[Git][security-tracker-team/security-tracker][master] 5 commits: CVE-2025-23217,mitmproxy: bullseye is postponed

Markus Koschany (@apo) apo at debian.org
Sun Feb 9 09:16:55 GMT 2025



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
49321340 by Markus Koschany at 2025-02-09T09:28:44+01:00
CVE-2025-23217,mitmproxy: bullseye is postponed

Minor issue

- - - - -
1dc23f77 by Markus Koschany at 2025-02-09T09:33:50+01:00
CVE-2024-57965,node-axios: bullseye is postponed

Minor issue,disputed upstream.

- - - - -
5fc540c6 by Markus Koschany at 2025-02-09T09:38:36+01:00
Add phpmyadmin to dla-needed.txt

- - - - -
2fe113b4 by Markus Koschany at 2025-02-09T09:40:14+01:00
CVE-2025-0938,pypy3: bullseye is postponed

Minor issue

- - - - -
4620b0e5 by Markus Koschany at 2025-02-09T10:16:21+01:00
Add thunderbird to dla-needed.txt with notes

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -338,6 +338,7 @@ CVE-2025-24786 (WhoDB is an open source database management tool. While the appl
 CVE-2025-23217 (mitmproxy is a interactive TLS-capable intercepting HTTP proxy for pen ...)
 	- mitmproxy <unfixed>
 	[bookworm] - mitmproxy <no-dsa> (Minor issue)
+	[bullseye] - mitmproxy <postponed> (Minor issue)
 	NOTE: https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-wg33-5h85-7q5p
 CVE-2025-22992 (A SQL Injection vulnerability exists in the /feed/insert.json endpoint ...)
 	NOT-FOR-US: Emoncms
@@ -1662,6 +1663,7 @@ CVE-2025-0938 (The Python standard library functions `urllib.parse.urlsplit` and
 	- python3.9 <removed>
 	- pypy3 <unfixed>
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
+	[bullseye] - pypy3 <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/
 	NOTE: https://github.com/python/cpython/issues/105704
 	NOTE: https://github.com/python/cpython/pull/129418
@@ -2295,6 +2297,7 @@ CVE-2025-0353 (The Divi Torque Lite \u2013 Best Divi Addon, Extensions, Modules
 CVE-2024-57965 (In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a U ...)
 	- node-axios 1.7.9+dfsg-1 (bug #1094731)
 	[bookworm] - node-axios <no-dsa> (Minor issue)
+	[bullseye] - node-axios <postponed> (Minor issue)
 	NOTE: https://github.com/axios/axios/issues/6351
 	NOTE: https://github.com/axios/axios/commit/0a8d6e19da5b9899a2abafaaa06a75ee548597db (v1.7.8)
 	NOTE: https://github.com/axios/axios/pull/6714


=====================================
data/dla-needed.txt
=====================================
@@ -205,6 +205,9 @@ pgagent
 php-nesbot-carbon
   NOTE: 20250119: Added by Front-Desk (rouca)
 --
+phpmyadmin
+  NOTE: 20250209: Added by Front-Desk (apo)
+--
 qemu (santiago)
   NOTE: 20240815: Added by Front-Desk (Beuc)
   NOTE: 20240815: Follow fixes from bookworm 12.4 (CVE-2023-5088)
@@ -265,6 +268,11 @@ tcpdf (Adrian Bunk)
   NOTE: 20241205: Added by Front-Desk (santiago)
   NOTE: 20241230: https://lists.debian.org/debian-lts/2024/12/msg00057.html (bunk)
 --
+thunderbird
+  NOTE: 20250209: Added by Front-Desk (apo)
+  NOTE: 20250209: We have two open issues which are fixed in bookworm but not
+  NOTE: 20250209: in bullseye. Was that an oversight? (apo)
+--
 trafficserver (dleidert)
   NOTE: 20241120: Added by Front-Desk (Beuc)
   NOTE: 20241120: Upcoming DSA (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb126c741fd4d289f53750d4015ea5aea7deeca0...4620b0e5f5be8c5005f92df792d190c28c26ffda

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cb126c741fd4d289f53750d4015ea5aea7deeca0...4620b0e5f5be8c5005f92df792d190c28c26ffda
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250209/c787ea00/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list