[Git][security-tracker-team/security-tracker][master] Add CVE-2025-58066/rust-ntpd
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 30 09:34:10 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c9f0edb7 by Salvatore Bonaccorso at 2025-08-30T10:33:23+02:00
Add CVE-2025-58066/rust-ntpd
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -35,7 +35,9 @@ CVE-2025-58068 (Eventlet is a concurrent networking library for Python. Prior to
CVE-2025-58067 (Basecamp's Google Sign-In adds Google sign-in to Rails applications. P ...)
NOT-FOR-US: Basecamp's Google Sign-In
CVE-2025-58066 (nptd-rs is a tool for synchronizing your computer's clock, implementin ...)
- TODO: check
+ - rust-ntpd <unfixed>
+ NOTE: https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4
+ NOTE: Fixed by: https://github.com/pendulum-project/ntpd-rs/commit/da37cf167736cbd4d7804b1ed7ceb572468298e0 (v1.6.2)
CVE-2025-57822 (Next.js is a React framework for building full-stack web applications. ...)
NOT-FOR-US: Next.js
CVE-2025-57752 (Next.js is a React framework for building full-stack web applications. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9f0edb7d7ca0bfed359ef12762c4322e65ad752
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9f0edb7d7ca0bfed359ef12762c4322e65ad752
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250830/d9c56edd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list