[Git][security-tracker-team/security-tracker][master] Add CVE-2023-30086/tiff

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed May 10 20:35:14 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
abeebcd3 by Salvatore Bonaccorso at 2023-05-10T21:34:38+02:00
Add CVE-2023-30086/tiff

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4016,7 +4016,11 @@ CVE-2023-30088 (An issue found in Cesanta MJS v.1.26 allows a local attacker to
 CVE-2023-30087 (Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a loc ...)
 	NOT-FOR-US: Cesenta MJS
 CVE-2023-30086 (Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local  ...)
-	TODO: check
+	- tiff 4.5.0-2
+	[bullseye] - tiff <no-dsa> (Minor issue)
+	NOTE: https://gitlab.com/libtiff/libtiff/-/issues/538
+	NOTE: Likely fixed by: https://gitlab.com/libtiff/libtiff/-/merge_requests/385
+	NOTE: https://gitlab.com/libtiff/libtiff/-/commit/f00484b9519df933723deb38fff943dc291a793d (v4.5.0rc1)
 CVE-2023-30085 (Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows ...)
 	- ming <removed>
 	NOTE: https://github.com/libming/libming/issues/267



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/abeebcd355bd9210005f6bf7cf291b1ce8b40ef1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/abeebcd355bd9210005f6bf7cf291b1ce8b40ef1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230510/c7ee1c6e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list