[Git][security-tracker-team/security-tracker][master] 3 commits: add catdoc
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Thu Jun 5 22:37:15 BST 2025
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b86ff3aa by Thorsten Alteholz at 2025-06-05T23:22:15+02:00
add catdoc
- - - - -
44821199 by Thorsten Alteholz at 2025-06-05T23:25:08+02:00
add modsecurity-apache
- - - - -
780060fe by Thorsten Alteholz at 2025-06-05T23:33:38+02:00
mark some CVEs of python3.9 as not-affected
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -607,6 +607,7 @@ CVE-2025-4517 (Allows arbitrary filesystem writes outside the extraction directo
- python3.12 <unfixed>
- python3.11 <removed>
- python3.9 <removed>
+ [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 3.12)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
- jython <unfixed>
@@ -624,6 +625,7 @@ CVE-2025-4435 (When using a TarFile.errorlevel = 0and extracting with a filter t
- python3.12 <unfixed>
- python3.11 <removed>
- python3.9 <removed>
+ [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 3.12)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
- jython <unfixed>
@@ -645,6 +647,7 @@ CVE-2025-4330 (Allows the extraction filter to be ignored, allowing symlink targ
- python3.12 <unfixed>
- python3.11 <removed>
- python3.9 <removed>
+ [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 3.12)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
- jython <unfixed>
@@ -664,6 +667,7 @@ CVE-2025-4138 (Allows the extraction filter to be ignored, allowing symlink targ
- python3.12 <unfixed>
- python3.11 <removed>
- python3.9 <removed>
+ [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 3.12)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
- jython <unfixed>
@@ -763,6 +767,7 @@ CVE-2024-12718 (Allows modifying some file metadata (e.g. last modified) with fi
- python3.12 <unfixed>
- python3.11 <removed>
- python3.9 <removed>
+ [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 3.12)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
- jython <unfixed>
=====================================
data/dla-needed.txt
=====================================
@@ -55,6 +55,9 @@ busybox
NOTE: 20250425: Added by Front-Desk (rouca)
NOTE: 20250519: Asked maintainers about any pending work and offered help. (spwhitton)
--
+catdoc
+ NOTE: 20250605: Added by Front-Desk (ta)
+--
ceph
NOTE: 20241205: Added by Front-Desk (santiago)
NOTE: 20241205: maintainer is preparing an update: https://lists.debian.org/debian-lts/2024/12/msg00008.html (santiago/front-desk)
@@ -211,6 +214,9 @@ mina2
NOTE: 20250114: Patches for CVE-2024-52046 https://github.com/apache/mina/commit/f9cc5ada6ebef4ee7cc51aac824e42e2e422310e (2.2.4) and ... (dleidert)
NOTE: 20250114: ... https://github.com/apache/mina/commit/cdb59eb6131696a440870ab89ad0e20804eb5ca7 (2.1.10) (dleidert)
--
+modsecurity-apache
+ NOTE: 20250605: Added by Front-Desk (ta)
+--
nagvis
NOTE: 20250117: Added by Front-Desk (rouca)
NOTE: 20250119: Also check/fix https://bugs.debian.org/1061044
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aecc2f87d3e04c570232a2b417eee61dbde40c57...780060fe6c86f949d9b937e016cf8e07c915b5ff
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aecc2f87d3e04c570232a2b417eee61dbde40c57...780060fe6c86f949d9b937e016cf8e07c915b5ff
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250605/c643a970/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list