[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Feb 24 20:12:46 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ff0d4959 by security tracker role at 2024-02-24T20:12:22+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,25 +1,41 @@
-CVE-2024-26600
+CVE-2024-1758 (The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Ser ...)
+	TODO: check
+CVE-2024-1710 (The Addon Library plugin for WordPress is vulnerable to unauthorized a ...)
+	TODO: check
+CVE-2024-1165 (The Brizy \u2013 Page Builder plugin for WordPress is vulnerable to Di ...)
+	TODO: check
+CVE-2024-0243 (With the following crawler configuration:  ```python from bs4 import B ...)
+	TODO: check
+CVE-2023-5775 (The BackWPup plugin for WordPress is vulnerable to Plaintext Storage o ...)
+	TODO: check
+CVE-2023-43051 (IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross ...)
+	TODO: check
+CVE-2023-38359 (IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross ...)
+	TODO: check
+CVE-2023-32344 (IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form  ...)
+	TODO: check
+CVE-2024-26600 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/7104ba0f1958adb250319e68a15eff89ec4fd36d (6.8-rc3)
-CVE-2024-26601
+CVE-2024-26601 (In the Linux kernel, the following vulnerability has been resolved:  e ...)
 	- linux <unfixed>
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/c9b528c35795b711331ed36dc3dbee90d5812d4e (6.8-rc3)
-CVE-2024-26602
+CVE-2024-26602 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/944d5fe50f3f03daacfea16300e656a1691c4a23
-CVE-2024-26603
+CVE-2024-26603 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
 	- linux <unfixed>
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/d877550eaf2dc9090d782864c96939397a3c6835 (6.8-rc4)
-CVE-2024-26604
+CVE-2024-26604 (In the Linux kernel, the following vulnerability has been resolved:  R ...)
 	- linux <unfixed>
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3ca8fbabcceb8bfe44f7f50640092fd8f1de375c (6.8-rc5)
-CVE-2024-26605
+CVE-2024-26605 (In the Linux kernel, the following vulnerability has been resolved:  P ...)
 	- linux <unfixed>
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	[buster] - linux <not-affected> (Vulnerable code not present)
@@ -3369,6 +3385,7 @@ CVE-2024-25191 (php-jwt 1.0.0 uses strcmp (which is not constant time) to verify
 CVE-2024-25190 (l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authe ...)
 	NOT-FOR-US: l8w8jwt
 CVE-2024-25189 (libjwt 1.15.3 uses strcmp (which is not constant time) to verify authe ...)
+	{DLA-3739-1}
 	[experimental] - libjwt 1.17.0-1
 	- libjwt 1.17.0-2 (bug #1063534)
 	[bookworm] - libjwt <no-dsa> (Minor issue)
@@ -46927,8 +46944,8 @@ CVE-2023-30998
 	RESERVED
 CVE-2023-30997
 	RESERVED
-CVE-2023-30996
-	RESERVED
+CVE-2023-30996 (IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to ...)
+	TODO: check
 CVE-2023-30995 (IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow  ...)
 	NOT-FOR-US: IBM
 CVE-2023-30994 (IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorith ...)
@@ -117810,8 +117827,8 @@ CVE-2022-34359
 	RESERVED
 CVE-2022-34358 (IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. Th ...)
 	NOT-FOR-US: IBM
-CVE-2022-34357
-	RESERVED
+CVE-2022-34357 (IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulne ...)
+	TODO: check
 CVE-2022-34356 (IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local ...)
 	NOT-FOR-US: IBM
 CVE-2022-34355 (IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff0d495981a33fe97bf42437af96ddeab27a4e24

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff0d495981a33fe97bf42437af96ddeab27a4e24
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240224/3ccac838/attachment.htm>


More information about the debian-security-tracker-commits mailing list