[Git][security-tracker-team/security-tracker][master] new openssl issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Oct 17 23:34:08 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
365b6141 by Moritz Mühlenhoff at 2024-10-17T11:17:10+02:00
new openssl issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -71,7 +71,10 @@ CVE-2024-9444 (The ElementsReady Addons for Elementor plugin for WordPress is vu
 CVE-2024-9348 (Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source ...)
 	NOT-FOR-US: Docker Desktop
 CVE-2024-9143 (Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with u ...)
-	TODO: check
+	- openssl <unfixed>
+	[bookworm] - openssl <postponed> (Minor issue, fix along in next update)
+	NOTE: https://openssl-library.org/news/secadv/20241016.txt
+	NOTE: https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712
 CVE-2024-8921 (The Zita Elementor Site Library plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-8040 (An authorization bypass through user-controlled key vulnerability affe ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/365b6141b059c48d02a8da7fde2d02f618fa9c46

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/365b6141b059c48d02a8da7fde2d02f618fa9c46
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241017/e0a3c663/attachment.htm>


More information about the debian-security-tracker-commits mailing list