[Git][security-tracker-team/security-tracker][master] iperf3 ignored

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Oct 28 19:15:23 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9e4df81c by Moritz Muehlenhoff at 2024-10-28T20:14:41+01:00
iperf3 ignored

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -44986,7 +44986,7 @@ CVE-2024-29212 (Due to an  unsafe de-serialization method used by the Veeam Serv
 	NOT-FOR-US: Veeam
 CVE-2024-26306 (iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server wi ...)
 	- iperf3 3.17.1-1 (bug #1071751)
-	[bookworm] - iperf3 <no-dsa> (Minor issue)
+	[bookworm] - iperf3 <ignored> (Minor issue)
 	[bullseye] - iperf3 <no-dsa> (Minor issue)
 	[buster] - iperf3 <postponed> (Minor issue; can be fixed in next update)
 CVE-2023-5052 (vulnerability in Uniform Server Zero, version 10.2.5, consisting of an ...)
@@ -96854,8 +96854,8 @@ CVE-2023-38473 (A vulnerability was found in Avahi. A reachable assertion exists
 	[bookworm] - avahi <no-dsa> (Minor issue)
 	[bullseye] - avahi <no-dsa> (Minor issue)
 	[buster] - avahi <postponed> (Minor issue; re-evaluate when fixed upstream)
-	NOTE: https://github.com/lathiat/avahi/issues/451
-	NOTE: https://github.com/lathiat/avahi/pull/486
+	NOTE: https://github.com/avahi/avahi/issues/451
+	NOTE: https://github.com/avahi/avahi/pull/486
 	NOTE: https://www.openwall.com/lists/oss-security/2023/10/06/4
 	NOTE: https://github.com/avahi/avahi/commit/b448c9f771bada14ae8de175695a9729f8646797 (v0.9-rc1)
 CVE-2023-38472 (A vulnerability was found in Avahi. A reachable assertion exists in th ...)
@@ -96863,8 +96863,8 @@ CVE-2023-38472 (A vulnerability was found in Avahi. A reachable assertion exists
 	[bookworm] - avahi <no-dsa> (Minor issue)
 	[bullseye] - avahi <no-dsa> (Minor issue)
 	[buster] - avahi <postponed> (Minor issue; re-evaluate when fixed upstream)
-	NOTE: https://github.com/lathiat/avahi/issues/452
-	NOTE: https://github.com/lathiat/avahi/pull/490
+	NOTE: https://github.com/avahi/avahi/issues/452
+	NOTE: https://github.com/avahi/avahi/pull/490
 	NOTE: https://www.openwall.com/lists/oss-security/2023/10/06/4
 	NOTE: https://github.com/avahi/avahi/commit/b024ae5749f4aeba03478e6391687c3c9c8dee40 (v0.9-rc1)
 CVE-2023-38471 (A vulnerability was found in Avahi. A reachable assertion exists in th ...)
@@ -96872,28 +96872,28 @@ CVE-2023-38471 (A vulnerability was found in Avahi. A reachable assertion exists
 	[bookworm] - avahi <no-dsa> (Minor issue)
 	[bullseye] - avahi <no-dsa> (Minor issue)
 	[buster] - avahi <postponed> (Minor issue; re-evaluate when fixed upstream)
-	NOTE: https://github.com/lathiat/avahi/issues/453
-	NOTE: https://github.com/lathiat/avahi/pull/494
-	NOTE: https://github.com/lathiat/avahi/commit/894f085f402e023a98cbb6f5a3d117bd88d93b09
+	NOTE: https://github.com/avahi/avahi/issues/453
+	NOTE: https://github.com/avahi/avahi/pull/494
+	NOTE: https://github.com/avahi/avahi/commit/894f085f402e023a98cbb6f5a3d117bd88d93b09
 	NOTE: https://www.openwall.com/lists/oss-security/2023/10/06/4
 CVE-2023-38470 (A vulnerability was found in Avahi. A reachable assertion exists in th ...)
 	- avahi <unfixed> (bug #1054877)
 	[bookworm] - avahi <no-dsa> (Minor issue)
 	[bullseye] - avahi <no-dsa> (Minor issue)
 	[buster] - avahi <postponed> (Minor issue; re-evaluate when fixed upstream)
-	NOTE: https://github.com/lathiat/avahi/issues/454
-	NOTE: https://github.com/lathiat/avahi/pull/457
-	NOTE: https://github.com/lathiat/avahi/commit/94cb6489114636940ac683515417990b55b5d66c
+	NOTE: https://github.com/avahi/avahi/issues/454
+	NOTE: https://github.com/avahi/avahi/pull/457
+	NOTE: https://github.com/avahi/avahi/commit/94cb6489114636940ac683515417990b55b5d66c
 	NOTE: https://www.openwall.com/lists/oss-security/2023/10/06/4
 CVE-2023-38469 (A vulnerability was found in Avahi, where a reachable assertion exists ...)
 	- avahi <unfixed> (bug #1054876)
 	[bookworm] - avahi <no-dsa> (Minor issue; can be mitigated by setting disable-user-service-publishing to yes)
 	[bullseye] - avahi <no-dsa> (Minor issue; can be mitigated by setting disable-user-service-publishing to yes)
 	[buster] - avahi <postponed> (Minor issue; can be mitigated by setting disable-user-service-publishing to yes)
-	NOTE: https://github.com/lathiat/avahi/issues/455
-	NOTE: https://github.com/lathiat/avahi/pull/500
+	NOTE: https://github.com/avahi/avahi/issues/455
+	NOTE: https://github.com/avahi/avahi/pull/500
 	NOTE: Fixed by: https://github.com/lathiat/avahi/commit/a337a1ba7d15853fb56deef1f464529af6e3a1cf
-	NOTE: Tests: https://github.com/lathiat/avahi/commit/c6cab87df290448a63323c8ca759baa516166237
+	NOTE: Tests: https://github.com/avahi/avahi/commit/c6cab87df290448a63323c8ca759baa516166237
 	NOTE: https://www.openwall.com/lists/oss-security/2023/10/06/4
 CVE-2023-5402 (A CWE-269: Improper Privilege Management vulnerability exists that cou ...)
 	NOT-FOR-US: Schneider Electric
@@ -108115,7 +108115,7 @@ CVE-2023-38404 (The XPRTLD web application in Veritas InfoScale Operations Manag
 	NOT-FOR-US: Veritas InfoScale
 CVE-2023-7250 (A flaw was found in iperf, a utility for testing network performance u ...)
 	- iperf3 3.15-1
-	[bookworm] - iperf3 <no-dsa> (Minor issue)
+	[bookworm] - iperf3 <ignored> (Minor issue)
 	[bullseye] - iperf3 <no-dsa> (Minor issue)
 	[buster] - iperf3 <no-dsa> (Minor issue)
 	NOTE: https://downloads.es.net/pub/iperf/esnet-secadv-2023-0002.txt.asc



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e4df81c9bf3d0352e2fecf2d5ad4aa84656d71a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e4df81c9bf3d0352e2fecf2d5ad4aa84656d71a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241028/b49dc9bd/attachment.htm>


More information about the debian-security-tracker-commits mailing list