[Git][security-tracker-team/security-tracker][master] new exiftags non issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 20 09:48:10 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2db5c027 by Moritz Muehlenhoff at 2024-09-20T10:47:48+02:00
new exiftags non issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5093,7 +5093,9 @@ CVE-2024-43783 (The Apollo Router Core is a configurable, high-performance graph
 CVE-2024-43414 (Apollo Federation is an architecture for declaratively composing APIs  ...)
 	NOT-FOR-US: Apollo Federation
 CVE-2024-42851 (Buffer Overflow vulnerability in open source exiftags v.1.01 allows a  ...)
-	TODO: check
+	- exiftags <unfixed> (unimportant)
+	NOTE: Crash in CLI tool, no security impact
+	NOTE: https://github.com/T1anyang/fuzzing/blob/main/exiftags/crash.md
 CVE-2024-41622 (D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command ...)
 	NOT-FOR-US: D-Link
 CVE-2024-40395 (An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 all ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2db5c027910b0c1e43553da340c2a8fe7b211143

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2db5c027910b0c1e43553da340c2a8fe7b211143
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240920/a9290ca0/attachment.htm>


More information about the debian-security-tracker-commits mailing list