[Git][security-tracker-team/security-tracker][master] Add notes for CVE-2024-3647 hardening

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 6 20:36:20 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b3e040f8 by Salvatore Bonaccorso at 2024-09-06T21:36:09+02:00
Add notes for CVE-2024-3647 hardening

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -24756,6 +24756,9 @@ CVE-2024-36472 (In GNOME Shell through 45.7, a portal helper can be launched aut
 	[bullseye] - gnome-shell <no-dsa> (Minor issue)
 	[buster] - gnome-shell <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/7688
+	NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/commit/4ab1ccf3f21b754ce4be77becf5df46084a893d8 (47.beta)
+	NOTE: As hardening related to CVE-2024-36472, version gnome-shell/47~rc-3 disabled
+	NOTE: the portal helper popup window and uses the notification/browser method.
 CVE-2024-36110 (ansibleguy-webui is an open source WebUI for using Ansible. Multiple f ...)
 	NOT-FOR-US: ansibleguy-webui
 CVE-2024-36109 (CoCalc is web-based software that enables collaboration in research, t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3e040f8ba12bbb38736fd9b13677584946a4244

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3e040f8ba12bbb38736fd9b13677584946a4244
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240906/3649cf58/attachment.htm>


More information about the debian-security-tracker-commits mailing list