[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2024-22749/gpac: buster end-of-life

Sylvain Beucler (@beuc) beuc at debian.org
Thu Jan 25 22:18:21 GMT 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eca6e58b by Sylvain Beucler at 2024-01-25T22:55:18+01:00
CVE-2024-22749/gpac: buster end-of-life

- - - - -
3b1c9bfe by Sylvain Beucler at 2024-01-25T22:55:19+01:00
CVE-2023-52354/chasquid: buster postponed

- - - - -
dbf2e8c9 by Sylvain Beucler at 2024-01-25T22:55:19+01:00
CVE-2024-22563/openvswitch: buster postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,6 +23,7 @@ CVE-2024-23655 (Tuta is an encrypted email service. Starting in version 3.118.12
 	NOT-FOR-US: Tuta
 CVE-2024-22749 (GPAC v2.3 was detected to contain a buffer overflow via the function g ...)
 	- gpac <unfixed>
+	[buster] - gpac <end-of-life> (EOL in buster LTS)
 	NOTE: https://github.com/gpac/gpac/issues/2713
 	NOTE: https://github.com/gpac/gpac/commit/7aef8038c6bdd310e65000704e39afaa0e721048
 CVE-2024-22729 (NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command i ...)
@@ -821,6 +822,7 @@ CVE-2023-52354 (chasquid before 1.13 allows SMTP smuggling because LF-terminated
 	- chasquid 1.13-1
 	[bookworm] - chasquid <no-dsa> (Minor issue)
 	[bullseye] - chasquid <no-dsa> (Minor issue)
+	[buster] - chasquid <postponed> (Minor issue, request smuggling)
 	NOTE: https://blitiri.com.ar/p/chasquid/relnotes/#113-2023-12-24
 CVE-2023-52353 (An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_sess ...)
 	- mbedtls <unfixed>
@@ -967,6 +969,7 @@ CVE-2024-22876 (StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerab
 CVE-2024-22563 (openvswitch 2.17.8 was discovered to contain a memory leak via the fun ...)
 	- openvswitch 2.17.2-4
 	[bullseye] - openvswitch <no-dsa> (Minor issue)
+	[buster] - openvswitch <postponed> (Minor issue, memory leak)
 	NOTE: https://github.com/openvswitch/ovs-issues/issues/315
 	NOTE: https://github.com/openvswitch/ovs/commit/3168f328c78cf6e4b3022940452673b0e49f7620 (v2.17.0)
 CVE-2024-22562 (swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fd1078ed4f3c7d09292a71b0fe09ffa002e421d4...dbf2e8c9de5e552bb184c44a2a56607393ce3844

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fd1078ed4f3c7d09292a71b0fe09ffa002e421d4...dbf2e8c9de5e552bb184c44a2a56607393ce3844
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240125/2ee45514/attachment.htm>


More information about the debian-security-tracker-commits mailing list