[Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2025-31672 as postponed
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Mon Apr 21 00:04:08 BST 2025
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e1c26641 by Thorsten Alteholz at 2025-04-21T01:03:45+02:00
mark CVE-2025-31672 as postponed
- - - - -
f4718086 by Thorsten Alteholz at 2025-04-21T01:03:45+02:00
add webpy
- - - - -
45a9004c by Thorsten Alteholz at 2025-04-21T01:03:47+02:00
mark CVE-2025-3155 as postponed for Bullseye
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -4372,6 +4372,7 @@ CVE-2025-32460 (GraphicsMagick before 8e56520 has a heap-based buffer over-read
NOTE: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/8e56520435df50f618a03f2721a39a70a515f1cb
CVE-2025-31672 (Improper Input Validation vulnerability in Apache POI. The issue affec ...)
- libapache-poi-java <unfixed> (bug #1103629)
+ [bullseye] - libapache-poi-java <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2025/04/08/2
NOTE: https://bz.apache.org/bugzilla/show_bug.cgi?id=69620
CVE-2025-31344 (Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. ...)
@@ -5693,6 +5694,7 @@ CVE-2025-3157 (A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. I
NOT-FOR-US: Intelbras WRN
CVE-2025-3155 (A flaw was found in Yelp. The Gnome user help application allows the h ...)
- yelp <unfixed> (bug #1102080)
+ [bullseye] - yelp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2357091
NOTE: https://www.openwall.com/lists/oss-security/2025/04/04/1
NOTE: https://gitlab.gnome.org/GNOME/yelp/-/issues/221
=====================================
data/dla-needed.txt
=====================================
@@ -326,6 +326,10 @@ webkit2gtk (Emilio)
NOTE: 20250407: reverted various dependency bumps, fixed out-of-tree build,
NOTE: 20250407: still working on getting the build finished but it's looking promising (Emilio)
--
+webpy
+ NOTE: 20250421: Added by Front-Desk (ta)
+ NOTE: 20250421: not yet fixed upstream
+--
wget (Adrian Bunk)
NOTE: 20250409: Added by Front-Desk (Beuc)
NOTE: 20250409: Follow fixes from bookworm 12.10 (CVE-2024-38428)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa5c9d2791aa060384e2de76356f277193a40259...45a9004c420f8e59051d7a927e03e0d392159d6e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fa5c9d2791aa060384e2de76356f277193a40259...45a9004c420f8e59051d7a927e03e0d392159d6e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250420/ed33d8e0/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list