[Git][security-tracker-team/security-tracker][master] Add CVE-2023-36328/libtommath

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 2 09:29:05 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
63bd46c0 by Salvatore Bonaccorso at 2023-09-02T10:28:33+02:00
Add CVE-2023-36328/libtommath

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -94,7 +94,9 @@ CVE-2023-37827 (A cross-site scripting (XSS) vulnerability in General Solutions
 CVE-2023-37826 (A cross-site scripting (XSS) vulnerability in General Solutions Steine ...)
 	NOT-FOR-US: General Solutions Steiner GmbH CASE 3 Taskmanagement
 CVE-2023-36328 (Integer Overflow vulnerability in mp_grow in libtom libtommath before  ...)
-	TODO: check
+	- libtommath <unfixed>
+	NOTE: https://github.com/libtom/libtommath/pull/546
+	NOTE: https://github.com/libtom/libtommath/commit/beba892bc0d4e4ded4d667ab1d2a94f4d75109a9
 CVE-2023-36327 (Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba424 ...)
 	TODO: check
 CVE-2023-36326 (Integer Overflow vulnerability in RELIC before commit 34580d840469361b ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63bd46c004315a1612db1ca16e8d137acd427728

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/63bd46c004315a1612db1ca16e8d137acd427728
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230902/cde407a2/attachment.htm>


More information about the debian-security-tracker-commits mailing list