[Git][security-tracker-team/security-tracker][master] Update status for CVE-2024-7776 and CVE-2024-5187
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Apr 10 17:12:03 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
53edc733 by Salvatore Bonaccorso at 2025-04-10T18:08:37+02:00
Update status for CVE-2024-7776 and CVE-2024-5187
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -8000,10 +8000,9 @@ CVE-2024-7776 (A vulnerability in the `download_model` function of the onnx/onnx
NOTE: https://huntr.com/bounties/a7a46cf6-1fa-454b-988c-62d222e83f63
NOTE: https://github.com/onnx/onnx/issues/6215
NOTE: https://github.com/onnx/onnx/pull/6222
- NOTE: Follow-up to CVE-2024-5187
+ NOTE: Follow-up to CVE-2024-5187 but different vulnerability in the download_model function
NOTE: https://github.com/onnx/onnx/commit/1b70f9b673259360b6a2339c4bd97db9ea6e552f (v1.17.0)
NOTE: cherry picks of fixes: https://github.com/onnx/onnx/commit/84051888d0943883a0edbf683f68c05ca3b28c40 (v1.16.2)
- NOTE: Introduced by: https://github.com/onnx/onnx/commit/474c0b64ccd913101c4dc7108b3dea4fd1f51de8 (v1.14.0)
CVE-2024-7773 (A vulnerability in ollama/ollama version 0.1.37 allows for remote code ...)
- ollama <itp> (bug #1094806)
CVE-2024-7771 (A vulnerability in the Dockerized version of mintplex-labs/anything-ll ...)
@@ -88385,7 +88384,7 @@ CVE-2024-5188 (The Essential Addons for Elementor \u2013 Best Elementor Template
NOT-FOR-US: WordPress plugin
CVE-2024-5187 (A vulnerability in the `download_model_with_test_data` function of the ...)
- onnx 1.16.2-1 (bug #1075852)
- [bookworm] - onnx <no-dsa> (Minor issue)
+ [bookworm] - onnx <not-affected> (Vulnerable code introduced later)
[bullseye] - onnx <not-affected> (Vulnerable code introduced later)
NOTE: https://huntr.com/bounties/50235ebd-3410-4ada-b064-1a648e11237e
NOTE: https://github.com/onnx/onnx/pull/6164
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53edc7330872ba2f70fbbf8b6203f09f9806adb1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53edc7330872ba2f70fbbf8b6203f09f9806adb1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250410/7786a979/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list