[Git][security-tracker-team/security-tracker][master] Add buildah references from v1.37.5 tag

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Oct 19 15:14:18 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
67e6f0ee by Salvatore Bonaccorso at 2024-10-19T16:13:24+02:00
Add buildah references from v1.37.5 tag

The commit for CVE-2024-9675 was indeed cherry-picked in the
1.37.4+ds1-1 version as well.

Link: https://github.com/containers/buildah/releases/tag/v1.37.5

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -981,6 +981,7 @@ CVE-2024-9676 (A vulnerability was found in Podman, Buildah, and CRI-O. A symlin
 	- podman <unfixed>
 	NOTE: https://github.com/advisories/GHSA-wq2p-5pc6-wpgf
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2317467
+	NOTE: https://github.com/containers/buildah/pull/5786
 CVE-2024-9506 (Improper regular expression in Vue's parseHTML function leads to a pot ...)
 	NOT-FOR-US: Vue
 CVE-2024-5749 (Certain HP DesignJet products may be vulnerable to credential reflecti ...)
@@ -2193,6 +2194,7 @@ CVE-2024-9675 (A vulnerability was found in Buildah. Cache mounts do not properl
 	[bookworm] - golang-github-containers-buildah <no-dsa> (Minor issue)
 	[bullseye] - golang-github-containers-buildah <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2317458
+	NOTE: https://github.com/containers/buildah/pull/5780
 CVE-2024-9671 (A vulnerability was found in 3Scale. There is no auth mechanism to see ...)
 	NOT-FOR-US: Red Hat 3scale
 CVE-2024-9575 (Local File Inclusion vulnerability in pretix Widget WordPress plugin p ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67e6f0eec260bf9e0791aebeefb6e55b3b4c97a3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67e6f0eec260bf9e0791aebeefb6e55b3b4c97a3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241019/49ae6953/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list