[Git][security-tracker-team/security-tracker][master] 5 commits: CVE-2023-5377/gpac: buster end-of-life
Sylvain Beucler (@beuc)
beuc at debian.org
Thu Oct 5 17:34:15 BST 2023
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7332d32b by Sylvain Beucler at 2023-10-05T18:33:39+02:00
CVE-2023-5377/gpac: buster end-of-life
- - - - -
9c9f24a4 by Sylvain Beucler at 2023-10-05T18:33:41+02:00
CVE-2023-3576/tiff: buster postponed
- - - - -
b415156e by Sylvain Beucler at 2023-10-05T18:33:44+02:00
CVE-2023-3550/mediawiki: buster postponed
- - - - -
c75ebf24 by Sylvain Beucler at 2023-10-05T18:33:46+02:00
CVE-2023-43898/libstb: buster postponed
- - - - -
7d61209a by Sylvain Beucler at 2023-10-05T18:33:48+02:00
CVE-2023-5344/vim: buster postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -50,6 +50,7 @@ CVE-2023-5391 (ACWE-502:Deserialization of untrusted datavulnerability existstha
NOT-FOR-US: Schneider Electric
CVE-2023-5377 (Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.)
- gpac <unfixed>
+ [buster] - gpac <end-of-life> (EOL in buster LTS)
NOTE: https://github.com/gpac/gpac/commit/8e9d6b38c036a97020c462ad48e1132e0ddc57ce
NOTE: https://huntr.dev/bounties/fe778df4-3867-41d6-954b-211c81bccbbf
CVE-2023-5375 (Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.)
@@ -124,6 +125,7 @@ CVE-2023-3665 (A code injection vulnerability in Trellix ENS 10.7.0 April 2023 r
NOT-FOR-US: Trellix
CVE-2023-3576 (A memory leak flaw was found in Libtiff's tiffcrop utility. This issue ...)
- tiff 4.5.1~rc3-1
+ [buster] - tiff <postponed> (Minor issue, memory leak in CLI tool)
NOTE: https://gitlab.com/libtiff/libtiff/-/merge_requests/475
NOTE: Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/1d5b1181c980090a6518f11e61a18b0e268bf31a (v4.5.1rc1)
CVE-2023-3512 (Relative path traversal vulnerability in Setelsa Security's ConacWin C ...)
@@ -189,6 +191,7 @@ CVE-2023-43898 (Nothings stb 2.28 was discovered to contain a Null Pointer Deref
- libstb <unfixed>
[bookworm] - libstb <no-dsa> (Minor issue)
[bullseye] - libstb <no-dsa> (Minor issue)
+ [buster] - libstb <postponed> (Minor issue, DoS / clean crash)
NOTE: https://github.com/nothings/stb/issues/1452
NOTE: Proposed fixes: https://github.com/nothings/stb/pull/1454
NOTE: https://github.com/nothings/stb/issues/1521
@@ -421,6 +424,7 @@ CVE-2023-5344 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to
- vim <unfixed>
[bookworm] - vim <no-dsa> (Minor issue)
[bullseye] - vim <no-dsa> (Minor issue)
+ [buster] - vim <postponed> (Minor issue, 1-byte overflow)
NOTE: https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04
NOTE: https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf
CVE-2023-5341
@@ -1920,6 +1924,7 @@ CVE-2023-3550 (Mediawiki v1.40.0 does not validate namespaces used in XML files.
- mediawiki <unfixed>
[bookworm] - mediawiki <postponed> (Wait until it lands in 1.39)
[bullseye] - mediawiki <postponed> (Wait until it lands in 1.35)
+ [buster] - mediawiki <postponed> (Wait until it lands in 1.35)
NOTE: https://phabricator.wikimedia.org/T341565
CVE-2023-3547 (The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does ...)
NOT-FOR-US: WordPress plugin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f9db17106e3dadba4ca175017a9482c8b910c062...7d61209acb1816a0901f4480ee603890c09bffde
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f9db17106e3dadba4ca175017a9482c8b910c062...7d61209acb1816a0901f4480ee603890c09bffde
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231005/8c35e80d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list