[Git][security-tracker-team/security-tracker][master] new asterisk issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Dec 16 11:06:43 GMT 2024
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dc5d7b00 by Moritz Muehlenhoff at 2024-12-16T12:05:21+01:00
new asterisk issue
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3938,7 +3938,9 @@ CVE-2024-53707 (Cross-Site Request Forgery (CSRF) vulnerability in Ahmet \u0130m
CVE-2024-53617 (A Cross Site Scripting vulnerability in LibrePhotos before commit 3223 ...)
NOT-FOR-US: LibrePhotos
CVE-2024-53566 (An issue in the action_listcategories() function of Sangoma Asterisk v ...)
- TODO: check
+ - asterisk <unfixed>
+ NOTE: https://gist.github.com/hyp164D1/e7c0f44ffb38c00320aa1a6d98bee616
+ NOTE: Wasn't reported upstream, but they confirmed it and an advisory will be published
CVE-2024-53564 (A serious vulnerability was discovered in FreePBX 17.0.19.17. FreePBX ...)
NOT-FOR-US: FreePBX
CVE-2024-53484 (Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation d ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc5d7b00f30579eb4f1d55e5cdc240f7653d2f90
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc5d7b00f30579eb4f1d55e5cdc240f7653d2f90
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241216/91cb932f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list