[Git][security-tracker-team/security-tracker][master] bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 16 13:06:00 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
195e5fce by Moritz Muehlenhoff at 2024-08-16T14:05:18+02:00
bookworm triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -731,6 +731,7 @@ CVE-2024-20082 (In Modem, there is a possible memory corruption due to a missing
 	NOT-FOR-US: Mediatek
 CVE-2024-7730
 	- qemu <unfixed>
+	[bookworm] - qemu <no-dsa> (Minor issue)
 	NOTE: https://lore.kernel.org/qemu-devel/virtio-snd-fuzz-2427-fix-v1-manos.pitsidianakis@linaro.org/
 	NOTE: https://gitlab.com/qemu-project/qemu/-/issues/2427
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/98e77e3dd8dd6e7aa9a7dffa60f49c8c8a49d4e3 (v9.1.0-rc0)
@@ -2168,6 +2169,7 @@ CVE-2024-7317 (The Folders \u2013 Unlimited Folders to Organize Media Library Fo
 	NOT-FOR-US: WordPress plugin
 CVE-2024-7246 (It's possible for a gRPC client communicating with a HTTP/2 proxy to p ...)
 	- grpc <unfixed>
+	[bookworm] - grpc <no-dsa> (Minor issue)
 	NOTE: https://github.com/grpc/grpc/issues/36245
 	NOTE: Fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.
 CVE-2024-6720 (The Light Poll WordPress plugin through 1.0.0 does not have CSRF check ...)
@@ -12030,7 +12032,7 @@ CVE-2024-34142 (Adobe Experience Manager versions 6.5.20 and earlier are affecte
 CVE-2024-34141 (Adobe Experience Manager versions 6.5.20 and earlier are affected by a ...)
 	NOT-FOR-US: Adobe
 CVE-2024-32111 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- wordpress 6.5.5+dfsg1-1 (bug #1074486)
+	- wordpress <not-affected> (Only affects Windows systems)
 	NOTE: https://wordpress.org/news/2024/06/wordpress-6-5-5/
 CVE-2024-31111 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	- wordpress 6.5.5+dfsg1-1 (bug #1074486)
@@ -67518,6 +67520,7 @@ CVE-2023-43364 (main.py in Searchor before 2.4.2 uses eval on CLI input, which m
 	NOT-FOR-US: Searchor
 CVE-2023-41337 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In ...)
 	- h2o <unfixed> (bug #1059413)
+	[bookworm] - h2o <no-dsa> (Minor issue)
 	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-5v5r-rghf-rm6q
 	NOTE: Fixed by: https://github.com/h2o/h2o/commit/35760540337a47e5150da0f4a66a609fad2ef0ab
 CVE-2023-38694 (Umbraco is an ASP.NET content management system (CMS). Starting in ver ...)
@@ -78693,6 +78696,7 @@ CVE-2023-44487 (The HTTP/2 protocol allows a denial of service (server resource
 	[bullseye] - grpc <no-dsa> (Minor issue)
 	[buster] - grpc <no-dsa> (Minor issue)
 	- h2o 2.2.5+dfsg2-8 (bug #1054232)
+	[bookworm] - h2o <no-dsa> (Minor issue)
 	- haproxy 1.8.13-1
 	- nginx 1.24.0-2 (unimportant; bug #1053770)
 	- nghttp2 1.57.0-1 (bug #1053769)


=====================================
data/dsa-needed.txt
=====================================
@@ -11,6 +11,8 @@ To pick an issue, simply add your uid behind it.
 
 If needed, specify the release by adding a slash after the name of the source package.
 
+--
+aom (jmm)
 --
 cacti
   Bastien Roucariès is proposing to work on a update and agreed on it with maintainer
@@ -25,8 +27,7 @@ dnsmasq
   Lee Garrett showed interest to prepare an update for review
 --
 frr
-  Tobias Frost (tobi) proposed to work on preparing an update, but discussion
-  with Debian maintainer for status on bullseye + updates
+  coordination with the maintainer ongoing
 --
 ghostscript (carnil)
 --
@@ -37,10 +38,8 @@ git
 glance
   Maintainer prepared updates for review
 --
-h2o (jmm)
---
 libreswan
-  Waiting on feedback from maintainer, proposal to EOL Bullseye
+  Waiting on feedback from maintainer
 --
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/195e5fce977fdbd73a6e3bf716abf90f21144645

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/195e5fce977fdbd73a6e3bf716abf90f21144645
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240816/740465dd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list