[Git][security-tracker-team/security-tracker][master] Track fixed version for two CVEs in php-dompdf

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Feb 4 08:39:05 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
650f425c by Salvatore Bonaccorso at 2023-02-04T09:36:50+01:00
Track fixed version for two CVEs in php-dompdf

One is actually unlear if the older version are affected:
CVE-2023-23924, which may affect only a specific version. Needs review.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3279,7 +3279,7 @@ CVE-2023-23926
 CVE-2023-23925 (Switcher Client is a JavaScript SDK to work with Switcher API which is ...)
 	TODO: check
 CVE-2023-23924 (Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 ...)
-	- php-dompdf <undetermined>
+	- php-dompdf 2.0.2+dfsg-1
 	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg
 	NOTE: https://github.com/dompdf/dompdf/commit/7558f07f693b2ac3266089f21051e6b78c6a0c85
 CVE-2023-23923
@@ -46860,7 +46860,7 @@ CVE-2022-2402 (The vulnerability in the driver dlpfde.sys enables a user logged
 CVE-2022-2401 (Unrestricted information disclosure of all users in Mattermost version ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2022-2400 (External Control of File Name or Path in GitHub repository dompdf/domp ...)
-	- php-dompdf <unfixed> (bug #1015874)
+	- php-dompdf 2.0.2+dfsg-1 (bug #1015874)
 	NOTE: https://huntr.dev/bounties/a6da5e5e-86be-499a-a3c3-2950f749202a
 	NOTE: https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6a
 CVE-2022-2399 (Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allow ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/650f425cee682a5f47ae4ebe6ccc25ffb66caf86

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/650f425cee682a5f47ae4ebe6ccc25ffb66caf86
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230204/5de62df7/attachment.htm>


More information about the debian-security-tracker-commits mailing list