[Git][security-tracker-team/security-tracker][master] new strongswan issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon May 27 15:21:18 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d53c47aa by Moritz Muehlenhoff at 2024-05-27T16:20:18+02:00
new strongswan issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -873,7 +873,7 @@ CVE-2024-3711 (The Brizy \u2013 Page Builder plugin for WordPress is vulnerable
 	NOT-FOR-US: WordPress plugin
 CVE-2024-3708 (A condition exists in lighttpd version prior to 1.4.51 whereby a remot ...)
 	- lighttpd 1.4.52-1
-	TODO: check details (will be only pubished on July 9th, 2024), but said to be an issue fixed by maintainer in 2018 in version 1.4.51
+	NOTE: will only be published on July 9th, 2024, but said to be an issue fixed by maintainer in 2018 in version 1.4.51
 CVE-2024-3648 (The ShareThis Share Buttons plugin for WordPress is vulnerable to Stor ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-3626 (The Email Subscribers by Icegram Express \u2013 Email Marketing, Newsl ...)
@@ -7161,7 +7161,11 @@ CVE-2023-49781 (NocoDB is software for building databases as spreadsheets. Prior
 CVE-2023-46870 (extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAP ...)
 	NOT-FOR-US: Nordic Semiconductor nRF Sniffer for Bluetooth
 CVE-2022-4967 (strongSwan versions 5.9.2 through 5.9.5 are affected by authorization  ...)
-	TODO: check
+	- strongswan 5.9.4-1
+	[bullseye] - strongswan <not-affected> (Introduced in 5.9.2)
+	[buster] - strongswan <not-affected> (Introduced in 5.9.2)
+	NOTE: https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html
+	NOTE: https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136 (5.9.6rc1)
 CVE-2024-27401 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
 	- linux 6.8.11-1
 	NOTE: https://git.kernel.org/linus/38762a0763c10c24a4915feee722d7aa6e73eb98 (6.9-rc7)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d53c47aa0e68dba09629401cb0ec280463b60608

-- 
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d53c47aa0e68dba09629401cb0ec280463b60608
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240527/849e3404/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list