[Git][security-tracker-team/security-tracker][master] mark CVE-2023-51847 as not-affected in Bullseye, Bookworm, Trixie

Thorsten Alteholz (@alteholz) alteholz at debian.org
Wed Aug 27 08:52:44 BST 2025



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
04741838 by Thorsten Alteholz at 2025-08-27T09:52:33+02:00
mark CVE-2023-51847 as not-affected in Bullseye, Bookworm, Trixie

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -131006,14 +131006,15 @@ CVE-2023-6491 (The Strong Testimonials plugin for WordPress is vulnerable to una
 	NOT-FOR-US: WordPress plugin
 CVE-2023-51847 (An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cau ...)
 	- libcoap3 4.3.5-1 (bug #1084981)
-	[trixie] - libcoap3 <ignored> (Minor issue, no reverse deps in trixie)
-	[bookworm] - libcoap3 <ignored> (Minor issue, no reverse deps in Bookworm)
+	[trixie] - libcoap3 <not-affected> (Vulnerable code introduced in v4.3.5-rc1)
+	[bookworm] - libcoap3 <not-affected> (Vulnerable code introduced in v4.3.5-rc1)
 	- libcoap2 <removed>
-	[bullseye] - libcoap2 <postponed> (Minor issue; can be fixed in next update)
+	[bullseye] - libcoap2 <not-affected> (Vulnerable code introduced in v4.3.5-rc1)
 	- libcoap <removed>
 	NOTE: https://github.com/obgm/libcoap/issues/1302
 	NOTE: https://github.com/obgm/libcoap/pull/1303
 	NOTE: https://github.com/obgm/libcoap/commit/e7105286f6cac3afdbf03c307ecb480d9a7d511c (v4.3.5-rc1)
+	NOTE: introduced by https://github.com/obgm/libcoap/commit/c69c5d5af0a30859e90756f535e2ca21cdeda0b2 (v4.3.5-rc1)
 CVE-2023-49441 (dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.)
 	- dnsmasq 2.90-1 (unimportant)
 	NOTE: https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2023q4/017334.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/047418382db69e9469cfeae328bd06afeaf395cb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/047418382db69e9469cfeae328bd06afeaf395cb
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250827/7bba497b/attachment.htm>


More information about the debian-security-tracker-commits mailing list