[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-26306,iperf3: link to fixing commit
Markus Koschany (@apo)
apo at debian.org
Tue Jan 28 12:46:46 GMT 2025
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3a67ffad by Markus Koschany at 2025-01-28T12:04:51+01:00
CVE-2024-26306,iperf3: link to fixing commit
- - - - -
9c86f89f by Markus Koschany at 2025-01-28T13:46:34+01:00
Reserve DLA-4032-1 for iperf3
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -73235,8 +73235,8 @@ CVE-2024-29212 (Due to an unsafe de-serialization method used by the Veeam Serv
CVE-2024-26306 (iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server wi ...)
- iperf3 3.17.1-1 (bug #1071751)
[bookworm] - iperf3 <ignored> (Minor issue)
- [bullseye] - iperf3 <no-dsa> (Minor issue)
[buster] - iperf3 <postponed> (Minor issue; can be fixed in next update)
+ NOTE: Fixed by https://github.com/esnet/iperf/commit/299b356df6939f71619bf45bf7a7d2222e17d840
CVE-2023-5052 (vulnerability in Uniform Server Zero, version 10.2.5, consisting of an ...)
NOT-FOR-US: Uniform Zero Server
CVE-2024-4799 (A vulnerability, which was classified as critical, was found in Kaship ...)
@@ -136405,7 +136405,6 @@ CVE-2023-38404 (The XPRTLD web application in Veritas InfoScale Operations Manag
CVE-2023-7250 (A flaw was found in iperf, a utility for testing network performance u ...)
- iperf3 3.15-1
[bookworm] - iperf3 <ignored> (Minor issue)
- [bullseye] - iperf3 <no-dsa> (Minor issue)
[buster] - iperf3 <no-dsa> (Minor issue)
NOTE: https://downloads.es.net/pub/iperf/esnet-secadv-2023-0002.txt.asc
NOTE: https://github.com/esnet/iperf/commit/5e3704dd850a5df2fb2b3eafd117963d017d07b4 (3.15)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[28 Jan 2025] DLA-4032-1 iperf3 - security update
+ {CVE-2023-7250 CVE-2024-26306 CVE-2024-53580}
+ [bullseye] - iperf3 3.9-1+deb11u2
[28 Jan 2025] DLA-4031-1 git - security update
{CVE-2024-50349 CVE-2024-52006}
[bullseye] - git 1:2.30.2-1+deb11u4
=====================================
data/dla-needed.txt
=====================================
@@ -117,9 +117,6 @@ gst-plugins-good1.0 (Adrian Bunk)
NOTE: 20241213: Added by Front-Desk (lamby)
NOTE: 20241213: See also gst-plugins-base1.0 (lamby)
--
-iperf3 (Markus Koschany)
- NOTE: 20250106: Added by Front-Desk (apo)
---
ipmctl
NOTE: 20250112: Added by Front-Desk (ta)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/488c9f2f5da9353e7c1ba35e0b54393075c5cd8a...9c86f89f2b85ef1caaa3db81368a7c37f92e600d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/488c9f2f5da9353e7c1ba35e0b54393075c5cd8a...9c86f89f2b85ef1caaa3db81368a7c37f92e600d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250128/7f4bc2a7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list