[Git][security-tracker-team/security-tracker][master] Add new openafs issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Nov 12 23:09:32 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2bcc52e by Salvatore Bonaccorso at 2024-11-13T00:09:06+01:00
Add new openafs issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,15 @@
+CVE-2024-10397 [OPENAFS-SA-2024-003: buffer overflows in XDR responses]
+	- openafs 1.8.13-1 (bug #1087406; bug #1087407)
+	NOTE: http://openafs.org/pages/security/OPENAFS-SA-2024-003.txt
+	NOTE: https://lists.openafs.org/pipermail/openafs-devel/2024-November/020961.html
+CVE-2024-10396 [OPENAFS-SA-2024-002: fileserver crash on malformed StoreACL]
+	- openafs 1.8.13-1 (bug #1087406; bug #1087407)
+	NOTE: http://openafs.org/pages/security/OPENAFS-SA-2024-002.txt
+	NOTE: https://lists.openafs.org/pipermail/openafs-devel/2024-November/020961.html
+CVE-2024-10394 [OPENAFS-SA-2024-001: theft of credentials from Unix PAGs]
+	- openafs 1.8.13-1 (bug #1087406; bug #1087407)
+	NOTE: http://openafs.org/pages/security/OPENAFS-SA-2024-001.txt
+	NOTE: https://lists.openafs.org/pipermail/openafs-devel/2024-November/020961.html
 CVE-2024-9999 (In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implem ...)
 	NOT-FOR-US: Progress WS_FTP Server
 CVE-2024-9998



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2bcc52e0d346a31818675ce8d82b4e39441e510

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2bcc52e0d346a31818675ce8d82b4e39441e510
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241112/0a7415ab/attachment.htm>


More information about the debian-security-tracker-commits mailing list