[Git][security-tracker-team/security-tracker][master] xmltooling DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Jun 18 15:45:27 BST 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
163e43b8 by Moritz Mühlenhoff at 2023-06-18T16:44:54+02:00
xmltooling DSA
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -559,6 +559,8 @@ CVE-2023-29160 (Stack-based buffer overflow vulnerability exists in FRENIC RHC L
NOT-FOR-US: FRENIC RHC Loader
CVE-2023-XXXX [Parsing of KeyInfo elements can cause remote resource access]
- xmltooling 3.2.4-1 (bug #1037948)
+ [bookworm] - xmltooling 3.2.3-1+deb12u1
+ [bullseye] - xmltooling 3.2.0-3+deb11u1
NOTE: https://shibboleth.net/community/advisories/secadv_20230612.txt
NOTE: https://git.shibboleth.net/view/?p=cpp-xmltooling.git;a=commit;h=6080f6343f98fec085bc0fd746913ee418cc9d30
CVE-2023-33991 (SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 7 ...)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[18 Jun 2023] DSA-5432-1 xmltooling - security update
+ [bookworm] - xmltooling 3.2.3-1+deb12u1
+ [bullseye] - xmltooling 3.2.0-3+deb11u1
[16 Jun 2023] DSA-5431-1 sofia-sip - security update
{CVE-2023-32307}
[bullseye] - sofia-sip 1.12.11+20110422.1-2.1+deb11u2
=====================================
data/dsa-needed.txt
=====================================
@@ -71,9 +71,6 @@ samba/oldstable
--
wpewebkit
--
-xmltooling (jmm)
- Maintainer preparing updates
---
xrdp/oldstable
needs some additional clarification, tentatively DSA worthy
maybe upgrade to 0.9.21 within bullseye?
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/163e43b864d196d87a851ec4e31b28eb5e1927c0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/163e43b864d196d87a851ec4e31b28eb5e1927c0
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230618/ac27eeb5/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list