[Git][security-tracker-team/security-tracker][master] 4 commits: mark CVE-2024-8372 and CVE-2024-8373 as postponed for Bullseye

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Sep 15 18:47:50 BST 2024



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5e82f773 by Thorsten Alteholz at 2024-09-15T19:23:20+02:00
mark CVE-2024-8372 and CVE-2024-8373 as postponed for Bullseye

- - - - -
5eb58505 by Thorsten Alteholz at 2024-09-15T19:35:17+02:00
mark CVE-2024-45321 as postponed for Bullseye

- - - - -
a701e8e7 by Thorsten Alteholz at 2024-09-15T19:39:55+02:00
mark CVE-2024-45508 as postponed for Bullseye

- - - - -
4f5f2f28 by Thorsten Alteholz at 2024-09-15T19:45:42+02:00
mark CVE-2024-45157 as not-affected for Bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1472,10 +1472,12 @@ CVE-2024-8601 (This vulnerability exists in TechExcel Back Office Software versi
 CVE-2024-8373 (Improper sanitization of the value of the [srcset] attribute in <sourc ...)
 	- angular.js <unfixed>
 	[bookworm] - angular.js <no-dsa> (Minor issue)
+	[bullseye] - angular.js <postponed> (Minor issue)
 	NOTE: https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b
 CVE-2024-8372 (Improper sanitization of the value of the '[srcset]' attribute in Angu ...)
 	- angular.js <unfixed>
 	[bookworm] - angular.js <no-dsa> (Minor issue)
+	[bullseye] - angular.js <postponed> (Minor issue)
 	NOTE: https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017
 CVE-2024-8042 (Rapid7 Insight Platform versions between November 2019 and August 14,  ...)
 	NOT-FOR-US: Rapid7 Insight Platform
@@ -2015,6 +2017,7 @@ CVE-2024-45158 (An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack bu
 CVE-2024-45157 (An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1 ...)
 	- mbedtls <unfixed>
 	[bookworm] - mbedtls <no-dsa> (Minor issue)
+	[bullseye] - mbedtls <not-affected> (Vulnerable code introduced in 2.26.0)
 	NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-1/
 CVE-2024-45107 (Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.0 ...)
 	NOT-FOR-US: Adobe
@@ -2945,6 +2948,7 @@ CVE-2024-45509 (In MISP through 2.4.196, app/Controller/BookmarksController.php
 CVE-2024-45508 (HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ...)
 	- htmldoc 1.9.18-2 (bug #1081236)
 	[bookworm] - htmldoc <no-dsa> (Minor issue)
+	[bullseye] - htmldoc <postponed> (Minor issue)
 	NOTE: https://github.com/michaelrsweet/htmldoc/issues/528
 	NOTE: https://github.com/michaelrsweet/htmldoc/commit/2d5b2ab9ddbf2aee2209010cebc11efdd1cab6e2
 CVE-2024-45270 (WordPress plugin "Carousel Slider" provided by Sayful Islam contains a ...)
@@ -3772,6 +3776,7 @@ CVE-2024-6688 (The Oxygen Builder plugin for WordPress is vulnerable to unauthor
 CVE-2024-45321 (The App::cpanminus package through 1.7047 for Perl downloads code via  ...)
 	- cpanminus <unfixed> (bug #1081559)
 	[bookworm] - cpanminus <no-dsa> (Minor issue)
+	[bullseye] - cpanminus <postponed> (Minor issue)
 	NOTE: https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
 	NOTE: https://github.com/miyagawa/cpanminus/issues/611
 	NOTE: https://github.com/miyagawa/cpanminus/pull/674



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/06081111dff54f3a79413e6c9a0a4f1f9a1fdf49...4f5f2f281c64c9ee10f0beddbea3173180d9e75b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/06081111dff54f3a79413e6c9a0a4f1f9a1fdf49...4f5f2f281c64c9ee10f0beddbea3173180d9e75b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240915/89344669/attachment.htm>


More information about the debian-security-tracker-commits mailing list