[Git][security-tracker-team/security-tracker][master] Add CVE-2023-3932{7,8,9}/openjpeg2
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 6 08:22:54 BST 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c5b19524 by Salvatore Bonaccorso at 2024-07-06T09:22:09+02:00
Add CVE-2023-3932{7,8,9}/openjpeg2
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,6 +3,16 @@ CVE-2024-6501
[bookworm] - network-manager <no-dsa> (Minor issue)
[bullseye] - network-manager <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2295734
+CVE-2023-39329 [Resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c]
+ - openjpeg2 <unfixed>
+ NOTE: https://github.com/uclouvain/openjpeg/issues/1474
+CVE-2023-39328 [denail of service via crafted image file]
+ - openjpeg2 <unfixed>
+ NOTE: https://github.com/uclouvain/openjpeg/issues/1471
+ NOTE: https://github.com/uclouvain/openjpeg/pull/1470
+CVE-2023-39327 [Malicious files can cause the program to enter a large loop]
+ - openjpeg2 <unfixed>
+ NOTE: https://github.com/uclouvain/openjpeg/issues/1472
CVE-2024-6526 (A vulnerability classified as problematic has been found in CodeIgnite ...)
TODO: check
CVE-2024-6525 (** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DA ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b195249302ba7f086f699a20d3274c3f25f755
--
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b195249302ba7f086f699a20d3274c3f25f755
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240706/43e18e4b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list