[Git][security-tracker-team/security-tracker][master] (for LTS) postpone CVE-2023-42366/busybox and ignore CVE-2023-42363/busybox
Tobias Frost (@tobi)
tobi at debian.org
Sun Jan 19 08:48:50 GMT 2025
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker
Commits:
21d91818 by Tobias Frost at 2025-01-19T09:46:28+01:00
(for LTS) postpone CVE-2023-42366/busybox and ignore CVE-2023-42363/busybox
See https://lists.debian.org/debian-lts/2025/01/msg00013.html and
https://lists.debian.org/debian-lts/2025/01/msg00014.html
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -113210,8 +113210,8 @@ CVE-2023-46349 (In the module "Product Catalog (CSV, Excel) Export/Update" (upda
CVE-2023-42366 (A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_ ...)
- busybox <unfixed> (bug #1059053)
[bookworm] - busybox <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - busybox <no-dsa> (Minor issue)
- [buster] - busybox <no-dsa> (Minor issue)
+ [bullseye] - busybox <postponed> (Minor issue)
+ [buster] - busybox <postponed> (Minor issue)
NOTE: https://bugs.busybox.net/show_bug.cgi?id=15874
CVE-2023-42365 (A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via ...)
- busybox 1:1.37.0-1 (bug #1059052)
@@ -113234,8 +113234,8 @@ CVE-2023-42364 (A use-after-free vulnerability in BusyBox v.1.36.1 allows attack
CVE-2023-42363 (A use-after-free vulnerability was discovered in xasprintf function in ...)
- busybox 1:1.37.0-1 (bug #1059050)
[bookworm] - busybox <no-dsa> (Minor issue)
- [bullseye] - busybox <no-dsa> (Minor issue)
- [buster] - busybox <no-dsa> (Minor issue)
+ [bullseye] - busybox <ignored> (Minor issue)
+ [buster] - busybox <ignored> (Minor issue)
NOTE: https://bugs.busybox.net/show_bug.cgi?id=15865
NOTE: The above ticket contains a poc, poc triggers on bookworm but not on bullseye.
NOTE: The poc starts triggering with https://git.busybox.net/busybox/commit/?id=a885ce1af05c4eaa5ebcf883cb3da3433ca1c48b (1_34_0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21d91818061eb924117d0f7a7c84c45ee10305a0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21d91818061eb924117d0f7a7c84c45ee10305a0
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250119/14053a8a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list