[Git][security-tracker-team/security-tracker][master] Add note about samba/buster for CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968

Santiago R.R. (@santiago) santiago at debian.org
Tue Mar 19 19:33:30 GMT 2024



Santiago R.R. pushed to branch master at Debian Security Tracker / security-tracker


Commits:
22cebdf4 by Santiago Ruano Rincón at 2024-03-19T16:33:05-03:00
Add note about samba/buster for CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43998,7 +43998,9 @@ CVE-2023-3347 (A vulnerability was found in Samba's SMB2 packet signing mechanis
 CVE-2023-34968 (A path disclosure vulnerability was found in Samba. As part of the Spo ...)
 	{DSA-5477-1}
 	- samba 2:4.18.5+dfsg-1
+	[buster] - samba <ignored> (spotlight enabled in 4.13.13+dfsg-1 - bullseye)
 	NOTE: https://www.samba.org/samba/security/CVE-2023-34968.html
+	NOTE: severity:unimportant for buster backwards, but we don't have suite-specific severity annotations
 CVE-2023-42464 (A Type Confusion vulnerability was found in the Spotlight RPC function ...)
 	{DSA-5503-1 DLA-3584-1}
 	- netatalk 3.1.17~ds-1 (bug #1052087)
@@ -44009,11 +44011,15 @@ CVE-2023-42464 (A Type Confusion vulnerability was found in the Spotlight RPC fu
 CVE-2023-34967 (A Type Confusion vulnerability was found in Samba's mdssvc RPC service ...)
 	{DSA-5477-1}
 	- samba 2:4.18.5+dfsg-1
+	[buster] - samba <ignored> (spotlight enabled in 4.13.13+dfsg-1 - bullseye)
 	NOTE: https://www.samba.org/samba/security/CVE-2023-34967.html
+	NOTE: severity:unimportant for buster backwards, but we don't have suite-specific severity annotations
 CVE-2023-34966 (An infinite loop vulnerability was found in Samba's mdssvc RPC service ...)
 	{DSA-5477-1}
 	- samba 2:4.18.5+dfsg-1
+	[buster] - samba <ignored> (spotlight enabled in 4.13.13+dfsg-1 - bullseye)
 	NOTE: https://www.samba.org/samba/security/CVE-2023-34966.html
+	NOTE: severity:unimportant for buster backwards, but we don't have suite-specific severity annotations
 CVE-2023-3750 (A flaw was found in libvirt. The virStoragePoolObjListSearch function  ...)
 	- libvirt 9.6.0-1 (bug #1041811)
 	[bookworm] - libvirt <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22cebdf452b5f354d4903713723d818e445f7e6d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22cebdf452b5f354d4903713723d818e445f7e6d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240319/9aa59005/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list