[Git][security-tracker-team/security-tracker][master] Process new gpac CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 1 21:32:41 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dac9a7d0 by Salvatore Bonaccorso at 2023-09-01T22:32:16+02:00
Process new gpac CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,18 @@
 CVE-2023-4722 (Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to ...)
-	TODO: check
+	- gpac <unfixed>
+	[buster] - gpac <end-of-life> (EOL in buster LTS)
+	NOTE: https://github.com/gpac/gpac/commit/de7f3a852bef72a52825fd307cf4e8f486401a76
+	NOTE: https://huntr.dev/bounties/ddfdb41d-e708-4fec-afe5-68ff1f88f830
 CVE-2023-4721 (Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.)
-	TODO: check
+	- gpac <unfixed>
+	[buster] - gpac <end-of-life> (EOL in buster LTS)
+	NOTE: https://github.com/gpac/gpac/commit/3ec93d73d048ed7b46fe6e9f307cc7a0cc13db63
+	NOTE: https://huntr.dev/bounties/f457dc62-3cff-47bd-8fd2-1cb2b4a832fc
 CVE-2023-4720 (Floating Point Comparison with Incorrect Operator in GitHub repository ...)
-	TODO: check
+	- gpac <unfixed>
+	[buster] - gpac <end-of-life> (EOL in buster LTS)
+	NOTE: https://github.com/gpac/gpac/commit/e396648e48c57e2d53988d3fd4465b068b96c89a
+	NOTE: https://huntr.dev/bounties/1dc2954c-8497-49fa-b2af-113e1e9381ad
 CVE-2023-4714 (A vulnerability was found in PlayTube 3.0.1 and classified as problema ...)
 	TODO: check
 CVE-2023-4713 (A vulnerability has been found in IBOS OA 4.5.5 and classified as crit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dac9a7d03d703c4aa0173045161bfdb09bc19781

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dac9a7d03d703c4aa0173045161bfdb09bc19781
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230901/f1c760af/attachment.htm>


More information about the debian-security-tracker-commits mailing list