[Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2025-31672 as postponed

Thorsten Alteholz (@alteholz) alteholz at debian.org
Mon Apr 21 00:04:08 BST 2025



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e1c26641 by Thorsten Alteholz at 2025-04-21T01:03:45+02:00
mark CVE-2025-31672 as postponed

- - - - -
f4718086 by Thorsten Alteholz at 2025-04-21T01:03:45+02:00
add webpy

- - - - -
45a9004c by Thorsten Alteholz at 2025-04-21T01:03:47+02:00
mark CVE-2025-3155 as postponed for Bullseye

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -4372,6 +4372,7 @@ CVE-2025-32460 (GraphicsMagick before 8e56520 has a heap-based buffer over-read
 	NOTE: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/8e56520435df50f618a03f2721a39a70a515f1cb
 CVE-2025-31672 (Improper Input Validation vulnerability in Apache POI. The issue affec ...)
 	- libapache-poi-java <unfixed> (bug #1103629)
+	[bullseye] - libapache-poi-java <postponed> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/04/08/2
 	NOTE: https://bz.apache.org/bugzilla/show_bug.cgi?id=69620
 CVE-2025-31344 (Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. ...)
@@ -5693,6 +5694,7 @@ CVE-2025-3157 (A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. I
 	NOT-FOR-US: Intelbras WRN
 CVE-2025-3155 (A flaw was found in Yelp. The Gnome user help application allows the h ...)
 	- yelp <unfixed> (bug #1102080)
+	[bullseye] - yelp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2357091
 	NOTE: https://www.openwall.com/lists/oss-security/2025/04/04/1
 	NOTE: https://gitlab.gnome.org/GNOME/yelp/-/issues/221


=====================================
data/dla-needed.txt
=====================================
@@ -326,6 +326,10 @@ webkit2gtk (Emilio)
   NOTE: 20250407: reverted various dependency bumps, fixed out-of-tree build,
   NOTE: 20250407: still working on getting the build finished but it's looking promising (Emilio)
 --
+webpy
+  NOTE: 20250421: Added by Front-Desk (ta)
+  NOTE: 20250421: not yet fixed upstream
+--
 wget (Adrian Bunk)
   NOTE: 20250409: Added by Front-Desk (Beuc)
   NOTE: 20250409: Follow fixes from bookworm 12.10 (CVE-2024-38428)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa5c9d2791aa060384e2de76356f277193a40259...45a9004c420f8e59051d7a927e03e0d392159d6e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa5c9d2791aa060384e2de76356f277193a40259...45a9004c420f8e59051d7a927e03e0d392159d6e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250420/ed33d8e0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list