[Git][security-tracker-team/security-tracker][master] bullseye triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri May 19 16:41:07 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
19efa95a by Moritz Muehlenhoff at 2023-05-19T17:40:51+02:00
bullseye triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -82,8 +82,9 @@ CVE-2023-31903 (GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload whic
 CVE-2023-31902 (RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execu ...)
 	NOT-FOR-US: RPA Technology Mobile Mouse
 CVE-2023-31725 (yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free v ...)
-	- yasm <unfixed>
+	- yasm <unfixed> (unimportant)
 	NOTE: https://github.com/yasm/yasm/issues/221
+	NOTE: Crash in CLI tool, no security impact
 CVE-2023-31724 (yasm 1.3.0.55.g101bc was discovered to contain a segmentation violatio ...)
 	- yasm <unfixed> (unimportant)
 	NOTE: https://github.com/yasm/yasm/issues/222
@@ -446,6 +447,7 @@ CVE-2023-31408 (Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW
 	NOT-FOR-US: SICK
 CVE-2023-32784 (In KeePass 2.x before 2.54, it is possible to recover the cleartext ma ...)
 	- keepass2 <unfixed>
+	[bullseye] - keepass2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/vdohney/keepass-password-dumper
 	NOTE: https://sourceforge.net/p/keepass/discussion/329220/thread/f3438e6283/
 CVE-2023-32758 (giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep thro ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19efa95abc996d1ec55635099eaa51129cbdd7b8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19efa95abc996d1ec55635099eaa51129cbdd7b8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230519/275fbe13/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list