[Git][security-tracker-team/security-tracker][master] 4 commits: add ipmctl

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Jan 12 00:09:23 GMT 2025



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2280e222 by Thorsten Alteholz at 2025-01-12T00:44:47+01:00
add ipmctl

- - - - -
86f3a8ad by Thorsten Alteholz at 2025-01-12T00:48:21+01:00
add suricata

- - - - -
574fe505 by Thorsten Alteholz at 2025-01-12T00:56:59+01:00
mark CVE-2025-23016 as postponed for Bullseye

- - - - -
386135c6 by Thorsten Alteholz at 2025-01-12T01:09:05+01:00
mark CVE-2024-57822 as postponed for Bullseye

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -327,6 +327,7 @@ CVE-2025-23022 (FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cf
 	NOTE: https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312
 CVE-2025-23016 (FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (an ...)
 	- libfcgi <unfixed> (bug #1092774)
+	[bullseye] - libfcgi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/FastCGI-Archives/fcgi2/issues/67
 CVE-2025-22949 (Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injectio ...)
 	NOT-FOR-US: Tenda
@@ -384,6 +385,7 @@ CVE-2024-57823 (In Raptor RDF Syntax Library through 2.0.16, there is an integer
 	NOTE: https://github.com/dajobe/raptor/issues/70
 CVE-2024-57822 (In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buf ...)
 	- raptor2 <unfixed> (bug #1067896)
+	[bullseye] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md
 	NOTE: https://github.com/dajobe/raptor/issues/70
 CVE-2024-57687 (An OS Command Injection vulnerability was found in /landrecordsys/admi ...)


=====================================
data/dla-needed.txt
=====================================
@@ -127,6 +127,9 @@ gst-plugins-good1.0 (Adrian Bunk)
 iperf3 (Markus Koschany)
   NOTE: 20250106: Added by Front-Desk (apo)
 --
+ipmctl
+  NOTE: 20250112: Added by Front-Desk (ta)
+--
 jetty9 (Markus Koschany)
   NOTE: 20241110: Added by Front-Desk (apo)
 --
@@ -217,6 +220,9 @@ squid
   NOTE: 20240930: Backported most patches, help will be needed with CVE-2024-25111 and CVE-2023-46846 (roberto)
   NOTE: 20241028: Sorted out all the patch backports. Still need to test (roberto)
 --
+suricata
+  NOTE: 20250112: Added by Front-Desk (ta)
+--
 symfony
   NOTE: 20241110: Added by Front-Desk (apo)
   NOTE: 20241120: Follow fixes from DSA-5809-1 and DSA-5813-1 (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a8d796b6d7f729391d79c55acaa515caba6b813d...386135c6e130c92fc5d164c62bf25bcaaecad09d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a8d796b6d7f729391d79c55acaa515caba6b813d...386135c6e130c92fc5d164c62bf25bcaaecad09d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250112/6bfd00e3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list