[Git][security-tracker-team/security-tracker][master] 2 commits: dla: add pypy3

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Fri May 3 17:14:27 BST 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
838a46e8 by Sylvain Beucler at 2024-05-03T18:14:03+02:00
dla: add pypy3

- - - - -
9cd54b9d by Sylvain Beucler at 2024-05-03T18:14:05+02:00
CVE-2024-3572/python-scrapy: un-triage buster, there's vulnerability mix-up

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -4976,10 +4976,12 @@ CVE-2024-3572 (The scrapy/scrapy project is vulnerable to XML External Entity (X
 	- python-scrapy 2.11.1-1
 	[bookworm] - python-scrapy <no-dsa> (Minor issue)
 	[bullseye] - python-scrapy <no-dsa> (Minor issue)
-	[buster] - python-scrapy <postponed> (Minor issue, XXE)
 	NOTE: https://huntr.com/bounties/c4a0fac9-0c5a-4718-9ee4-2d06d58adabb
 	NOTE: https://github.com/scrapy/scrapy/commit/809bfac4890f75fc73607318a04d2ccba71b3d9f (2.11.1)
-	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-7j7m-v7m3-jqm7
+	NOTE: The CVE and bounty descriptions discuss general XML issues (not specifically XXE), but
+	NOTE: the bounty comments and the patch discuss a compression bomb.
+	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-7j7m-v7m3-jqm7 (compression bomb)
+	NOTE: (or https://github.com/scrapy/scrapy/security/advisories/GHSA-cc65-xxvf-f7r9 (XML ReDoS) ?)
 CVE-2024-3571 (langchain-ai/langchain is vulnerable to path traversal due to improper ...)
 	NOT-FOR-US: langchain
 CVE-2024-3493 (A specific malformed fragmented packet type (fragmented packets may be ...)


=====================================
data/dla-needed.txt
=====================================
@@ -225,6 +225,12 @@ putty (rouca)
 pymongo
   NOTE: 20240420: Added by Front-Desk (apo)
 --
+pypy3
+  NOTE: 20240503: Added by Front-Desk (Beuc)
+  NOTE: 20240503: Fix newly triaged (but old) issues;
+  NOTE: 20240503: follow PU #1070218;
+  NOTE: 20240503: check with maintainers about syncing bullseye too (Beuc/front-desk)
+--
 python-asyncssh
   NOTE: 20240116: Added by Front-Desk (lamby)
   NOTE: 20240131: Patch for CVE-2023-46445 and CVE-2023-46446 backported and in Git, but one test is failing. Waiting for feedback before release. (dleidert)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/50c5ca558591d556bbaf649e05747a377af2c4fb...9cd54b9dbf334785a14753f756e3ce521bede479

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/50c5ca558591d556bbaf649e05747a377af2c4fb...9cd54b9dbf334785a14753f756e3ce521bede479
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240503/956cc839/attachment.htm>


More information about the debian-security-tracker-commits mailing list