[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-28550: Reference non-merge commit upstream and add upstream tag

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 10 19:43:59 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
67e36bd1 by Salvatore Bonaccorso at 2023-07-10T20:42:53+02:00
CVE-2022-28550: Reference non-merge commit upstream and add upstream tag

- - - - -
3a36cf4f by Salvatore Bonaccorso at 2023-07-10T20:43:26+02:00
Track fixed version via unstable for CVE-2022-28550/jhead

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -94027,11 +94027,11 @@ CVE-2022-28552 (Cscms 4.1 is vulnerable to SQL Injection. Log into the backgroun
 CVE-2022-28551
 	RESERVED
 CVE-2022-28550 (Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via  ...)
-	- jhead <unfixed>
+	- jhead 1:3.08-1
 	[bookworm] - jhead <no-dsa> (Minor issue)
 	[bullseye] - jhead <no-dsa> (Minor issue)
 	NOTE: https://github.com/Matthias-Wandel/jhead/issues/51
-	NOTE: https://github.com/Matthias-Wandel/jhead/commit/64894dbc7d8e1e232e85f1cab25c64290b2fc167
+	NOTE: https://github.com/Matthias-Wandel/jhead/commit/9688daa7de7eb7bdc6b2223c33eb9ccc2f668b88 (3.08)
 CVE-2022-28549
 	RESERVED
 CVE-2022-28548



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4c8813d16eb10b38f25e84a25d2dcdeb47a22c26...3a36cf4f938b6efcb7d62031ddb1e16c477463d2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4c8813d16eb10b38f25e84a25d2dcdeb47a22c26...3a36cf4f938b6efcb7d62031ddb1e16c477463d2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230710/be0b13eb/attachment.htm>


More information about the debian-security-tracker-commits mailing list