[Git][security-tracker-team/security-tracker][master] xmltooling DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Jun 18 15:45:27 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
163e43b8 by Moritz Mühlenhoff at 2023-06-18T16:44:54+02:00
xmltooling DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -559,6 +559,8 @@ CVE-2023-29160 (Stack-based buffer overflow vulnerability exists in FRENIC RHC L
 	NOT-FOR-US: FRENIC RHC Loader
 CVE-2023-XXXX [Parsing of KeyInfo elements can cause remote resource access]
 	- xmltooling 3.2.4-1 (bug #1037948)
+	[bookworm] - xmltooling 3.2.3-1+deb12u1
+	[bullseye] - xmltooling 3.2.0-3+deb11u1
 	NOTE: https://shibboleth.net/community/advisories/secadv_20230612.txt
 	NOTE: https://git.shibboleth.net/view/?p=cpp-xmltooling.git;a=commit;h=6080f6343f98fec085bc0fd746913ee418cc9d30
 CVE-2023-33991 (SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 7 ...)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[18 Jun 2023] DSA-5432-1 xmltooling - security update
+	[bookworm] - xmltooling 3.2.3-1+deb12u1
+	[bullseye] - xmltooling 3.2.0-3+deb11u1
 [16 Jun 2023] DSA-5431-1 sofia-sip - security update
 	{CVE-2023-32307}
 	[bullseye] - sofia-sip 1.12.11+20110422.1-2.1+deb11u2


=====================================
data/dsa-needed.txt
=====================================
@@ -71,9 +71,6 @@ samba/oldstable
 --
 wpewebkit
 --
-xmltooling (jmm)
-  Maintainer preparing updates
---
 xrdp/oldstable
   needs some additional clarification, tentatively DSA worthy
   maybe upgrade to 0.9.21 within bullseye?



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/163e43b864d196d87a851ec4e31b28eb5e1927c0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/163e43b864d196d87a851ec4e31b28eb5e1927c0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230618/ac27eeb5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list