[Git][security-tracker-team/security-tracker][master] Add reference for CVE-2024-43688/cron
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 22 05:56:03 BST 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
edb55029 by Salvatore Bonaccorso at 2024-08-22T06:55:14+02:00
Add reference for CVE-2024-43688/cron
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1007,6 +1007,7 @@ CVE-2024-4785 (BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Div
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2024-43688 (cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and ...)
- cron <not-affected> (Debian package does not contain the vulnerable code)
+ NOTE: https://www.supernetworks.org/CVE-2024-43688/openbsd-cron-heap-underflow.txt
NOTE: Introduced while refactoring: https://github.com/vixie/cron/commit/62a064fd775cd682426176bab002a7d54a6b5bfc
NOTE: Fixed by: https://github.com/vixie/cron/commit/9cc8ab1087bb9ab861dd5595c41200683c9f6712
CVE-2024-43202 (Exposure of Remote Code Execution in Apache Dolphinscheduler. This is ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edb5502988420654c2ccaa1a2c599c63d0cad5ab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edb5502988420654c2ccaa1a2c599c63d0cad5ab
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240822/e83952d3/attachment.htm>
More information about the debian-security-tracker-commits
mailing list