[Git][security-tracker-team/security-tracker][master] CVE-2023-2602 - libpsx is introduced in later versions. Not

Abhijith PA (@abhijith) abhijith at debian.org
Wed Jun 7 19:03:35 BST 2023



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d288b216 by Abhijith PA at 2023-06-07T23:22:33+05:30
CVE-2023-2602 - libpsx is introduced in later versions. Not
affecting 2.25.

CVE-2023-2603 - Code improvement done on
https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=a56162c6900d203c5ac63a2b41b46cb0c45c645f
This is an improved fix over something attempted
in libcap-2.55

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2458,6 +2458,7 @@ CVE-2023-2671 (A vulnerability was found in SourceCodester Lost and Found Inform
 CVE-2023-2603 (A vulnerability was found in libcap. This issue occurs in the _libcap_ ...)
 	- libcap2 1:2.66-4 (bug #1036114)
 	[bullseye] - libcap2 <no-dsa> (Minor issue)
+	[buster] - libcap2 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.iuvg7sbjg8pe
 	NOTE: https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
 	NOTE: https://www.openwall.com/lists/oss-security/2023/05/15/4
@@ -2465,6 +2466,7 @@ CVE-2023-2603 (A vulnerability was found in libcap. This issue occurs in the _li
 CVE-2023-2602 (A vulnerability was found in the pthread_create() function in libcap.  ...)
 	- libcap2 1:2.66-4 (bug #1036114)
 	[bullseye] - libcap2 <no-dsa> (Minor issue)
+	[buster] - libcap2 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.iuvg7sbjg8pe
 	NOTE: https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf
 	NOTE: https://www.openwall.com/lists/oss-security/2023/05/15/4



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d288b216c78e80f3b405df19d7a463d14e16e737

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d288b216c78e80f3b405df19d7a463d14e16e737
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230607/be3a0c1a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list