[Git][security-tracker-team/security-tracker][master] update entry for CVE-2023-50782

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Mar 19 19:41:49 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4dbdc9d by Moritz Muehlenhoff at 2024-03-19T20:41:28+01:00
update entry for CVE-2023-50782

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -20909,13 +20909,15 @@ CVE-2023-31546 (Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allow
 	NOT-FOR-US: DedeBIZ
 CVE-2023-50782 (A flaw was found in the python-cryptography package. This issue may al ...)
 	- python-cryptography <unfixed> (bug #1059308)
-	[bookworm] - python-cryptography <no-dsa> (Minor issue)
-	[bullseye] - python-cryptography <no-dsa> (Minor issue)
+	[bookworm] - python-cryptography <ignored> (Minor issue, fix relies on OpenSSL 3.2 interfaces)
+	[bullseye] - python-cryptography <ignored> (Minor issue, fix relies on OpenSSL 3.2 interfaces)
 	[buster] - python-cryptography <no-dsa> (Minor issue; it's an incomplete fix of CVE-2020-25659)
 	NOTE: https://github.com/pyca/cryptography/issues/9785
 	NOTE: https://people.redhat.com/~hkario/marvin/
 	NOTE: https://github.com/openssl/openssl/pull/13817
 	NOTE: CVE is for incomplete fix of CVE-2020-25659
+	NOTE: The fix relies on OpenSSL 3.2, we can mark this as fixed when openssl 3.2 lands
+	NOTE: in unstable
 CVE-2023-50781 (A flaw was found in m2crypto. This issue may allow a remote attacker t ...)
 	- m2crypto <unfixed> (bug #1059292)
 	[bookworm] - m2crypto <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4dbdc9d9922ebef19edb138a84a9adefc4a9fe8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4dbdc9d9922ebef19edb138a84a9adefc4a9fe8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240319/2f386d29/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list