[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-2603/libcap2 is vulnerable in bullseye; now pending update. Thanks,...

Chris Lamb (@lamby) lamby at debian.org
Mon Mar 24 16:50:43 GMT 2025



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
14c40fdc by Chris Lamb at 2025-03-24T16:50:02+00:00
CVE-2023-2603/libcap2 is vulnerable in bullseye; now pending update. Thanks, Salvatore and Marc Deslauriers.

- - - - -
bbf74175 by Chris Lamb at 2025-03-24T16:50:06+00:00
data/dla-needed.txt: Claim phpmyadmin.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -161611,7 +161611,6 @@ CVE-2023-2671 (A vulnerability was found in SourceCodester Lost and Found Inform
 	NOT-FOR-US: SourceCodester Lost and Found Information System
 CVE-2023-2603 (A vulnerability was found in libcap. This issue occurs in the _libcap_ ...)
 	- libcap2 1:2.66-4 (bug #1036114)
-	[bullseye] - libcap2 <not-affected> (Vulnerable code introduced later)
 	[buster] - libcap2 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.iuvg7sbjg8pe
 	NOTE: https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf


=====================================
data/dla-needed.txt
=====================================
@@ -228,7 +228,7 @@ php-twig
   NOTE: 20250209: Added by Front-Desk (apo)
   NOTE: 20250209: Vulnerable code is in src/Node/Expression/NullCoalesceExpression.php (apo)
 --
-phpmyadmin
+phpmyadmin (Chris Lamb)
   NOTE: 20250209: Added by Front-Desk (apo)
   NOTE: 20250219: Packaged prepared on salsa. (lamby)
   NOTE: 20250306: Checking some postponed issues. (lamby)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b1868c484de92a7705b8a10f28d553c591584d0a...bbf7417512699ae176fc7d437f9da1c9e8c4e12b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b1868c484de92a7705b8a10f28d553c591584d0a...bbf7417512699ae176fc7d437f9da1c9e8c4e12b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250324/dd2df93a/attachment.htm>


More information about the debian-security-tracker-commits mailing list