[Git][security-tracker-team/security-tracker][master] Add CVE-2023-3172{3,4,5}/yasm

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 18 06:25:50 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7ca8a1fb by Salvatore Bonaccorso at 2023-05-18T07:25:20+02:00
Add CVE-2023-3172{3,4,5}/yasm

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,11 +7,16 @@ CVE-2023-31903 (GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload whic
 CVE-2023-31902 (RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execu ...)
 	NOT-FOR-US: RPA Technology Mobile Mouse
 CVE-2023-31725 (yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free v ...)
-	TODO: check
+	- yasm <unfixed>
+	NOTE: https://github.com/yasm/yasm/issues/221
 CVE-2023-31724 (yasm 1.3.0.55.g101bc was discovered to contain a segmentation violatio ...)
-	TODO: check
+	- yasm <unfixed> (unimportant)
+	NOTE: https://github.com/yasm/yasm/issues/222
+	NOTE: Crash in CLI tool, no security impact
 CVE-2023-31723 (yasm 1.3.0.55.g101bc was discovered to contain a segmentation violatio ...)
-	TODO: check
+	- yasm <unfixed> (unimportant)
+	NOTE: https://github.com/yasm/yasm/issues/220
+	NOTE: Crash in CLI tool, no security impact
 CVE-2023-31722 (There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: ...)
 	TODO: check
 CVE-2023-31703 (Cross Site Scripting (XSS) in the edit user form in Microworld Technol ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca8a1fbcca1b5c9b46845119503799b3bdddd17

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca8a1fbcca1b5c9b46845119503799b3bdddd17
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230518/cc3265ab/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list