[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2023-47641/python-aiohttp

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Nov 15 08:57:04 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0fe95534 by Salvatore Bonaccorso at 2023-11-15T09:56:14+01:00
Add CVE-2023-47641/python-aiohttp

- - - - -
90d2b996 by Salvatore Bonaccorso at 2023-11-15T09:56:15+01:00
Add CVE-2023-47627/python-aiohttp

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,9 @@ CVE-2023-48217 (Statamic is a flat-first, Laravel + Git powered CMS designed for
 CVE-2023-47678 (An improper access control vulnerability exists in RT-AC87U all versio ...)
 	NOT-FOR-US: ASUSTeK
 CVE-2023-47641 (aiohttp is an asynchronous HTTP client/server framework for asyncio an ...)
-	TODO: check
+	- python-aiohttp 3.8.1-2
+	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xx9p-xxvh-7g8j
+	NOTE: https://github.com/aio-libs/aiohttp/commit/f016f0680e4ace6742b03a70cb0382ce86abe371 (v3.8.0b0)
 CVE-2023-47640 (DataHub is an open-source metadata platform. The HMAC signature for Da ...)
 	NOT-FOR-US: DataHub
 CVE-2023-47631 (vantage6 is a framework to manage and deploy privacy enhancing technol ...)
@@ -25,7 +27,9 @@ CVE-2023-47631 (vantage6 is a framework to manage and deploy privacy enhancing t
 CVE-2023-47630 (Kyverno is a policy engine designed for Kubernetes. An issue was found ...)
 	NOT-FOR-US: Kyverno
 CVE-2023-47627 (aiohttp is an asynchronous HTTP client/server framework for asyncio an ...)
-	TODO: check
+	- python-aiohttp 3.8.6-1
+	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-gfw2-4jvh-wgfg
+	NOTE: https://github.com/aio-libs/aiohttp/commit/d5c12ba890557a575c313bb3017910d7616fce3d (v3.8.6)
 CVE-2023-47586 (Multiple heap-based buffer overflow vulnerabilities exist in V-Server  ...)
 	NOT-FOR-US: FUJI
 CVE-2023-47585 (Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c2490cdffab061b0e80494e870971aa502d4325b...90d2b996a183d6cde139f20d31e6b8d6c78472d1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c2490cdffab061b0e80494e870971aa502d4325b...90d2b996a183d6cde139f20d31e6b8d6c78472d1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231115/423bf308/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list