[Git][security-tracker-team/security-tracker][master] gifsicle non issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Oct 9 22:26:39 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2832033 by Moritz Muehlenhoff at 2023-10-09T23:22:41+02:00
gifsicle non issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,7 +43,9 @@ CVE-2023-45247 (Sensitive information disclosure and manipulation due to missing
 CVE-2023-44993 (Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI Cha ...)
 	NOT-FOR-US: QuantumCloud
 CVE-2023-44821 (Buffer Overflow vulnerability in gifsicle v.1.92 allows a remote attac ...)
-	TODO: check
+	- gifsicle <unfixed> (unimportant)
+	NOTE: Memory leak in CLI tool, no security impact
+	NOTE: https://github.com/kohler/gifsicle/issues/195
 CVE-2023-44812 (Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a ...)
 	NOT-FOR-US: mooSocial
 CVE-2023-44811 (Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28320337084d90aeb0f5bc926f9642501ed58dc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d28320337084d90aeb0f5bc926f9642501ed58dc
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231009/f38daeb9/attachment.htm>


More information about the debian-security-tracker-commits mailing list