[Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2023-31555/libpodofo as no-dsa for buster

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Mon May 15 06:23:38 BST 2023



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
842a0cf5 by Utkarsh Gupta at 2023-05-15T10:50:22+05:30
Mark CVE-2023-31555/libpodofo as no-dsa for buster

- - - - -
eb607fa1 by Utkarsh Gupta at 2023-05-15T10:52:33+05:30
Mark CVE-2023-31566-67/libpodofo as no-dsa for buster

- - - - -
20824c93 by Utkarsh Gupta at 2023-05-15T10:53:10+05:30
Mark CVE-2023-29491/ncurses as no-dsa for buster

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -240,11 +240,13 @@ CVE-2023-31567 (Podofo v0.10.0 was discovered to contain a heap buffer overflow
 	- libpodofo <unfixed>
 	[bookworm] - libpodofo <no-dsa> (Minor issue)
 	[bullseye] - libpodofo <no-dsa> (Minor issue)
+	[buster] - libpodofo <no-dsa> (Minor issue)
 	NOTE: https://github.com/podofo/podofo/issues/71
 CVE-2023-31566 (Podofo v0.10.0 was discovered to contain a heap-use-after-free via the ...)
 	- libpodofo <unfixed>
 	[bookworm] - libpodofo <no-dsa> (Minor issue)
 	[bullseye] - libpodofo <no-dsa> (Minor issue)
+	[buster] - libpodofo <no-dsa> (Minor issue)
 	NOTE: https://github.com/podofo/podofo/issues/70
 CVE-2023-31557 (xpdf pdfimages v4.04 was discovered to contain a stack overflow in the ...)
 	TODO: check
@@ -256,6 +258,7 @@ CVE-2023-31556 (podofoinfo 0.10.0 was discovered to contain a segmentation viola
 CVE-2023-31555 (podofoinfo 0.10.0 was discovered to contain a segmentation violation v ...)
 	- libpodofo <not-affected> (Vulnerable code not present)
 	[bullseye] - libpodofo <no-dsa> (Minor issue)
+	[buster] - libpodofo <no-dsa> (Minor issue)
 	NOTE: https://github.com/podofo/podofo/issues/67
 	NOTE: Fixed by: https://github.com/podofo/podofo/commit/3759eb6aae7c01f2d8670f16ac46f5e116c7f468
 	NOTE: Introduced by: https://github.com/podofo/podofo/commit/a2eca000e5a4337fb79ee8215d06413785653184
@@ -5732,6 +5735,7 @@ CVE-2023-29492 (Novi Survey before 8.9.43676 allows remote attackers to execute
 CVE-2023-29491 (ncurses before 6.4 20230408, when used by a setuid application, allows ...)
 	- ncurses <unfixed> (bug #1034372)
 	[bullseye] - ncurses <no-dsa> (Minor issue)
+	[buster] - ncurses <no-dsa> (Minor issue)
 	NOTE: https://invisible-island.net/ncurses/NEWS.html#index-t20230408
 	NOTE: http://ncurses.scripts.mit.edu/?p=ncurses.git;a=commitdiff;h=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
 	NOTE: https://github.com/ThomasDickey/ncurses-snapshots/commit/a6d3f92bb5bba1a71c7c3df39497abbe5fe999ff



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37f2f02b581e7c4e8063b16df657bf335703ec48...20824c93746e330a22509eebbfe4d6f83c47fe40

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37f2f02b581e7c4e8063b16df657bf335703ec48...20824c93746e330a22509eebbfe4d6f83c47fe40
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230515/bd931fdc/attachment.htm>


More information about the debian-security-tracker-commits mailing list