/dla-needed.txt
=====================================
@@ -98,6 +98,14 @@ imagemagick
NOTE: 20230622: Requested by maintainer (rouca) to tidy remaining open CVEs (Beuc/front-desk)
NOTE: 20231014: Some work under git branch debian/buster but unease
--
+jenkins-htmlunit-core-js
+ NOTE: 20231231: Added by Front-Desk (lamby)
+ NOTE: 20231231: Needs checking that this is definitely vulnerable: a quick glance
+ NOTE: 20231231: … suggests that the embedded copy of htmlunit is very old and may
+ NOTE: 20231231: … not even support XLST processing. However, it does use the
+ NOTE: 20231231: … TransformerFactory without setting the ~secure flag, so it may
+ NOTE: 20231231: … indeed be vulnerable. (lamby)
+--
keystone
NOTE: 20231102: Added by Front-Desk (lamby)
NOTE: 20231102: Sync (eg. CVE-2021-38155) with stable etc. (lamby)
@@ -250,6 +258,10 @@ suricata (Adrian Bunk)
NOTE: 20231016: Still reviewing+testing CVEs. (bunk)
NOTE: 20231120: DLA coming soon. (bunk)
--
+tiff
+ NOTE: 20231231: Added by Front-Desk (lamby)
+ NOTE: 20231231: CVE-2023-3576 already fixed in bullseye via DSA or point release(s). (lamby)
+--
tinymce
NOTE: 20231123: Added by Front-Desk (ola)
NOTE: 20231216: Someone with more XSS experience needed to assess the
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ca8ce7390e8ffa33ef93fccee9734db8047563ec...46294fe95d55a442c022843bb1b143758a1d7bca
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ca8ce7390e8ffa33ef93fccee9734db8047563ec...46294fe95d55a442c022843bb1b143758a1d7bca
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231231/40824f99/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list