[Git][security-tracker-team/security-tracker][master] Add four new gpac CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon May 22 22:13:30 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
315cf75c by Salvatore Bonaccorso at 2023-05-22T23:12:17+02:00
Add four new gpac CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,13 +23,21 @@ CVE-2023-31689 (In Wcms 0.3.2, an attacker can send a crafted request from a vul
 CVE-2023-31584 (GitHub repository cu/silicon commit a9ef36 was discovered to contain a ...)
 	TODO: check
 CVE-2023-2840 (NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2 ...)
-	TODO: check
+	- gpac <unfixed>
+	NOTE: https://huntr.dev/bounties/21926fc2-6eb1-4e24-8a36-e60f487d0257/
+	NOTE: https://github.com/gpac/gpac/commit/ba59206b3225f0e8e95a27eff41cb1c49ddf9a37
 CVE-2023-2839 (Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.)
-	TODO: check
+	- gpac <unfixed>
+	NOTE: https://huntr.dev/bounties/42dce889-f63d-4ea9-970f-1f20fc573d5f/
+	NOTE: https://github.com/gpac/gpac/commit/047f96fb39e6bf70cb9f344093f5886e51dce0ac
 CVE-2023-2838 (Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.)
-	TODO: check
+	- gpac <unfixed>
+	NOTE: https://huntr.dev/bounties/711e0988-5345-4c01-a2fe-1179604dd07f/
+	NOTE: https://github.com/gpac/gpac/commit/c88df2e202efad214c25b4e586f243b2038779ba
 CVE-2023-2837 (Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2. ...)
-	TODO: check
+	- gpac <unfixed>
+	NOTE: https://huntr.dev/bounties/a6bfd1b2-aba8-4c6f-90c4-e95b1831cb17/
+	NOTE: https://github.com/gpac/gpac/commit/6f28c4cd607d83ce381f9b4a9f8101ca1e79c611
 CVE-2023-2832 (SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.)
 	NOT-FOR-US: unilogies/bumsys
 CVE-2023-2597 (In Eclipse Openj9 before version 0.38.0, in the implementation of the  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/315cf75cf6fed70dd92b309f5c9dc4f0caae6e3c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/315cf75cf6fed70dd92b309f5c9dc4f0caae6e3c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230522/551bc665/attachment.htm>


More information about the debian-security-tracker-commits mailing list