[Git][security-tracker-team/security-tracker][master] Update status for CVE-2024-7776 and CVE-2024-5187

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Apr 10 17:12:03 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
53edc733 by Salvatore Bonaccorso at 2025-04-10T18:08:37+02:00
Update status for CVE-2024-7776 and CVE-2024-5187

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8000,10 +8000,9 @@ CVE-2024-7776 (A vulnerability in the `download_model` function of the onnx/onnx
 	NOTE: https://huntr.com/bounties/a7a46cf6-1fa-454b-988c-62d222e83f63
 	NOTE: https://github.com/onnx/onnx/issues/6215
 	NOTE: https://github.com/onnx/onnx/pull/6222
-	NOTE: Follow-up to CVE-2024-5187
+	NOTE: Follow-up to CVE-2024-5187 but different vulnerability in the download_model function
 	NOTE: https://github.com/onnx/onnx/commit/1b70f9b673259360b6a2339c4bd97db9ea6e552f (v1.17.0)
 	NOTE: cherry picks of fixes: https://github.com/onnx/onnx/commit/84051888d0943883a0edbf683f68c05ca3b28c40 (v1.16.2)
-	NOTE: Introduced by: https://github.com/onnx/onnx/commit/474c0b64ccd913101c4dc7108b3dea4fd1f51de8 (v1.14.0)
 CVE-2024-7773 (A vulnerability in ollama/ollama version 0.1.37 allows for remote code ...)
 	- ollama <itp> (bug #1094806)
 CVE-2024-7771 (A vulnerability in the Dockerized version of mintplex-labs/anything-ll ...)
@@ -88385,7 +88384,7 @@ CVE-2024-5188 (The Essential Addons for Elementor \u2013 Best Elementor Template
 	NOT-FOR-US: WordPress plugin
 CVE-2024-5187 (A vulnerability in the `download_model_with_test_data` function of the ...)
 	- onnx 1.16.2-1 (bug #1075852)
-	[bookworm] - onnx <no-dsa> (Minor issue)
+	[bookworm] - onnx <not-affected> (Vulnerable code introduced later)
 	[bullseye] - onnx <not-affected> (Vulnerable code introduced later)
 	NOTE: https://huntr.com/bounties/50235ebd-3410-4ada-b064-1a648e11237e
 	NOTE: https://github.com/onnx/onnx/pull/6164



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53edc7330872ba2f70fbbf8b6203f09f9806adb1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53edc7330872ba2f70fbbf8b6203f09f9806adb1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250410/7786a979/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list