[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2024-0007

Alberto Garcia (@berto) berto at debian.org
Wed Nov 27 14:02:51 GMT 2024



Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a28b64b by Alberto Garcia at 2024-11-27T15:02:26+01:00
webkit2gtk / wpewebkit upstream advisory WSA-2024-0007

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1760,9 +1760,19 @@ CVE-2024-45511 (An issue was discovered in Zimbra Collaboration (ZCS) through 10
 CVE-2024-45510 (An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zi ...)
 	NOT-FOR-US: Zimbra
 CVE-2024-44309 (A cookie management issue was addressed with improved state management ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.4-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.46.4-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0007.html
 CVE-2024-44308 (The issue was addressed with improved checks. This issue is fixed in S ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.4-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.46.4-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0007.html
 CVE-2024-44307 (A buffer overflow issue was addressed with improved memory handling. T ...)
 	NOT-FOR-US: Apple
 CVE-2024-44306 (A buffer overflow issue was addressed with improved memory handling. T ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -44,6 +44,8 @@ thunderbird (jmm)
 --
 trafficserver
 --
+webkit2gtk (berto)
+--
 wordpress
 --
 xen



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a28b64b8b8471563c0f3a73e3e306f844032b79

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a28b64b8b8471563c0f3a73e3e306f844032b79
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241127/7ae84881/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list