[Git][security-tracker-team/security-tracker][master] libkf5ksieve spu/ospu

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Apr 30 11:26:17 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
58f12d99 by Moritz Muehlenhoff at 2024-04-30T12:22:23+02:00
libkf5ksieve spu/ospu

- - - - -


3 changed files:

- data/CVE/list
- data/next-oldstable-point-update.txt
- data/next-point-update.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -315,6 +315,8 @@ CVE-2024-1905 (The Smart Forms  WordPress plugin before 2.6.96 does not sanitise
 	NOT-FOR-US: WordPress plugin
 CVE-2023-52723 (In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cl ...)
 	- libkf5ksieve 4:22.12.3-2 (bug #1069163)
+	[bookworm] - libkf5ksieve <no-dsa> (Minor issue, will be fixed via spu)
+	[bullseye] - libkf5ksieve <no-dsa> (Minor issue, will be fixed via ospu)
 	NOTE: https://www.openwall.com/lists/oss-security/2024/04/25/1
 	NOTE: Fixed by: https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 (v23.03.80)
 CVE-2024-4294 (A vulnerability, which was classified as critical, has been found in P ...)
@@ -6276,7 +6278,6 @@ CVE-2024-2201 [Native Branch History Injection]
 	[bookworm] - xen <postponed> (Minor issue, fix along in next DSA)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	[buster] - xen <end-of-life> (DSA 4677-1)
-	NOTE: https://www.openwall.com/lists/oss-security/2024/04/09/15
 	NOTE: https://vusec.net/projects/native-bhi
 	NOTE: https://download.vusec.net/papers/inspectre_sec24.pdf
 	NOTE: https://xenbits.xen.org/xsa/advisory-456.html


=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -93,3 +93,5 @@ CVE-2024-30204
 	[bullseye] - emacs 1:27.1+1-3.1+deb11u3
 CVE-2024-30205
 	[bullseye] - emacs 1:27.1+1-3.1+deb11u3
+CVE-2023-52723
+	[bullseye] - libkf5ksieve 4:20.08.3-1+deb11u1


=====================================
data/next-point-update.txt
=====================================
@@ -122,3 +122,5 @@ CVE-2024-30204
 	[bookworm] - emacs 1:28.2+1-15+deb12u1
 CVE-2024-30205
 	[bookworm] - emacs 1:28.2+1-15+deb12u1
+CVE-2023-52723
+	[bookworm] - libkf5ksieve 4:22.12.3-1+deb12u1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58f12d9954dd7e440a34a0c10f4a572ff497258d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58f12d9954dd7e440a34a0c10f4a572ff497258d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240430/2593a8c7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list