[Git][security-tracker-team/security-tracker][master] bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Jan 11 13:48:02 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1310760a by Moritz Muehlenhoff at 2023-01-11T14:47:36+01:00
bookworm triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -110082,6 +110082,7 @@ CVE-2021-37232 (A stack overflow vulnerability occurs in Atomicparsley 20210124.
 	[buster] - atomicparsley <no-dsa> (Minor issue)
 	[stretch] - atomicparsley <no-dsa> (Minor issue)
 	- gtkpod <unfixed> (bug #993376)
+	[bookworm] - gtkpod <ignored> (Minor issue)
 	[bullseye] - gtkpod <ignored> (Minor issue)
 	[buster] - gtkpod <ignored> (Minor issue)
 	[stretch] - gtkpod <ignored> (Minor issue)
@@ -110093,6 +110094,7 @@ CVE-2021-37231 (A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.
 	[buster] - atomicparsley <no-dsa> (Minor issue)
 	[stretch] - atomicparsley <no-dsa> (Minor issue)
 	- gtkpod <unfixed> (bug #993375)
+	[bookworm] - gtkpod <ignored> (Minor issue)
 	[bullseye] - gtkpod <ignored> (Minor issue)
 	[buster] - gtkpod <ignored> (Minor issue)
 	[stretch] - gtkpod <ignored> (Minor issue)
@@ -173394,6 +173396,7 @@ CVE-2020-24828
 	RESERVED
 CVE-2020-24827 (A vulnerability in the dwarf::cursor::skip_form function of Libelfin v ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173401,6 +173404,7 @@ CVE-2020-24827 (A vulnerability in the dwarf::cursor::skip_form function of Libe
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#segv-in-function-dwarfcursorskip_form-at-dwarfcursorcc181
 CVE-2020-24826 (A vulnerability in the elf::section::as_strtab function of Libelfin v0 ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173408,6 +173412,7 @@ CVE-2020-24826 (A vulnerability in the elf::section::as_strtab function of Libel
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#segv-in-function-elfsectionas_strtab-at-elfelfcc284
 CVE-2020-24825 (A vulnerability in the line_table::line_table function of Libelfin v0. ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173415,6 +173420,7 @@ CVE-2020-24825 (A vulnerability in the line_table::line_table function of Libelf
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#segv-in-function-line_tableline_table-at-dwarflinecc104
 CVE-2020-24824 (A global buffer overflow issue in the dwarf::line_table::line_table fu ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173422,6 +173428,7 @@ CVE-2020-24824 (A global buffer overflow issue in the dwarf::line_table::line_ta
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#global-buffer-overflow-in-function-dwarfline_tableline_table-at-dwarflinecc107
 CVE-2020-24823 (A vulnerability in the dwarf::to_string function of Libelfin v0.3 allo ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173429,6 +173436,7 @@ CVE-2020-24823 (A vulnerability in the dwarf::to_string function of Libelfin v0.
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#segv-in-function-dwarfto_string-at-dwarfvaluecc300
 CVE-2020-24822 (A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 a ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -173436,6 +173444,7 @@ CVE-2020-24822 (A vulnerability in the dwarf::cursor::uleb function of Libelfin
 	NOTE: https://github.com/xiaoxiongwang/function_bugs/tree/master/libelfin#segv-in-function-dwarfcursoruleb128-at-dwarfinternalhh154
 CVE-2020-24821 (A vulnerability in the dwarf::cursor::skip_form function of Libelfin v ...)
 	- libelfin <unfixed> (bug #1014122)
+	[bookworm] - libelfin <no-dsa> (Minor issue)
 	[bullseye] - libelfin <no-dsa> (Minor issue)
 	[buster] - libelfin <no-dsa> (Minor issue)
 	[stretch] - libelfin <no-dsa> (Minor issue)
@@ -274955,6 +274964,7 @@ CVE-2015-9281 (Logon Manager in SAS Web Infrastructure Platform before 9.4M3 all
 	NOT-FOR-US: SAS Web Infrastructure Platform
 CVE-2019-6462 (An issue was discovered in cairo 1.16.0. There is an infinite loop in  ...)
 	- cairo <unfixed> (low; bug #929945)
+	[bookworm] - cairo <ignored> (Minor issue)
 	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
@@ -274962,6 +274972,7 @@ CVE-2019-6462 (An issue was discovered in cairo 1.16.0. There is an infinite loo
 	NOTE: https://gitlab.freedesktop.org/cairo/cairo/issues/353
 CVE-2019-6461 (An issue was discovered in cairo 1.16.0. There is an assertion problem ...)
 	- cairo <unfixed> (low; bug #929944)
+	[bookworm] - cairo <ignored> (Minor issue)
 	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
@@ -297056,6 +297067,7 @@ CVE-2018-18065 (_set_key in agent/helpers/table_container.c in Net-SNMP before 5
 	NOTE: https://sourceforge.net/p/net-snmp/code/ci/7ffb8e25a0db851953155de91f0170e9bf8c457d/
 CVE-2018-18064 (cairo through 1.15.14 has an out-of-bounds stack-memory write during p ...)
 	- cairo <unfixed> (low; bug #916083)
+	[bookworm] - cairo <ignored> (Minor issue)
 	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
@@ -318447,6 +318459,7 @@ CVE-2018-10113 (An issue was discovered in GEGL through 0.3.32. The process func
 	NOTE: https://gitlab.gnome.org/GNOME/gegl/commit/c83b05d565a1e3392c9606a4ecaa560eb9a4ee29
 CVE-2018-10112 (An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_ ...)
 	- gegl <unfixed> (low; bug #1014710)
+	[bookworm] - gegl <ignored> (Minor issue, architectual limitation)
 	[bullseye] - gegl <ignored> (Minor issue, architectual limitation)
 	[buster] - gegl <ignored> (Minor issue, architectual limitation)
 	[stretch] - gegl <ignored> (Minor issue, architectual limitation)
@@ -318457,6 +318470,7 @@ CVE-2018-10112 (An issue was discovered in GEGL through 0.3.32. The gegl_tile_ba
 	NOTE: https://github.com/xiaoqx/pocs/tree/master/gegl#4-gegl-outbound-write-2
 CVE-2018-10111 (An issue was discovered in GEGL through 0.3.32. The render_rectangle f ...)
 	- gegl <unfixed> (low; bug #1014710)
+	[bookworm] - gegl <ignored> (Minor issue, architectual limitation)
 	[bullseye] - gegl <ignored> (Minor issue, architectual limitation)
 	[buster] - gegl <ignored> (Minor issue, architectual limitation)
 	[stretch] - gegl <ignored> (Minor issue, architectual limitation)
@@ -377358,6 +377372,7 @@ CVE-2017-7476 (Gnulib before 2017-04-26 has a heap-based buffer overflow with th
 	NOTE: Introduced with 4bc76593 and 4e6e16b3f.
 CVE-2017-7475 (Cairo version 1.15.4 is vulnerable to a NULL pointer dereference relat ...)
 	- cairo <unfixed> (low; bug #870264)
+	[bookworm] - cairo <ignored> (Minor issue)
 	[bullseye] - cairo <ignored> (Minor issue)
 	[buster] - cairo <ignored> (Minor issue)
 	[stretch] - cairo <no-dsa> (Minor issue)
@@ -412564,6 +412579,7 @@ CVE-2016-4456 (The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 all
 	NOTE: https://www.openwall.com/lists/oss-security/2016/06/07/2
 CVE-2016-1000002 (gdm3 3.14.2 and possibly later has an information leak before screen l ...)
 	- gdm3 <unfixed> (low; bug #849432)
+	[bookworm] - gdm3 <ignored> (Minor issue)
 	[bullseye] - gdm3 <ignored> (Minor issue)
 	[buster] - gdm3 <ignored> (Minor issue)
 	[stretch] - gdm3 <ignored> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1310760a868c9ba0242671aa8593093f4a74fa16

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1310760a868c9ba0242671aa8593093f4a74fa16
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230111/48084bb9/attachment.htm>


More information about the debian-security-tracker-commits mailing list