[Git][security-tracker-team/security-tracker][master] 2 commits: Sync some NOTE format with current practice
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 05:11:01 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9d20d4f3 by Salvatore Bonaccorso at 2026-08-14T06:04:35+02:00
Sync some NOTE format with current practice
- - - - -
783cc5b9 by Salvatore Bonaccorso at 2026-08-14T06:09:51+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,25 +1,25 @@
CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open redirect ...)
- TODO: check
+ NOT-FOR-US: Saurus CMS
CVE-2026-73670 (A CMS contains a SQL injection vulnerability in admin/db_data.php at l ...)
- TODO: check
+ NOT-FOR-US: Saurus CMS
CVE-2026-73653 (Vitest is a testing framework powered by Vite. Prior to versions 3.2.7 ...)
- TODO: check
+ NOT-FOR-US: Vitest
CVE-2026-73652 (vantage6 is an open-source infrastructure for privacy preserving analy ...)
- TODO: check
+ NOT-FOR-US: vantage6
CVE-2026-73651 (TypeORM is a TypeScript and JavaScript ORM for Node.js that supports P ...)
- TODO: check
+ NOT-FOR-US: TypeORM
CVE-2026-73650 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
TODO: check
CVE-2026-73649 (Velocity.js is a JavaScript implementation of the Apache Velocity temp ...)
- TODO: check
+ NOT-FOR-US: Velocity.js
CVE-2026-73648 (rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
TODO: check
CVE-2026-73647 (Quasar Framework is a framework for building high-performance Vue.js u ...)
- TODO: check
+ NOT-FOR-US: Quasar Framework
CVE-2026-73645 (OpenZeppelin Confidential Contracts is an experimental library for dev ...)
- TODO: check
+ NOT-FOR-US: OpenZeppelin
CVE-2026-73644 (OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the S ...)
- TODO: check
+ NOT-FOR-US: OpenDJ
CVE-2026-73643 (js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2 ...)
TODO: check
CVE-2026-73629 (Serendipity before 2.6.0 contains a server-side request forgery vulner ...)
@@ -13086,7 +13086,7 @@ CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterat
CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
- NOTE: Fixed by https://github.com/nodejs/node/commit/daa6d25e3dceb30edb832a778ec0610c8bc2dd12 (v22.23.2)
+ NOTE: Fixed by: https://github.com/nodejs/node/commit/daa6d25e3dceb30edb832a778ec0610c8bc2dd12 (v22.23.2)
CVE-2026-56846 (A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blo ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high
@@ -13213,7 +13213,7 @@ CVE-2026-56847 (A flaw in Node.js Permission Model enforcement allows `trace_eve
[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-trace-events-to-write-outside-the-allowlist-cve-2026-56847---low
- NOTE: Fixed by https://github.com/nodejs/node/commit/0566c3cccdc99b935646e813f71e2380aedee50d (v22.23.2)
+ NOTE: Fixed by: https://github.com/nodejs/node/commit/0566c3cccdc99b935646e813f71e2380aedee50d (v22.23.2)
CVE-2026-54249 (Pydantic AI is a Python agent framework for building Generative AI app ...)
NOT-FOR-US: Pydantic AI
CVE-2026-50782 (Jinher OA C6 contains an XML External Entity (XXE) injection vulnerabi ...)
@@ -49787,7 +49787,7 @@ CVE-2026-44663 (OpenEXR is the reference implementation and specification for th
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-777r-f9x8-7r84
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2403
NOTE: Introduced by https://github.com/AcademySoftwareFoundation/openexr/commit/50ba96b1dbe353a98a626c7fd0ff1e50cc8c188f (v3.4-alpha)
- NOTE: Fixed by https://github.com/AcademySoftwareFoundation/openexr/commit/3e2a99a55b1ee3dc5b962bf2cfde86eb24cc6897 (v3.4.13-rc)
+ NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/3e2a99a55b1ee3dc5b962bf2cfde86eb24cc6897 (v3.4.13-rc)
CVE-2026-43994 (Coturn is a free open source implementation of TURN and STUN Server. V ...)
- coturn 4.12.0-1 (bug #1140563)
[trixie] - coturn <no-dsa> (Minor issue)
@@ -80012,7 +80012,7 @@ CVE-2026-42285 (GoBGP is an open source Border Gateway Protocol (BGP) implementa
[bookworm] - gobgp <not-affected> (Vulnerable code not present, introduced in 4.4.0)
[bullseye] - gobgp <not-affected> (Vulnerable code not present, introduced in 4.4.0)
NOTE: https://github.com/osrg/gobgp/security/advisories/GHSA-p3w2-64xm-833j
- NOTE: Fixed by https://github.com/osrg/gobgp/commit/d2d2be3e4e7915d407e662e5d388d9f8ae8a8f7b (v4.5.0)
+ NOTE: Fixed by: https://github.com/osrg/gobgp/commit/d2d2be3e4e7915d407e662e5d388d9f8ae8a8f7b (v4.5.0)
CVE-2026-42214 (Notepad Next is a cross-platform, reimplementation of Notepad++. Prior ...)
NOT-FOR-US: Notepad Next
CVE-2026-41906 (FreeScout is a free help desk and shared inbox built with PHP's Larave ...)
@@ -210573,7 +210573,7 @@ CVE-2025-50200 (RabbitMQ is a messaging and streaming broker. In versions 3.13.7
[bookworm] - rabbitmq-server <not-affected> (vulnerable code introduced later)
[bullseye] - rabbitmq-server <not-affected> (vulnerable code introduced later)
NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gh3x-4x42-fvq8
- NOTE: Fixed by https://github.com/rabbitmq/rabbitmq-server/pull/13612
+ NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-server/pull/13612
NOTE: Introduced with: https://github.com/rabbitmq/rabbitmq-server/commit/383ddb16341200f63091e2dd8bb7c0c6346e3ef7 (v4.1.0-alpha)
NOTE: Introduced with (backport): https://github.com/rabbitmq/rabbitmq-server/commit/a4465d7a728a41dba125c6c0553f124b45dbb6bd (v3.13.2-rc.1)
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-server/commit/0a7c86b4807619b1ab52c18f091752d4f711d5b1 (v4.2.0-beta.1)
@@ -212768,7 +212768,7 @@ CVE-2025-6170 (A flaw was found in the interactive shell of the xmllint command-
[bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u3
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/941
NOTE: Crash in CLI tool, no security impact
- NOTE: Fixed by https://gitlab.gnome.org/GNOME/libxml2/-/commit/c340e419505cf4bf1d9ed7019a87cc00ec200434 (2.14)
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/c340e419505cf4bf1d9ed7019a87cc00ec200434 (2.14)
CVE-2025-6137 (A vulnerability classified as critical has been found in TOTOLINK T10 ...)
NOT-FOR-US: TOTOLINK
CVE-2025-6136 (A vulnerability was found in Projectworlds Life Insurance Management S ...)
@@ -224769,7 +224769,7 @@ CVE-2025-27533 (Memory Allocation with Excessive Size Value vulnerability in Apa
- activemq 5.17.6+dfsg-2 (bug #1104933)
[bookworm] - activemq <postponed> (Minor issue, DoS)
NOTE: https://issues.apache.org/jira/browse/AMQ-6596
- NOTE: Fixed by https://github.com/apache/activemq/pull/1399
+ NOTE: Fixed by: https://github.com/apache/activemq/pull/1399
CVE-2025-4372 (Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 all ...)
{DSA-5916-1}
- chromium 136.0.7103.92-1
@@ -233090,7 +233090,7 @@ CVE-2025-32700 (Exposure of Sensitive Information to an Unauthorized Actor vulne
[bullseye] - mediawiki <not-affected> (Vulnerable code introduced later)
NOTE: https://phabricator.wikimedia.org/T389235
NOTE: Introduced by https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1026560 (REL1_43)
- NOTE: Fixed by https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1135788
+ NOTE: Fixed by: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1135788
CVE-2025-32699 (Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation ...)
{DSA-5901-1 DLA-4249-1}
- mediawiki 1:1.43.1+dfsg-1
@@ -276068,7 +276068,7 @@ CVE-2024-42333 (The researcher is showing that it is possible to leak a small am
- zabbix 1:7.0.5+dfsg-1 (bug #1088689)
[bookworm] - zabbix <no-dsa> (Minor issue)
NOTE: https://support.zabbix.com/browse/ZBX-25629
- NOTE: Fixed by https://github.com/zabbix/zabbix/commit/72d2ce61872fcbace8f8dfdabc0568c99980989d (7.0.4rc1)
+ NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/72d2ce61872fcbace8f8dfdabc0568c99980989d (7.0.4rc1)
NOTE: Fixed by (merge commit) https://github.com/zabbix/zabbix/commit/c4ea57b823cb6a4c2cb0796f500e862fbb6a46ea (6.0.35rc1)
CVE-2024-42332 (The researcher is showing that due to the way the SNMP trap log is par ...)
{DLA-3984-1}
@@ -276118,7 +276118,7 @@ CVE-2024-42326 (There was discovered a use after free bug in browser.c in the es
[bookworm] - zabbix <not-affected> (Vulnerable code introduced later)
[bullseye] - zabbix <not-affected> (Vulnerable code introduced later)
NOTE: https://support.zabbix.com/browse/ZBX-25622
- NOTE: Fixed by https://github.com/zabbix/zabbix/commit/0b01b889fc1d47002e1cf9fa50d52a5cca5f1a97 (7.0.4rc1)
+ NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/0b01b889fc1d47002e1cf9fa50d52a5cca5f1a97 (7.0.4rc1)
NOTE: webdriver (browser.c) introduced with commit https://github.com/zabbix/zabbix/commit/4d22c15fe4499602e0da5399e3dd6dc9da03277b (7.0.0rc1)
CVE-2024-41126 (Contiki-NG is an open-source, cross-platform operating system for IoT ...)
NOT-FOR-US: Contiki-NG
@@ -283224,7 +283224,7 @@ CVE-2024-51990 (jj, or Jujutsu, is a Git-compatible VCS written in rust. In affe
CVE-2024-51736 (Symphony process is a module for the Symphony PHP framework which exec ...)
- symfony <not-affected> (Only affects Symfony on Windows)
NOTE: https://github.com/symfony/symfony/security/advisories/GHSA-qq5c-677p-737q
- NOTE: Fixed by https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9 (v5.4.46, v6.4.14, v7.1.7)
+ NOTE: Fixed by: https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9 (v5.4.46, v6.4.14, v7.1.7)
CVE-2024-51409 (Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote at ...)
NOT-FOR-US: Tenda
CVE-2024-50345 (symfony/http-foundation is a module for the Symphony PHP framework whi ...)
@@ -298931,8 +298931,8 @@ CVE-2024-8443 (A heap-based buffer overflow vulnerability was found in the libop
[bookworm] - opensc 0.23.0-0.3+deb12u2
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2310494
NOTE: https://github.com/OpenSC/OpenSC/wiki/CVE-2024-8443
- NOTE: Fixed by https://github.com/OpenSC/OpenSC/commit/02e847458369c08421fd2d5e9a16a5f272c2de9e (0.26.0-rc1)
- NOTE: Fixed by https://github.com/OpenSC/OpenSC/commit/b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc (0.26.0-rc1)
+ NOTE: Fixed by: https://github.com/OpenSC/OpenSC/commit/02e847458369c08421fd2d5e9a16a5f272c2de9e (0.26.0-rc1)
+ NOTE: Fixed by: https://github.com/OpenSC/OpenSC/commit/b28a3cef416fcfb92fbb9ea7fd3c71df52c6c9fc (0.26.0-rc1)
CVE-2024-8517 (SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command inje ...)
- spip 4.3.2+dfsg-1
[bullseye] - spip <not-affected> (bigup module not shipped in 3.x)
@@ -309911,7 +309911,7 @@ CVE-2024-41110 (Moby is an open-source project created by Docker for software co
[bookworm] - docker.io 20.10.24+dfsg1-1+deb12u1
NOTE: https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
NOTE: https://www.docker.com/blog/docker-security-advisory-docker-engine-authz-plugin/
- NOTE: Fixed by https://github.com/moby/moby/commit/88c4b7690840044ce15489699294ec7c5dadf5dd (20.10 branch)
+ NOTE: Fixed by: https://github.com/moby/moby/commit/88c4b7690840044ce15489699294ec7c5dadf5dd (20.10 branch)
NOTE: Follow-up: https://github.com/moby/moby/commit/7ff423cc1c991d8dc0a7b5d1d93e1cf3efaac169
CVE-2024-40575 (An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7. ...)
NOT-FOR-US: Huawei Technologies opengauss
@@ -315656,14 +315656,14 @@ CVE-2023-43554 (Memory corruption while processing IOCTL handler in FastRPC.)
CVE-2024-40898 (SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost ...)
- apache2 <not-affected> (Windows specific)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-40898
- NOTE: Fixed by https://github.com/apache/httpd/commit/9967bf49599f9be6eaaf9c5de5c84f15bb07df9f
+ NOTE: Fixed by: https://github.com/apache/httpd/commit/9967bf49599f9be6eaaf9c5de5c84f15bb07df9f
CVE-2024-40725 (A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4 ...)
- apache2 2.4.62-1
[bookworm] - apache2 2.4.62-1~deb12u1
[bullseye] - apache2 2.4.62-1~deb11u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-40725
NOTE: Introduced due to fix for CVE-2024-39884 (this CVE was fixed in 2.4.60)
- NOTE: Fixed by https://github.com/apache/httpd/commit/a7d24b4ea9a6ea35878fd33075365328caafcf91 (2.4.62)
+ NOTE: Fixed by: https://github.com/apache/httpd/commit/a7d24b4ea9a6ea35878fd33075365328caafcf91 (2.4.62)
NOTE: (or svn https://svn.apache.org/viewvc?view=revision&revision=1919249)
CVE-2024-39884 (A regression in the core of Apache HTTP Server 2.4.60 ignores some use ...)
- apache2 2.4.61-1
@@ -315689,7 +315689,7 @@ CVE-2024-38477 (null pointer dereference in mod_proxy in Apache HTTP Server 2.4.
{DSA-5729-1}
- apache2 2.4.60-1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-38477
- NOTE: Fixed by https://github.com/apache/httpd/commit/1d98d4db186e708f059336fb9342d0adb6925e85 (2.4.60)
+ NOTE: Fixed by: https://github.com/apache/httpd/commit/1d98d4db186e708f059336fb9342d0adb6925e85 (2.4.60)
NOTE: (or https://svn.apache.org/viewvc?view=revision&revision=1918607)
NOTE: Regression identified by Ubuntu https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2072648
NOTE: Regression fixed by: https://github.com/apache/httpd/commit/4d3a308014be26e5407113b4c827a1ea2882bf38 (2.4.60)
@@ -315697,8 +315697,8 @@ CVE-2024-38476 (Vulnerability in core of Apache HTTP Server 2.4.59 and earlier a
{DSA-5729-1}
- apache2 2.4.60-1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-38476
- NOTE: Fixed by https://github.com/apache/httpd/commit/925b6f0ceb8983a11662b5f3a6f2fa75860c2cde (trunk)
- NOTE: Fixed by https://github.com/apache/httpd/commit/554554b0ebb14d6578adb70a389c57a0d5f18a3b (2.4.60)
+ NOTE: Fixed by: https://github.com/apache/httpd/commit/925b6f0ceb8983a11662b5f3a6f2fa75860c2cde (trunk)
+ NOTE: Fixed by: https://github.com/apache/httpd/commit/554554b0ebb14d6578adb70a389c57a0d5f18a3b (2.4.60)
NOTE: (or https://svn.apache.org/viewvc?view=revision&revision=1918560)
NOTE: see also regression CVE-2024-39884 and CVE-2024-40725
CVE-2024-38475 (Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.5 ...)
@@ -340466,7 +340466,7 @@ CVE-2024-31585 (FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-
- ffmpeg 7:7.0.1-3
[bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
[buster] - ffmpeg <not-affected> (Vulnerable code not present)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/ab0fdaedd1e7224f7e84ea22fcbfaa4ca75a6c06 (n7.0)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/ab0fdaedd1e7224f7e84ea22fcbfaa4ca75a6c06 (n7.0)
NOTE: Introduced by https://github.com/FFmpeg/FFmpeg/commit/81df787b53eb5c6433731f6eaaf7f2a94d8a8c80 (n5.1)
CVE-2024-31583 (Pytorch before version v2.2.0 was discovered to contain a use-after-fr ...)
- pytorch 2.4.1-1 (bug #1070379)
@@ -340479,15 +340479,15 @@ CVE-2024-31582 (FFmpeg version n6.1 was discovered to contain a heap buffer over
- ffmpeg 7:7.0.1-3
[bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
[buster] - ffmpeg <not-affected> (Vulnerable code not present)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/99debe5f823f45a482e1dc08de35879aa9c74bd2 (n7.0)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/785a6df0e477f408c3e939a043b8608acf071964 (n5.1.7)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/99debe5f823f45a482e1dc08de35879aa9c74bd2 (n7.0)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/785a6df0e477f408c3e939a043b8608acf071964 (n5.1.7)
CVE-2024-31581 (FFmpeg version n6.1 was discovered to contain an improper validation o ...)
[experimental] - ffmpeg 7:7.0-1
- ffmpeg 7:7.0.1-3
[bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
[bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
[buster] - ffmpeg <not-affected> (Vulnerable code not present)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/ce0c178a408d43e71085c28a47d50dc939b60196 (n7.0)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/ce0c178a408d43e71085c28a47d50dc939b60196 (n7.0)
CVE-2024-31580 (PyTorch before v2.2.0 was discovered to contain a heap buffer overflow ...)
- pytorch 2.4.1-1 (bug #1070379)
[bookworm] - pytorch <ignored> (Minor issue)
@@ -340499,7 +340499,7 @@ CVE-2024-31578 (FFmpeg version n6.1.1 was discovered to contain a heap use-after
- ffmpeg 7:7.0.1-3
[bookworm] - ffmpeg <postponed> (Pick up when fixed in 5.1.x)
[buster] - ffmpeg <postponed> (Pick up when fixed in 4.3.x)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7 (n7.0)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7 (n7.0)
CVE-2024-31463 (Ironic-image is an OpenStack Ironic deployment packaged and configured ...)
NOT-FOR-US: ironic-image container image
CVE-2024-31041 (Null Pointer Dereference vulnerability in topic_filtern function in mq ...)
@@ -342703,7 +342703,7 @@ CVE-2023-49528 (Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4
[buster] - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://trac.ffmpeg.org/ticket/10691
NOTE: Introduced after: https://github.com/FFmpeg/FFmpeg/commit/f05c52985cf80d565c6e91fb4749e57dd8977d3e (n5.1)
- NOTE: Fixed by https://github.com/ffmpeg/ffmpeg/commit/2d9ed64859c9887d0504cd71dbd5b2c15e14251a (n7.0)
+ NOTE: Fixed by: https://github.com/ffmpeg/ffmpeg/commit/2d9ed64859c9887d0504cd71dbd5b2c15e14251a (n7.0)
CVE-2023-48865 (An issue discovered in Reportico Till 8.1.0 allows attackers to obtain ...)
NOT-FOR-US: Reportico Till
CVE-2023-45186 (IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6 ...)
@@ -375842,7 +375842,7 @@ CVE-2023-33202 (Bouncy Castle for Java before 1.73 contains a potential Denial o
[bullseye] - bouncycastle <no-dsa> (Minor issue)
[buster] - bouncycastle <ignored> (Minor issue)
NOTE: https://github.com/bcgit/bc-java/wiki/CVE-2023-33202
- NOTE: Fixed by https://github.com/bcgit/bc-java/commit/0c576892862ed41894f49a8f639112e8d66d229c (r1rv73)
+ NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/0c576892862ed41894f49a8f639112e8d66d229c (r1rv73)
CVE-2023-43123 (On unix-like systems, the temporary directory is shared between all us ...)
NOT-FOR-US: Apache Storm
CVE-2023-49146 (DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG do ...)
@@ -382755,7 +382755,7 @@ CVE-2018-25091 (urllib3 before 1.24.2 does not remove the authorization HTTP hea
- python-urllib3 1.25.6-4
NOTE: https://github.com/urllib3/urllib3/issues/1510
NOTE: This issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
- NOTE: Fixed by https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.25)
+ NOTE: Fixed by: https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.25)
CVE-2023-5586 (NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0 ...)
- gpac <removed> (bug #1055124)
[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
@@ -421486,7 +421486,7 @@ CVE-2023-0809 (In Mosquitto before 2.0.16, excessive memory is allocated based o
- mosquitto 2.0.17-1
[buster] - mosquitto <not-affected> (The vulnerable code was introduced later)
NOTE: https://mosquitto.org/blog/2023/08/version-2-0-16-released/
- NOTE: Fixed by https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad
+ NOTE: Fixed by: https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad
CVE-2023-3592 (In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 ...)
{DSA-5511-1}
- mosquitto 2.0.17-1
@@ -436320,7 +436320,7 @@ CVE-2022-4492 (The undertow client is not checking the server identity presented
[experimental] - undertow 2.3.8-1
- undertow 2.3.8-2 (bug #1032087)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2153260 has missing public details
- NOTE: Fixed by https://github.com/undertow-io/undertow/pull/1447
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/pull/1447
CVE-2022-4491 (The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate ...)
NOT-FOR-US: WordPress plugin
CVE-2022-4490
@@ -439391,7 +439391,7 @@ CVE-2022-46393 (An issue was discovered in Mbed TLS before 2.28.2 and 3.x before
[bullseye] - mbedtls <not-affected> (The vulnerable code was introduced later)
[buster] - mbedtls <not-affected> (The vulnerable code was introduced later)
NOTE: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2
- NOTE: Fixed by https://github.com/Mbed-TLS/mbedtls/commit/f385fcebee017973cf4137333628a78248f1f443
+ NOTE: Fixed by: https://github.com/Mbed-TLS/mbedtls/commit/f385fcebee017973cf4137333628a78248f1f443
CVE-2022-46392 (An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0 ...)
{DLA-4236-1}
- mbedtls 2.28.2-1
@@ -455390,7 +455390,7 @@ CVE-2022-41915 (Netty project is an event-driven asynchronous network applicatio
{DSA-5316-1 DLA-3268-1}
- netty 1:4.1.48-6 (bug #1027180)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-hh82-3pmq-7frp
- NOTE: Fixed by https://github.com/netty/netty/commit/fe18adff1c2b333acb135ab779a3b9ba3295a1c4 (netty-4.1.86.Final)
+ NOTE: Fixed by: https://github.com/netty/netty/commit/fe18adff1c2b333acb135ab779a3b9ba3295a1c4 (netty-4.1.86.Final)
CVE-2022-41914 (Zulip is an open-source team collaboration tool. For organizations wit ...)
- zulip-server <itp> (bug #800052)
CVE-2022-41913 (Discourse-calendar is a plugin for the Discourse messaging platform wh ...)
@@ -455484,7 +455484,7 @@ CVE-2022-41881 (Netty project is an event-driven asynchronous network applicatio
{DSA-5316-1 DLA-3268-1}
- netty 1:4.1.48-6 (bug #1027180)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985v
- NOTE: Fixed by https://github.com/netty/netty/commit/cd91cf3c99123bd1e53fd6a1de0e3d1922f05bb2 (netty-4.1.86.Final)
+ NOTE: Fixed by: https://github.com/netty/netty/commit/cd91cf3c99123bd1e53fd6a1de0e3d1922f05bb2 (netty-4.1.86.Final)
CVE-2022-41880 (TensorFlow is an open source platform for machine learning. When the ` ...)
- tensorflow <not-affected> (Fixed before initial upload to the archive)
CVE-2022-41879 (Parse Server is an open source backend that can be deployed to any inf ...)
@@ -463764,8 +463764,8 @@ CVE-2022-38751 (Using snakeYAML to parse untrusted YAML files may be vulnerable
[bullseye] - snakeyaml 1.28-1+deb11u1
NOTE: https://bitbucket.org/snakeyaml/snakeyaml/issues/530/stackoverflow-oss-fuzz-47039
NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47039
- NOTE: Fixed by https://bitbucket.org/snakeyaml/snakeyaml/commits/f3ab4e0f54c37ddb10f00b71d04187bb0ef1799c (snakeyaml-1.31)
- NOTE: Fixed by https://bitbucket.org/snakeyaml/snakeyaml/commits/6aedd33a811f7347c5dae2940e75940966f59466 (snakeyaml-1.31)
+ NOTE: Fixed by: https://bitbucket.org/snakeyaml/snakeyaml/commits/f3ab4e0f54c37ddb10f00b71d04187bb0ef1799c (snakeyaml-1.31)
+ NOTE: Fixed by: https://bitbucket.org/snakeyaml/snakeyaml/commits/6aedd33a811f7347c5dae2940e75940966f59466 (snakeyaml-1.31)
CVE-2022-38750 (Using snakeYAML to parse untrusted YAML files may be vulnerable to Den ...)
{DLA-3132-1}
- snakeyaml 1.31-1
@@ -500255,22 +500255,22 @@ CVE-2022-26129 (Buffer overflow vulnerabilities exist in FRRouting through 8.1.0
{DLA-3865-1 DLA-3797-1}
- frr 8.4.1-1 (bug #1008010)
NOTE: https://github.com/FRRouting/frr/issues/10503
- NOTE: Fixed by https://github.com/FRRouting/frr/issues/10504 (together with CVE-2022-26128)
+ NOTE: Fixed by: https://github.com/FRRouting/frr/issues/10504 (together with CVE-2022-26128)
CVE-2022-26128 (A buffer overflow vulnerability exists in FRRouting through 8.1.0 due ...)
{DLA-3865-1 DLA-3797-1}
- frr 8.4.1-1 (bug #1008010)
NOTE: https://github.com/FRRouting/frr/issues/10502
- NOTE: Fixed by https://github.com/FRRouting/frr/issues/10504 (together with CVE-2022-26129)
+ NOTE: Fixed by: https://github.com/FRRouting/frr/issues/10504 (together with CVE-2022-26129)
CVE-2022-26127 (A buffer overflow vulnerability exists in FRRouting through 8.1.0 due ...)
{DLA-3865-1 DLA-3797-1}
- frr 8.4.1-1 (bug #1008010)
NOTE: https://github.com/FRRouting/frr/issues/10487
- NOTE: Fixed by https://github.com/FRRouting/frr/pull/10494
+ NOTE: Fixed by: https://github.com/FRRouting/frr/pull/10494
CVE-2022-26126 (Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due t ...)
{DLA-3865-1 DLA-3797-1}
- frr 8.4.1-1 (bug #1008010)
NOTE: https://github.com/FRRouting/frr/issues/10505
- NOTE: Fixed by https://github.com/FRRouting/frr/pull/10566
+ NOTE: Fixed by: https://github.com/FRRouting/frr/pull/10566
CVE-2022-26125 (Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due t ...)
{DLA-3865-1 DLA-3797-1}
- frr 8.4.1-1 (bug #1008010)
@@ -500943,7 +500943,7 @@ CVE-2022-21222 (The package css-what before 2.1.3 are vulnerable to Regular Expr
NOTE: https://security.snyk.io/vuln/SNYK-JS-CSSWHAT-3035488
NOTE: ReDoS issue fixed with rewrite of module to TypeScript
NOTE: Not fixed in 4.0.0 see https://sources.debian.org/src/node-css-what/4.0.0-3/src/parse.ts/#L84
- NOTE: Fixed by https://github.com/fb55/css-what/pull/503/commits/46b0dbd6f38fb375da02208426f93f87f7169b7e
+ NOTE: Fixed by: https://github.com/fb55/css-what/pull/503/commits/46b0dbd6f38fb375da02208426f93f87f7169b7e
CVE-2022-21221 (The package github.com/valyala/fasthttp before 1.34.0 are vulnerable t ...)
NOT-FOR-US: github.com/valyala/fasthttp
CVE-2022-21213 (This affects all versions of package mout. The deepFillIn function can ...)
@@ -510029,7 +510029,7 @@ CVE-2022-23221 (H2 Console before 2.1.210 allows remote attackers to execute arb
{DSA-5076-1 DLA-2923-1}
- h2database 2.1.210-1
NOTE: https://github.com/h2database/h2database/releases/tag/version-2.1.210
- NOTE: Fixed by https://github.com/h2database/h2database/commit/eb75633d0dfa86341e6ef77a861665c4a0f16ab8
+ NOTE: Fixed by: https://github.com/h2database/h2database/commit/eb75633d0dfa86341e6ef77a861665c4a0f16ab8
NOTE: https://github.com/h2database/h2database/issues/3360#issuecomment-1018351050
CVE-2022-23220 (USBView 2.1 before 2.2 allows some local users (e.g., ones logged in v ...)
{DSA-5052-1}
@@ -513307,7 +513307,7 @@ CVE-2022-0084 (A flaw was found in XNIO, specifically in the notifyReadClosed me
[bullseye] - jboss-xnio <no-dsa> (Minor issue)
[buster] - jboss-xnio <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2064226
- NOTE: Fixed by https://github.com/xnio/xnio/commit/b05531de0433f498af26f9aec6c0e944c3c1689c
+ NOTE: Fixed by: https://github.com/xnio/xnio/commit/b05531de0433f498af26f9aec6c0e944c3c1689c
CVE-2021-46129
RESERVED
CVE-2021-46128
@@ -528573,7 +528573,7 @@ CVE-2021-42392 (The org.h2.util.JdbcUtils.getConnection method of the H2 databas
- h2database 2.1.210-1 (bug #1003894)
NOTE: https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6
NOTE: https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/
- NOTE: Fixed by https://github.com/h2database/h2database/commit/41dd2a4cf89da9dd18239debbf73f88da6184ec7
+ NOTE: Fixed by: https://github.com/h2database/h2database/commit/41dd2a4cf89da9dd18239debbf73f88da6184ec7
NOTE: https://github.com/h2database/h2database/commit/956c6241868332c5b440f5d55ea8fdc1e51ae4fd
CVE-2021-42391 (Divide-by-zero in Clickhouse's Gorilla compression codec when parsing ...)
- clickhouse <not-affected> (Vulnerable code introduced later)
@@ -530364,7 +530364,7 @@ CVE-2021-41800 (MediaWiki before 1.36.2 allows a denial of service (resource con
[stretch] - mediawiki <not-affected> (The vulnerable code was introduced later)
NOTE: https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/2IFS5CM2YV4VMSODPX3J2LFHKSEWVFV5/
NOTE: https://phabricator.wikimedia.org/T284419
- NOTE: Fixed by https://github.com/wikimedia/mediawiki/commit/781caf83dba90c18349f930bbaaa0e89f003f874
+ NOTE: Fixed by: https://github.com/wikimedia/mediawiki/commit/781caf83dba90c18349f930bbaaa0e89f003f874
CVE-2021-41799 (MediaWiki before 1.36.2 allows a denial of service (resource consumpti ...)
{DSA-4979-1 DLA-2779-1}
- mediawiki 1:1.35.4-1
@@ -538487,7 +538487,7 @@ CVE-2021-38576 (A BIOS bug in firmware for a particular PC model leaves the Plat
- edk2 2021.11-1 (bug #1014468)
[buster] - edk2 <no-dsa> (Minor issue)
NOTE: https://bugzilla.tianocore.org/show_bug.cgi?id=3499
- NOTE: Fixed by https://github.com/tianocore/edk2/pull/1968
+ NOTE: Fixed by: https://github.com/tianocore/edk2/pull/1968
CVE-2021-38575 (NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.)
{DLA-4207-1}
- edk2 2021.08-1
@@ -542174,7 +542174,7 @@ CVE-2021-3658 (bluetoothd from bluez incorrectly saves adapters' Discoverable st
[buster] - bluez <not-affected> (Vulnerable code introduced later)
[stretch] - bluez <not-affected> (Vulnerable code introduced later)
NOTE: Introduced by https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=d04eb02f9bad8795297210ef80e262be16ea8f07 (5.51)
- NOTE: Fixed by https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
+ NOTE: Fixed by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
CVE-2021-37216 (QSAN Storage Manager header page parameters does not filter special ch ...)
NOT-FOR-US: QSAN Storage Manager
CVE-2021-37215 (The employee management page of Flygo contains an Insecure Direct Obje ...)
@@ -546349,7 +546349,7 @@ CVE-2021-35515 (When reading a specially crafted 7Z archive, the construction of
[buster] - libcommons-compress-java <no-dsa> (Minor issue)
[stretch] - libcommons-compress-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2021/07/13/1
- NOTE: Fixed by https://gitbox.apache.org/repos/asf?p=commons-compress.git;a=commit;h=3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321
+ NOTE: Fixed by: https://gitbox.apache.org/repos/asf?p=commons-compress.git;a=commit;h=3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321
CVE-2021-35514 (Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the t ...)
NOT-FOR-US: Narou
CVE-2021-35513 (Mermaid before 8.11.0 allows XSS when the antiscript feature is used.)
@@ -548907,7 +548907,7 @@ CVE-2021-34429 (For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1
[buster] - jetty9 <not-affected> (Vulnerable code was introduced in version 9.4.37)
[stretch] - jetty9 <not-affected> (Vulnerable code was introduced in version 9.4.37)
NOTE: https://github.com/eclipse/jetty.project/security/advisories/GHSA-vjv5-gp2w-65vm
- NOTE: Fixed by https://github.com/eclipse/jetty.project/pull/6477
+ NOTE: Fixed by: https://github.com/eclipse/jetty.project/pull/6477
CVE-2021-34428 (For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exce ...)
{DSA-4949-1}
- jetty9 9.4.39-2 (bug #990578)
@@ -573107,7 +573107,7 @@ CVE-2021-25220 (BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND S
{DSA-5105-1 DLA-2955-1}
- bind9 1:9.18.1-1
NOTE: https://kb.isc.org/docs/cve-2021-25220
- NOTE: Fixed by https://gitlab.isc.org/isc-projects/bind9/-/commit/fc9cb6cf91c1a36b797ffef0a277dbb3989d43dc
+ NOTE: Fixed by: https://gitlab.isc.org/isc-projects/bind9/-/commit/fc9cb6cf91c1a36b797ffef0a277dbb3989d43dc
CVE-2021-25219 (In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> ...)
{DSA-4994-1 DLA-2807-1}
- bind9 1:9.17.19-1
@@ -580494,7 +580494,7 @@ CVE-2021-21996 (An issue was discovered in SaltStack Salt before 3003.3. A user
{DSA-5011-1 DLA-2823-1}
- salt 3002.7+dfsg1-1 (bug #994016)
NOTE: https://saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/
- NOTE: Fixed by https://github.com/saltstack/salt/commit/0b75ba190fda9c04cc026ad1aa4a6d572f40349b
+ NOTE: Fixed by: https://github.com/saltstack/salt/commit/0b75ba190fda9c04cc026ad1aa4a6d572f40349b
NOTE: https://github.com/openSUSE/salt/commit/57ed9c41a177f57e3d56465662750617ac36cc95
CVE-2021-21995 (OpenSLP as used in ESXi has a denial-of-service vulnerability due a he ...)
NOT-FOR-US: VMware
@@ -603873,7 +603873,7 @@ CVE-2020-25638 (A flaw was found in hibernate-core in versions prior to and incl
{DSA-4908-1 DLA-2512-1}
- libhibernate3-java 3.6.10.Final-11
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1881353
- NOTE: Fixed by https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78
+ NOTE: Fixed by: https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78
CVE-2020-25637 (A double free memory issue was found to occur in the libvirt API, in v ...)
{DLA-3778-1 DLA-2395-1}
- libvirt 6.8.0-1 (bug #971555)
@@ -643993,13 +643993,13 @@ CVE-2020-9498 (Apache Guacamole 1.1.0 and older may mishandle pointers involved
- guacamole-server 1.3.0-1 (bug #964195)
NOTE: https://www.openwall.com/lists/oss-security/2020/07/02/3
NOTE: https://research.checkpoint.com/2020/apache-guacamole-rce/
- NOTE: Fixed by https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
+ NOTE: Fixed by: https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
CVE-2020-9497 (Apache Guacamole 1.1.0 and older do not properly validate datareceived ...)
{DLA-2435-1}
- guacamole-server 1.3.0-1 (bug #964195)
NOTE: https://www.openwall.com/lists/oss-security/2020/07/02/2
NOTE: https://research.checkpoint.com/2020/apache-guacamole-rce/
- NOTE: Fixed by https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
+ NOTE: Fixed by: https://github.com/apache/guacamole-server/commit/a0e11dc81727528224d28466903454e1cb0266bb
CVE-2020-9496 (XML-RPC request are vulnerable to unsafe deserialization and Cross-Sit ...)
NOT-FOR-US: Apache OFBiz
CVE-2020-9495 (Apache Archiva login service before 2.2.5 is vulnerable to LDAP inject ...)
@@ -673477,7 +673477,7 @@ CVE-2019-17571 (Included in Log4j 1.2 is a SocketServer class that is vulnerable
NOTE: CVE-2019-17571 correspond to CVE-2017-5645 for apache-log4j2. 1.2.x branch
NOTE: is end-of-life upstream and does not recieve a fix for this issue. Users
NOTE: should upgrade to Log4j 2.x.
- NOTE: Fixed by https://src.fedoraproject.org/rpms/log4j12/c/d4c817c458d69dcc629a7271999d178b0dcb7c74?branch=master
+ NOTE: Fixed by: https://src.fedoraproject.org/rpms/log4j12/c/d4c817c458d69dcc629a7271999d178b0dcb7c74?branch=master
CVE-2019-17570 (An untrusted deserialization was found in the org.apache.xmlrpc.parser ...)
{DSA-4619-1 DLA-2078-1}
- libxmlrpc3-java <removed> (bug #949089)
@@ -689839,7 +689839,7 @@ CVE-2019-12594 (DOSBox 0.74-2 has Incorrect Access Control.)
NOTE: Fixed in 0.74-3 upstream.
NOTE: https://github.com/Alexandre-Bartel/CVE-2019-12594
NOTE: Upstream clarification https://sourceforge.net/p/dosbox/bugs/508/
- NOTE: Fixed by https://sourceforge.net/p/dosbox/code-0/4246/
+ NOTE: Fixed by: https://sourceforge.net/p/dosbox/code-0/4246/
CVE-2019-12593 (IceWarp Mail Server through 10.4.4 is prone to a local file inclusion ...)
NOT-FOR-US: IceWarp Mail Server
CVE-2019-12592 (A universal Cross-site scripting (UXSS) vulnerability in the Evernote ...)
@@ -690368,7 +690368,7 @@ CVE-2019-12422 (Apache Shiro before 1.4.2, when using the default "remember me"
[stretch] - shiro <no-dsa> (Minor issue)
[jessie] - shiro <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2019/11/18/1
- NOTE: Fixed by https://github.com/apache/shiro/commit/44f6548b97610cdf661976969d5735c0be14a57b#diff-a8fc9cf5d6f24966aa18cdf0850a730e
+ NOTE: Fixed by: https://github.com/apache/shiro/commit/44f6548b97610cdf661976969d5735c0be14a57b#diff-a8fc9cf5d6f24966aa18cdf0850a730e
CVE-2019-12421 (When using an authentication mechanism other than PKI, when the user c ...)
NOT-FOR-US: Apache NiFi
CVE-2019-12420 (In Apache SpamAssassin before 3.4.3, a message can be crafted in a way ...)
@@ -696485,7 +696485,7 @@ CVE-2019-10219 (A vulnerability was found in Hibernate-Validator. The SafeHtml v
- libhibernate-validator4-java <not-affected> (Vulnerable code was introduced later)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1738673
NOTE: https://hibernate.atlassian.net/browse/HV-1739
- NOTE: Fixed by https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
+ NOTE: Fixed by: https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
CVE-2019-10218 (A flaw was found in the samba client, all samba versions before samba ...)
{DLA-3563-1 DLA-2668-1}
- samba 2:4.11.1+dfsg-2
@@ -698629,7 +698629,7 @@ CVE-2019-9826 (The fulltext search component in phpBB before 3.2.6 allows Denial
{DLA-1775-1}
- phpbb3 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2019/04/29/3
- NOTE: Fixed by https://github.com/phpbb/phpbb/commit/3075d2fecc9f5bb780bb478c0851a704c7f9b392
+ NOTE: Fixed by: https://github.com/phpbb/phpbb/commit/3075d2fecc9f5bb780bb478c0851a704c7f9b392
CVE-2019-9825 (FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arb ...)
NOT-FOR-US: FeiFeiCMS
CVE-2019-9824 (tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 u ...)
@@ -700504,7 +700504,7 @@ CVE-2019-9210 (In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an int
{DLA-2868-1 DLA-1702-1}
- advancecomp 2.1-2 (low; bug #923416)
NOTE: https://sourceforge.net/p/advancemame/bugs/277/
- NOTE: Fixed by https://github.com/amadvance/advancecomp/commit/fcf71a89265c78fc26243574dda3a872574a5c02
+ NOTE: Fixed by: https://github.com/amadvance/advancecomp/commit/fcf71a89265c78fc26243574dda3a872574a5c02
CVE-2018-20797 (An issue was discovered in PoDoFo 0.9.6. There is an attempted excessi ...)
- libpodofo <unfixed> (unimportant; bug #923415)
NOTE: https://sourceforge.net/p/podofo/tickets/34/
@@ -706013,7 +706013,7 @@ CVE-2019-7165 (A buffer overflow in DOSBox 0.74-2 allows attackers to execute ar
- dosbox 0.74-3-1 (bug #931222)
NOTE: Fixed in 0.74-3 upstream.
NOTE: Upstream clarification https://sourceforge.net/p/dosbox/bugs/508/
- NOTE: Fixed by https://sourceforge.net/p/dosbox/code-0/3925/
+ NOTE: Fixed by: https://sourceforge.net/p/dosbox/code-0/3925/
CVE-2019-7164 (SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injecti ...)
{DLA-2811-1 DLA-1718-1}
[experimental] - sqlalchemy 1.3.0~b3+ds1-1
@@ -715702,7 +715702,7 @@ CVE-2018-20482 (GNU Tar through 1.30, when --sparse is used, mishandles file shr
NOTE: https://news.ycombinator.com/item?id=18745431
NOTE: https://twitter.com/thatcks/status/1076166645708668928
NOTE: https://lists.gnu.org/archive/html/bug-tar/2018-12/msg00023.html
- NOTE: Fixed by https://git.savannah.gnu.org/cgit/tar.git/commit/?id=c15c42c
+ NOTE: Fixed by: https://git.savannah.gnu.org/cgit/tar.git/commit/?id=c15c42c
CVE-2018-20481 (XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRe ...)
{DLA-2287-1 DLA-1706-1}
- poppler 0.71.0-4 (low; bug #917325)
@@ -720483,7 +720483,7 @@ CVE-2018-20004 (An issue has been found in Mini-XML (aka mxml) 2.12. It is a sta
- mxml 2.12-2 (low; bug #918007)
[stretch] - mxml <no-dsa> (Minor issue)
NOTE: https://github.com/michaelrsweet/mxml/issues/233
- NOTE: Fixed by https://github.com/michaelrsweet/mxml/commit/4f5577dd4672d228e4180f06bdbd66f343ea45e0
+ NOTE: Fixed by: https://github.com/michaelrsweet/mxml/commit/4f5577dd4672d228e4180f06bdbd66f343ea45e0
CVE-2018-20003
RESERVED
CVE-2018-20002 (The _bfd_generic_read_minisymbols function in syms.c in the Binary Fil ...)
@@ -727001,7 +727001,7 @@ CVE-2018-19105 (LibreCAD 2.1.3 allows remote attackers to cause a denial of serv
[stretch] - librecad 2.1.2-1+deb9u1
NOTE: https://code610.blogspot.com/2018/11/crashing-librecad-213.html
NOTE: https://github.com/LibreCAD/LibreCAD/issues/1038
- NOTE: Fixed by https://github.com/LibreCAD/LibreCAD/commit/6da7cc5f7f31afb008f03dbd11e07207ccd82085
+ NOTE: Fixed by: https://github.com/LibreCAD/LibreCAD/commit/6da7cc5f7f31afb008f03dbd11e07207ccd82085
NOTE: Regression fix https://github.com/LibreCAD/LibreCAD/commit/8604f171ee380f294102da6154adf77ab754d403
CVE-2018-19104 (In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can b ...)
NOT-FOR-US: BageCMS
@@ -732764,7 +732764,7 @@ CVE-2018-16883 (sssd versions from 1.13.0 to before 2.0.0 did not properly restr
[jessie] - sssd <not-affected> (Issue got introduced with 1.13.0)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1659862
NOTE: Fixed in upstream 2.0.0 while refactoring code
- NOTE: Fixed by https://pagure.io/SSSD/sssd/c/fbe2476a3dd9be83ffa85c29dca26f734618d72d?branch=master
+ NOTE: Fixed by: https://pagure.io/SSSD/sssd/c/fbe2476a3dd9be83ffa85c29dca26f734618d72d?branch=master
CVE-2018-16882 (A use-after-free issue was found in the way the Linux kernel's KVM hyp ...)
- linux 4.19.13-1
[stretch] - linux <not-affected> (Vulnerable code not present)
@@ -744348,7 +744348,7 @@ CVE-2018-12495 (The quoteblock function in markdown.c in libmarkdown.a in DISCOU
{DSA-4293-1 DLA-1499-1}
- discount 2.2.4-1 (bug #901912)
NOTE: https://github.com/Orc/discount/issues/189#issuecomment-397541501
- NOTE: Fixed by https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+ NOTE: Fixed by: https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
CVE-2018-12494 (An issue was discovered in PublicCMS V4.0.20180210. There is a "Direct ...)
NOT-FOR-US: PublicCMS
CVE-2018-12493 (An issue was discovered in PublicCMS V4.0.20180210. There is a "Direct ...)
@@ -747312,13 +747312,13 @@ CVE-2018-11504 (The islist function in markdown.c in libmarkdown.a in DISCOUNT 2
- discount 2.2.4-1 (bug #901912)
NOTE: https://github.com/Orc/discount/issues/189#issuecomment-392247798
NOTE: POC: https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue3_testcase
- NOTE: Fixed by https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+ NOTE: Fixed by: https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
CVE-2018-11503 (The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2 ...)
{DSA-4293-1 DLA-1499-1}
- discount 2.2.4-1 (bug #901912)
NOTE: https://github.com/Orc/discount/issues/189#issuecomment-392247798
NOTE: POC: https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue2_testcase
- NOTE: Fixed by https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+ NOTE: Fixed by: https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
CVE-2018-11502 (An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB ...)
NOT-FOR-US: MyBB plugin
CVE-2018-11501 (PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit. ...)
@@ -747413,7 +747413,7 @@ CVE-2018-11468 (The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISC
- discount 2.2.4-1 (bug #901912)
NOTE: https://github.com/Orc/discount/issues/189
NOTE: POC: https://github.com/fCorleone/fuzz_programs/blob/master/discount/issue1_testcase
- NOTE: Fixed by https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
+ NOTE: Fixed by: https://github.com/Orc/discount/commit/b002a5a4db31e42dfb45451c059bc56941c17974
CVE-2018-11467
RESERVED
CVE-2018-11466 (A vulnerability has been identified in SINUMERIK 808D V4.7 (All versio ...)
@@ -761722,7 +761722,7 @@ CVE-2016-10711 (Apsis Pound before 2.8a allows request smuggling via crafted hea
[stretch] - pound 2.7-1.3+deb9u1
NOTE: http://www.apsis.ch/pound/pound_list/archive/2016/2016-10/1477235279000
NOTE: https://www.suse.com/de-de/security/cve/CVE-2016-10711/
- NOTE: Fixed by https://build.opensuse.org/request/show/571084
+ NOTE: Fixed by: https://build.opensuse.org/request/show/571084
NOTE: Confirmed that the SUSE patch is the security relevant diff between
NOTE: version 2.7 and 2.8a
NOTE: an additional fix of the fix is needed to avoid that pound uses 100% CPU
@@ -777393,7 +777393,7 @@ CVE-2018-1067 (In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that
- undertow 1.4.25-1 (bug #900323)
NOTE: https://issues.jboss.org/browse/UNDERTOW-1302
NOTE: Issue is incomplete fix for CVE-2016-4993
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/85d4478e598105fe94ac152d3e11e388374e8b86 (1.4.25.Final)
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/85d4478e598105fe94ac152d3e11e388374e8b86 (1.4.25.Final)
CVE-2018-1066 (The Linux kernel before version 4.11 is vulnerable to a NULL pointer d ...)
{DSA-4188-1 DSA-4187-1 DLA-1422-1}
- linux 4.11.6-1
@@ -777529,19 +777529,19 @@ CVE-2018-1048 (It was found that the AJP connector in undertow, as shipped in Jb
- undertow 1.4.22-1 (bug #891928)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1534343
NOTE: https://issues.jboss.org/browse/UNDERTOW-1245
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/1bc0c275aadf5835abfbd3835d5d78095c2f1cf5
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/1bc0c275aadf5835abfbd3835d5d78095c2f1cf5
CVE-2018-1047 (A flaw was found in Wildfly 9.x. A path traversal vulnerability throug ...)
- wildfly <itp> (bug #752018)
NOTE: https://issues.jboss.org/browse/WFLY-9620
NOTE: https://developer.jboss.org/thread/276826
- NOTE: Fixed by https://github.com/wildfly/wildfly/pull/10748
+ NOTE: Fixed by: https://github.com/wildfly/wildfly/pull/10748
CVE-2018-1046 (pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsrep ...)
- pdns 4.1.2-1 (bug #898255)
[stretch] - pdns 4.0.3-1+deb9u3
[jessie] - pdns <not-affected> (Vulnerable code not present)
[wheezy] - pdns <not-affected> (Vulnerable code not present)
NOTE: https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2018-02.html
- NOTE: Fixed by https://github.com/PowerDNS/pdns/commit/f9c57c98da1b1007a51680629b667d57d9b702b8
+ NOTE: Fixed by: https://github.com/PowerDNS/pdns/commit/f9c57c98da1b1007a51680629b667d57d9b702b8
CVE-2018-1045 (In Moodle 3.x, there is XSS via a calendar event name.)
- moodle <removed>
CVE-2018-1044 (In Moodle 3.x, quiz web services allow students to see quiz results wh ...)
@@ -785069,14 +785069,14 @@ CVE-2017-15602 (In GNU Libextractor 1.4, there is an integer signedness error fo
[stretch] - libextractor 1:1.3-4+deb9u1
[jessie] - libextractor 1:1.3-2+deb8u1
NOTE: http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00005.html
- NOTE: Fixed by https://git.gnunet.org/libextractor.git/commit/?id=ffab889c1710c7646af9ed360c796a2a0a619efc
+ NOTE: Fixed by: https://git.gnunet.org/libextractor.git/commit/?id=ffab889c1710c7646af9ed360c796a2a0a619efc
CVE-2017-15601 (In GNU Libextractor 1.4, there is a heap-based buffer overflow in the ...)
{DLA-1198-1}
- libextractor 1:1.6-1 (low)
[stretch] - libextractor 1:1.3-4+deb9u1
[jessie] - libextractor 1:1.3-2+deb8u1
NOTE: http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00006.html
- NOTE: Fixed by https://git.gnunet.org/libextractor.git/commit/?id=f813535dad4ad860b989952a46266a1469801091
+ NOTE: Fixed by: https://git.gnunet.org/libextractor.git/commit/?id=f813535dad4ad860b989952a46266a1469801091
CVE-2017-15600 (In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EX ...)
{DLA-1198-1}
- libextractor 1:1.6-1 (low)
@@ -785084,7 +785084,7 @@ CVE-2017-15600 (In GNU Libextractor 1.4, there is a NULL Pointer Dereference in
[jessie] - libextractor 1:1.3-2+deb8u1
NOTE: http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00004.html
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1501695
- NOTE: Fixed by https://git.gnunet.org/libextractor.git/commit/?id=38e8933539ee9d044057b18a971c2eae3c21aba7
+ NOTE: Fixed by: https://git.gnunet.org/libextractor.git/commit/?id=38e8933539ee9d044057b18a971c2eae3c21aba7
CVE-2017-15599
RESERVED
CVE-2017-15598
@@ -789233,7 +789233,7 @@ CVE-2017-14266 (tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow v
- tcpreplay 3.4.4-3
[jessie] - tcpreplay 3.4.4-2+deb8u1
[wheezy] - tcpreplay 3.4.3-2+wheezy2
- NOTE: Fixed by http://launchpadlibrarian.net/270778908/tcpreplay_3.4.4-2_3.4.4-3.diff.gz
+ NOTE: Fixed by: http://launchpadlibrarian.net/270778908/tcpreplay_3.4.4-2_3.4.4-3.diff.gz
NOTE: Not a duplicate of CVE-2016-6160 the detailed MITRE description, but both issues
NOTE: are addressed with the same patch:
NOTE: Patch enforce-maxpacket.patch addresses the issue
@@ -789971,7 +789971,7 @@ CVE-2016-10510 (Cross-site scripting (XSS) vulnerability in the Security compone
- libkohana2-php <removed>
[jessie] - libkohana2-php <ignored> (Minor issue)
NOTE: https://github.com/kohana/kohana/issues/107
- NOTE: Fixed by https://github.com/kohana/core/pull/697
+ NOTE: Fixed by: https://github.com/kohana/core/pull/697
CVE-2016-10509 (SQL injection vulnerability in the updateAmazonOrderTracking function ...)
NOT-FOR-US: OpenCart
CVE-2016-10508 (Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() befo ...)
@@ -790734,7 +790734,7 @@ CVE-2017-13748 (There are lots of memory leaks in JasPer 2.0.12, triggered in th
[wheezy] - jasper <ignored> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1485287
NOTE: https://github.com/mdadams/jasper/issues/168
- NOTE: Fixed by https://github.com/mdadams/jasper/pull/159 but still no upstream comment.
+ NOTE: Fixed by: https://github.com/mdadams/jasper/pull/159 but still no upstream comment.
CVE-2017-13747 (There is a reachable assertion abort in the function jpc_floorlog2() i ...)
- jasper <removed> (unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1485282
@@ -791087,7 +791087,7 @@ CVE-2017-13672 (QEMU (aka Quick Emulator), when built with the VGA display emula
- qemu-kvm <removed>
[wheezy] - qemu-kvm <postponed> (Can be fixed along in a future DSA)
NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-08/msg04684.html
- NOTE: Fixed by https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=3d90c6254863693a6b13d918d2b8682e08bbc681
+ NOTE: Fixed by: https://git.qemu.org/gitweb.cgi?p=qemu.git;a=commit;h=3d90c6254863693a6b13d918d2b8682e08bbc681
NOTE: CentOS7 has a backport/upgrade(?) for their frankenstein version
NOTE: http://vault.centos.org/7.6.1810/updates/Source/SPackages/qemu-kvm-1.5.3-160.el7_6.3.src.rpm
CVE-2017-13671 (app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent ...)
@@ -795466,7 +795466,7 @@ CVE-2017-12197 (It was found that libpam4j up to and including 1.8 did not prope
CVE-2017-12196 (undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was fou ...)
- undertow 1.4.25-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1503055
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/facb33a5cedaf4b7b96d3840a08210370a806870
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/facb33a5cedaf4b7b96d3840a08210370a806870
NOTE: See also https://github.com/undertow-io/undertow/commit/8804170ce3186bdd83b486959399ec7ac0f59d0f
CVE-2017-12195 (A flaw was found in all Openshift Enterprise versions using the opensh ...)
NOT-FOR-US: OpenShift
@@ -796893,7 +796893,7 @@ CVE-2017-11684 (There is an illegal address access in the build_table function i
[jessie] - libav 6:11.11-1~deb8u1
- ffmpeg 7:2.3.1-1
NOTE: https://bugzilla.libav.org/show_bug.cgi?id=1073
- NOTE: Fixed by https://github.com/libav/libav/commit/ec683ed527cef9aad208d1daeb10d0e7fb63e75e.patch
+ NOTE: Fixed by: https://github.com/libav/libav/commit/ec683ed527cef9aad208d1daeb10d0e7fb63e75e.patch
CVE-2017-11683 (There is a reachable assertion in the Internal::TiffReader::visitDirec ...)
{DLA-3186-1 DLA-1147-1}
- exiv2 0.27.2-6 (unimportant)
@@ -797095,7 +797095,7 @@ CVE-2017-11628 (In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7,
- php5 <removed> (low)
NOTE: https://bugs.php.net/bug.php?id=74603
NOTE: Fixed in 7.1.7, 7.0.21, 5.6.31
- NOTE: Fixed by https://git.php.net/?p=php-src.git;a=commit;h=05255749139b3686c8a6a58ee01131ac0047465e
+ NOTE: Fixed by: https://git.php.net/?p=php-src.git;a=commit;h=05255749139b3686c8a6a58ee01131ac0047465e
CVE-2017-11627 (A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, ...)
[experimental] - qpdf 7.0~b1-1
- qpdf 7.0.0-1 (low; bug #871320)
@@ -807161,7 +807161,7 @@ CVE-2017-8314 (Directory Traversal in Zip Extraction built-in function in Kodi 1
[jessie] - xbmc <no-dsa> (Minor issue)
NOTE: http://blog.checkpoint.com/2017/05/23/hacked-in-translation/
NOTE: https://kodi.tv/article/kodi-v172-minor-bug-fix-and-security-release
- NOTE: Fixed by https://github.com/xbmc/xbmc/commit/35cfe35608b15335ef21d798947fceab3f47c8d7
+ NOTE: Fixed by: https://github.com/xbmc/xbmc/commit/35cfe35608b15335ef21d798947fceab3f47c8d7
CVE-2017-8313 (Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to ...)
{DSA-3899-1}
- vlc 2.2.5-1
@@ -809741,7 +809741,7 @@ CVE-2017-7559 (In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, a
NOTE: https://issues.jboss.org/browse/UNDERTOW-1165
NOTE: https://issues.jboss.org/browse/UNDERTOW-1295
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1481665#c7
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/3436b03eda8b0b62c1855698c4d7c358add836c2
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/3436b03eda8b0b62c1855698c4d7c358add836c2
CVE-2017-7558 (A kernel data leak due to an out-of-bound read was found in the Linux ...)
- linux 4.12.13-1
[stretch] - linux 4.9.30-2+deb9u5
@@ -814890,7 +814890,7 @@ CVE-2017-5953 (vim before patch 8.0.0322 does not properly validate values for t
{DSA-3786-1 DLA-822-1}
- vim 2:8.0.0197-2 (bug #854969)
- neovim 0.1.7-4
- NOTE: Fixed by https://github.com/vim/vim/commit/399c297aa93afe2c0a39e2a1b3f972aebba44c9d
+ NOTE: Fixed by: https://github.com/vim/vim/commit/399c297aa93afe2c0a39e2a1b3f972aebba44c9d
CVE-2017-5952
RESERVED
CVE-2017-5951 (The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Softw ...)
@@ -820971,7 +820971,7 @@ CVE-2016-10074 (The mail transport (aka Swift_Transport_MailTransport) in Swift
- libphp-swiftmailer 5.4.2-1.1 (bug #849626)
NOTE: https://legalhackers.com/advisories/SwiftMailer-Exploit-Remote-Code-Exec-CVE-2016-10074-Vuln.html
NOTE: https://github.com/swiftmailer/swiftmailer/issues/844
- NOTE: Fixed by https://github.com/swiftmailer/swiftmailer/commit/e6ccf40d856af9598b76eb313b215eed25ae9e86
+ NOTE: Fixed by: https://github.com/swiftmailer/swiftmailer/commit/e6ccf40d856af9598b76eb313b215eed25ae9e86
CVE-2016-10073 (The from method in library/core/class.email.php in Vanilla Forums befo ...)
NOT-FOR-US: Vanilla Forums
CVE-2016-10072 (WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000. ...)
@@ -825048,7 +825048,7 @@ CVE-2017-2671 (The ping_unhash function in net/ipv4/ping.c in the Linux kernel t
CVE-2017-2670 (It was found in Undertow before 1.3.28 that with non-clean TCP close, ...)
{DSA-3906-1}
- undertow 1.4.18-1 (bug #864405)
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/9bfe9fbbb595d51157b61693f072895f7dbadd1d
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/9bfe9fbbb595d51157b61693f072895f7dbadd1d
NOTE: https://issues.jboss.org/browse/UNDERTOW-1035
CVE-2017-2669 (Dovecot before version 2.2.29 is vulnerable to a denial of service. Wh ...)
- dovecot 1:2.2.27-3 (bug #860049)
@@ -825067,7 +825067,7 @@ CVE-2017-2666 (It was discovered in Undertow that the code that parsed the HTTP
{DSA-3906-1}
- undertow 1.4.18-1 (bug #864405)
NOTE: https://issues.jboss.org/browse/UNDERTOW-1101
- NOTE: Fixed by https://github.com/undertow-io/undertow/commit/1e72647818c9fb31b693a953b1ae595a6c82eb7f
+ NOTE: Fixed by: https://github.com/undertow-io/undertow/commit/1e72647818c9fb31b693a953b1ae595a6c82eb7f
CVE-2017-2665 (The skyring-setup command creates random password for mongodb skyring ...)
NOT-FOR-US: Red Hat Storage / skyring
CVE-2017-2664 (CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8. ...)
@@ -825332,11 +825332,11 @@ CVE-2017-2588
CVE-2017-2587 (A memory allocation vulnerability was found in netpbm before 10.61. A ...)
- netpbm-free <not-affected> (vulnerable code not present)
NOTE: Debian uses an old fork of netpbm
- NOTE: Fixed by http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
+ NOTE: Fixed by: http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
CVE-2017-2586 (A null pointer dereference vulnerability was found in netpbm before 10 ...)
- netpbm-free <not-affected> (vulnerable code not present)
NOTE: Debian uses an old fork of netpbm
- NOTE: Fixed by http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
+ NOTE: Fixed by: http://pkgs.fedoraproject.org/cgit/rpms/netpbm.git/commit/?id=c16a8b893ed77fc3f6f2b382d0d47d03621ed328
CVE-2017-2585 (Red Hat Keycloak before version 2.5.1 has an implementation of HMAC ve ...)
- keycloak <itp> (bug #1088287)
CVE-2017-2584 (arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local ...)
@@ -829193,7 +829193,7 @@ CVE-2017-0842 (An elevation of privilege vulnerability in the Android system (bl
NOT-FOR-US: Fluoride Bluetooth stack in Android
CVE-2017-0841 (A remote code execution vulnerability in the Android system (libutils) ...)
- android-platform-system-core <removed> (unimportant)
- NOTE: Fixed by https://android.googlesource.com/platform/system/core/+/47efc676c849e3abf32001d66e2d6eb887e83c48%5E!/
+ NOTE: Fixed by: https://android.googlesource.com/platform/system/core/+/47efc676c849e3abf32001d66e2d6eb887e83c48%5E!/
CVE-2017-0840 (An information disclosure vulnerability in the Android media framework ...)
NOT-FOR-US: Android media framework
CVE-2017-0839 (An information disclosure vulnerability in the Android media framework ...)
@@ -829232,7 +829232,7 @@ CVE-2017-0823 (An information disclosure vulnerability in the Android system (ri
NOT-FOR-US: Android (rild)
CVE-2017-0822 (An elevation of privilege vulnerability in the Android system (camera) ...)
- android-framework-23 <unfixed> (unimportant)
- NOTE: Fixed by https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a
+ NOTE: Fixed by: https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a
CVE-2017-0821
RESERVED
CVE-2017-0820 (A vulnerability in the Android media framework (n/a). Product: Android ...)
@@ -829382,7 +829382,7 @@ CVE-2017-0753 (A remote code execution vulnerability in the Android libraries (l
NOT-FOR-US: Android (libgdx)
CVE-2017-0752 (A elevation of privilege vulnerability in the Android framework (windo ...)
- android-framework-23 <unfixed> (unimportant)
- NOTE: Fixed by https://android.googlesource.com/platform/frameworks/base/+/6ca2eccdbbd4f11698bd5312812b4d171ff3c8ce%5E%21/
+ NOTE: Fixed by: https://android.googlesource.com/platform/frameworks/base/+/6ca2eccdbbd4f11698bd5312812b4d171ff3c8ce%5E%21/
CVE-2017-0751 (An elevation of privilege vulnerability in the Qualcomm QCE driver. Pr ...)
NOT-FOR-US: Google drivers for Android
CVE-2017-0750 (A elevation of privilege vulnerability in the Upstream Linux file syst ...)
@@ -830772,7 +830772,7 @@ CVE-2016-9584 (libical allows remote attackers to cause a denial of service (use
CVE-2016-9583 (An out-of-bounds heap read vulnerability was found in the jpc_pi_nextp ...)
- jasper <removed> (unimportant)
NOTE: https://github.com/mdadams/jasper/issues/103
- NOTE: Fixed by https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27
+ NOTE: Fixed by: https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27
NOTE: The issue exists due to an overflow check which is not present
NOTE: in Wheezy and Jessie. However it makes sense to implement this check.
NOTE: This can be done when more important issues are found [wheezy].
@@ -831795,9 +831795,9 @@ CVE-2016-9427 (Integer overflow vulnerability in bdwgc before 2016-09-27 allows
- libgc 1:7.6.4-0.3 (bug #844771)
[jessie] - libgc <no-dsa> (Minor issue)
NOTE: https://github.com/ivmai/bdwgc/issues/135
- NOTE: Fixed by https://github.com/ivmai/bdwgc/commit/4e1a6f9d8f2a49403bbd00b8c8e5324048fb84d4
- NOTE: Fixed by https://github.com/ivmai/bdwgc/commit/7292c02fac2066d39dd1bcc37d1a7054fd1e32ee
- NOTE: Fixed by https://github.com/ivmai/bdwgc/commit/552ad0834672fed86ada6430150ef9ebdd3f54d7
+ NOTE: Fixed by: https://github.com/ivmai/bdwgc/commit/4e1a6f9d8f2a49403bbd00b8c8e5324048fb84d4
+ NOTE: Fixed by: https://github.com/ivmai/bdwgc/commit/7292c02fac2066d39dd1bcc37d1a7054fd1e32ee
+ NOTE: Fixed by: https://github.com/ivmai/bdwgc/commit/552ad0834672fed86ada6430150ef9ebdd3f54d7
CVE-2016-9426 (An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3 ...)
- w3m 0.5.3-30
[jessie] - w3m 0.5.3-19+deb8u1
@@ -833713,11 +833713,11 @@ CVE-2016-XXXX [sendmail: Privilege escalation from group smmsp to root]
CVE-2016-8885 (The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1 ...)
- jasper <not-affected> (Incomplete fix for CVE-2016-8690 not applied)
NOTE: https://blogs.gentoo.org/ago/2016/10/18/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c-incomplete-fix-for-cve-2016-8690
- NOTE: Fixed by https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
+ NOTE: Fixed by: https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
CVE-2016-8884 (The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 ...)
- jasper <not-affected> (Incomplete fix for CVE-2016-8690 not applied)
NOTE: https://blogs.gentoo.org/ago/2016/10/18/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c-incomplete-fix-for-cve-2016-8690
- NOTE: Fixed by https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
+ NOTE: Fixed by: https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698
CVE-2016-8883 (The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 ...)
{DLA-739-1}
- jasper <removed> (unimportant)
@@ -837786,22 +837786,22 @@ CVE-2016-7449 (The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.
NOTE: http://hg.code.sf.net/p/graphicsmagick/code/rev/eb58028dacf5
NOTE: https://blogs.gentoo.org/ago/2016/08/23/graphicsmagick-two-heap-based-buffer-overflow-in-readtiffimage-tiff-c/
NOTE: https://blogs.gentoo.org/ago/2016/09/07/graphicsmagick-null-pointer-dereference-in-magickstrlcpy-utility-c/
- NOTE: Fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/eb58028dacf5
+ NOTE: Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/eb58028dacf5
CVE-2016-7448 (The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote atta ...)
{DLA-1401-1 DLA-683-1}
- graphicsmagick 1.3.25-1
- NOTE: Fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/30043afadb10
- NOTE: Fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d972c761b55d
+ NOTE: Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/30043afadb10
+ NOTE: Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d972c761b55d
CVE-2016-7447 (Heap-based buffer overflow in the EscapeParenthesis function in Graphi ...)
{DLA-1401-1 DLA-651-1}
- graphicsmagick 1.3.25-1
- NOTE: Fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d580e3c3c034
+ NOTE: Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/d580e3c3c034
CVE-2016-7446 (Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1. ...)
{DLA-1401-1 DLA-651-1}
- graphicsmagick 1.3.25-1
NOTE: For the http://www.graphicsmagick.org/NEWS.html#september-5-2016 case
NOTE: which remained present in the 1.3.24 release (and was not fixed until 1.3.25)
- NOTE: Fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/6071b5820215
+ NOTE: Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/6071b5820215
CVE-2016-7445 (convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a ...)
- openjpeg2 2.1.2-1 (unimportant; bug #838690)
NOTE: https://github.com/uclouvain/openjpeg/issues/843
@@ -842121,7 +842121,7 @@ CVE-2016-6209 (Cross-site scripting (XSS) vulnerability in Nagios.)
- icinga <not-affected> (Vulnerable code not present)
NOTE: http://seclists.org/fulldisclosure/2016/Jun/20
NOTE: https://github.com/NagiosEnterprises/nagioscore/issues/297
- NOTE: Fixed by https://github.com/NagiosEnterprises/nagioscore/commit/78b7bdde3ab4dec265879ff1b4d49a398bf3ba9c
+ NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/78b7bdde3ab4dec265879ff1b4d49a398bf3ba9c
CVE-2016-6206 (Huawei AR3200 routers with software before V200R007C00SPC600 allow rem ...)
NOT-FOR-US: Huawei
CVE-2016-6205
@@ -842369,8 +842369,8 @@ CVE-2016-6171 (Knot DNS before 2.3.0 allows remote DNS servers to cause a denial
CVE-2016-6170 (ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x throug ...)
- bind9 1:9.10.6+dfsg-1 (unimportant; bug #830810)
NOTE: Not fixed upstream, proposed patches below are unofficial:
- NOTE: Fixed by https://github.com/sischkg/xfer-limit/blob/master/bind-9.10.3-xfer-limit-0.0.1.patch
- NOTE: Fixed by https://github.com/sischkg/xfer-limit/blob/master/bind-9.9.9-P1-xfer-limit-0.0.1.patch
+ NOTE: Fixed by: https://github.com/sischkg/xfer-limit/blob/master/bind-9.10.3-xfer-limit-0.0.1.patch
+ NOTE: Fixed by: https://github.com/sischkg/xfer-limit/blob/master/bind-9.9.9-P1-xfer-limit-0.0.1.patch
NOTE: Negligible security impact
CVE-2016-6163 (The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librs ...)
- librsvg 2.40.9-2
@@ -844453,18 +844453,18 @@ CVE-2016-5421 (Use-after-free vulnerability in libcurl before 7.50.1 allows atta
- curl 7.50.1-1
[wheezy] - curl <not-affected> (introduced in 7.32.0)
NOTE: https://curl.haxx.se/docs/adv_20160803C.html
- NOTE: Fixed by https://curl.haxx.se/CVE-2016-5421.patch
+ NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5421.patch
CVE-2016-5420 (curl and libcurl before 7.50.1 do not check the client certificate whe ...)
{DSA-3638-1 DLA-586-1}
- curl 7.50.1-1
NOTE: https://curl.haxx.se/docs/adv_20160803B.html
- NOTE: Fixed by https://curl.haxx.se/CVE-2016-5420.patch
+ NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5420.patch
NOTE: Wheezy: vulnerable code is in lib/sslgen.c
CVE-2016-5419 (curl and libcurl before 7.50.1 do not prevent TLS session resumption w ...)
{DSA-3638-1 DLA-586-1}
- curl 7.50.1-1
NOTE: https://curl.haxx.se/docs/adv_20160803A.html
- NOTE: Fixed by https://curl.haxx.se/CVE-2016-5419.patch
+ NOTE: Fixed by: https://curl.haxx.se/CVE-2016-5419.patch
NOTE: Wheezy: vulnerable code is in lib/sslgen.c
CVE-2016-5418 (The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlin ...)
{DSA-3677-1 DLA-657-1}
@@ -844976,54 +844976,54 @@ CVE-2015-8928 (The process_add_entry function in archive_read_support_format_mtr
- libarchive 3.2.0-2
[wheezy] - libarchive <not-affected> (vulnerable code not present)
NOTE: https://github.com/libarchive/libarchive/issues/550
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/64d5628
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/64d5628
CVE-2015-8927 (The trad_enc_decrypt_update function in archive_read_support_format_zi ...)
- libarchive 3.2.0-2
[jessie] - libarchive <not-affected> (vulnerable code not present)
[wheezy] - libarchive <not-affected> (vulnerable code not present)
NOTE: https://github.com/libarchive/libarchive/issues/523
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/eff35d4
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/eff35d4
CVE-2015-8926 (The archive_read_format_rar_read_data function in archive_read_support ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/518
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/aab73938
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/aab73938
CVE-2015-8925 (The readline function in archive_read_support_format_mtree.c in libarc ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/516
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/1e18cbb71
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1e18cbb71
CVE-2015-8924 (The archive_read_format_tar_read_header function in archive_read_suppo ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/515
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/bb9b157
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/bb9b157
CVE-2015-8923 (The process_extra function in libarchive before 3.2.0 uses the size fi ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/514
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/9e0689c
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/9e0689c
CVE-2015-8922 (The read_CodersInfo function in archive_read_support_format_7zip.c in ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/513
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/d094dc
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/d094dc
CVE-2015-8921 (The ae_strtofflags function in archive_entry.c in libarchive before 3. ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/512
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/1cbc76f
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/05a875fdb876e7a2f56a2937f756927cbed919e0
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1cbc76f
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/05a875fdb876e7a2f56a2937f756927cbed919e0
CVE-2015-8920 (The _ar_read_header function in archive_read_support_format_ar.c in li ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/511
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/97f964e
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/97f964e
CVE-2015-8919 (The lha_read_file_extended_header function in archive_read_support_for ...)
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/510
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/e8a2e4d
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/e8a2e4d
CVE-2015-8918 (The archive_string_append function in archive_string.c in libarchive b ...)
- libarchive <not-affected> (Vulnerable code not in a released version)
NOTE: Introduced in https://github.com/libarchive/libarchive/commit/cf8e67ffc8a2227b63fc6d3d1569b0214f160f54
@@ -845033,13 +845033,13 @@ CVE-2015-8917 (bsdtar in libarchive before 3.2.0 allows remote attackers to caus
{DSA-3657-1 DLA-554-1}
- libarchive 3.2.0-2
NOTE: https://github.com/libarchive/libarchive/issues/505
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/b2e2abb
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/b2e2abb
CVE-2015-8916 (bsdtar in libarchive before 3.2.0 returns a success code without filli ...)
{DSA-3657-1}
- libarchive 3.2.0-2
[wheezy] - libarchive <not-affected> (no segfault, not reproducible with reproducer)
NOTE: https://github.com/libarchive/libarchive/issues/504
- NOTE: Fixed by https://github.com/libarchive/libarchive/commit/b2e2abb
+ NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/b2e2abb
CVE-2015-8915 (bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a ...)
{DLA-1600-1 DLA-617-1}
- libarchive 3.2.0-2 (low; bug #784213)
@@ -845152,7 +845152,7 @@ CVE-2016-5286
RESERVED
CVE-2016-5285 (A Null pointer dereference vulnerability exists in Mozilla Network Sec ...)
- nss 2:3.25-1
- NOTE: Fixed by https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
+ NOTE: Fixed by: https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
NOTE: Upstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1306103
CVE-2016-5284 (Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunder ...)
{DSA-3674-1 DLA-636-1}
@@ -846418,7 +846418,7 @@ CVE-2016-5017 (Buffer overflow in the C cli shell in Apache Zookeeper before 3.4
NOTE: The C cli shell is intended as a sample/example of how to use the C
NOTE: client interface, not as a production tool
NOTE: https://zookeeper.apache.org/security.html#CVE-2016-5017
- NOTE: Fixed by https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;h=27ecf981a15554dc8e64a28630af7a5c9e2bdf4f
+ NOTE: Fixed by: https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;h=27ecf981a15554dc8e64a28630af7a5c9e2bdf4f
CVE-2016-5016 (Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authe ...)
NOT-FOR-US: Pivotal Cloud Foundry
CVE-2016-5015
@@ -847269,7 +847269,7 @@ CVE-2016-4793 (The clientIp function in CakePHP 3.2.4 and earlier allows remote
[jessie] - cakephp <no-dsa> (Minor issue)
NOTE: http://legalhackers.com/advisories/CakePHP-IP-Spoofing-Vulnerability.txt
NOTE: https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html
- NOTE: Fixed by https://github.com/cakephp/cakephp/commit/48af49ddde16c8b99edb701f1c31283455b2b0b6
+ NOTE: Fixed by: https://github.com/cakephp/cakephp/commit/48af49ddde16c8b99edb701f1c31283455b2b0b6
CVE-2016-4792 (Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to ...)
NOT-FOR-US: Pulse Connect Secure
CVE-2016-4791 (The administrative user interface in Pulse Connect Secure (PCS) 8.2 be ...)
@@ -851917,7 +851917,7 @@ CVE-2016-3092 (The MultipartStream class in Apache Commons Fileupload before 1.3
- tomcat7 7.0.70-1
- tomcat8 8.0.36-1
- tomcat9 <not-affected> (Fixed before initial upload to Debian)
- NOTE: Fixed by https://svn.apache.org/r1743480
+ NOTE: Fixed by: https://svn.apache.org/r1743480
NOTE: Upstream advisory http://markmail.org/message/oyxfv73jb2g7rjg3
NOTE: https://mail-archives.us.apache.org/mod_mbox/www-announce/201606.mbox/%3C6223ece6-2b41-ef4f-22f9-d3481e492832@apache.org%3E
CVE-2016-3091 (Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers ...)
@@ -852605,7 +852605,7 @@ CVE-2016-2848 (ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows
{DLA-672-1}
- bind9 1:9.9.3.dfsg.P2-1 (bug #839051)
NOTE: https://kb.isc.org/article/AA-01433
- NOTE: Fixed by https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4
+ NOTE: Fixed by: https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4
CVE-2016-2846 (Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers ...)
NOT-FOR-US: Siemens SIMATIC S7-1200 CPU devices
CVE-2016-2845 (The Content Security Policy (CSP) implementation in Blink, as used in ...)
@@ -855631,7 +855631,7 @@ CVE-2016-2091 (The dwarf_read_cie_fde_prefix function in dwarf_frame2.c in libdw
- dwarfutils 20160507-1 (bug #813148)
[jessie] - dwarfutils 20120410-2+deb8u1
NOTE: https://www.openwall.com/lists/oss-security/2016/01/19/3
- NOTE: Fixed by http://sourceforge.net/p/libdwarf/code/ci/9565964f26966d8391fe2cfa8e6e8e59278c5f91
+ NOTE: Fixed by: http://sourceforge.net/p/libdwarf/code/ci/9565964f26966d8391fe2cfa8e6e8e59278c5f91
CVE-2016-2090 (Off-by-one vulnerability in the fgetwln function in libbsd before 0.8. ...)
{DLA-2052-1}
- libbsd 0.8.2-1
@@ -856389,7 +856389,7 @@ CVE-2016-2050 (The get_abbrev_array_info function in libdwarf-20151114 allows re
- dwarfutils 20160507+git20160523.9086738-1 (unimportant)
[jessie] - dwarfutils 20120410-2+deb8u1
NOTE: https://www.openwall.com/lists/oss-security/2016/01/19/9
- NOTE: Fixed by http://sourceforge.net/p/libdwarf/code/ci/a05f5e2ae6a5f34daa566975894fc2803d6ec684
+ NOTE: Fixed by: http://sourceforge.net/p/libdwarf/code/ci/a05f5e2ae6a5f34daa566975894fc2803d6ec684
NOTE: Reasoning for "unimportant" severity: The affected source code is present
NOTE: in dwarfdump/, but in the binary package is installed dwarfdump2/ .
NOTE: dwarfdump2 (the C++ implentation) has been abandoned again by upstream in
@@ -862222,7 +862222,7 @@ CVE-2015-8504 (Qemu, when built with VNC display driver support, allows remote a
[squeeze] - qemu <end-of-life> (Not supported in Squeeze LTS)
- qemu-kvm <removed>
[squeeze] - qemu-kvm <end-of-life> (Not supported in Squeeze LTS)
- NOTE: Fixed by http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4c65fed8bdf96780735dbdb92a8bd0d6b6526cc3 (v2.5.0-rc3)
+ NOTE: Fixed by: http://git.qemu.org/?p=qemu.git;a=commitdiff;h=4c65fed8bdf96780735dbdb92a8bd0d6b6526cc3 (v2.5.0-rc3)
NOTE: Issue possibly introduced after http://git.qemu.org/?p=qemu.git;a=commitdiff;h=6cec5487990bf3f1f22b3fcb871978255e92ae0d (v0.10.0)
NOTE: https://www.openwall.com/lists/oss-security/2015/12/08/4
CVE-2016-0200 (Microsoft Internet Explorer 9 through 11 allows remote attackers to ex ...)
@@ -870365,7 +870365,7 @@ CVE-2015-8384 (PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern a
NOTE: https://bugs.exim.org/show_bug.cgi?id=1636
NOTE: related issue to CVE-2015-8392 and CVE-2015-8395
NOTE: Fixed in 8.38
- NOTE: Fixed by http://vcs.pcre.org/pcre?view=revision&revision=1558
+ NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1558
NOTE: Same fixing commit as CVE-2015-3210 but different issues
CVE-2015-8383 (PCRE before 8.38 mishandles certain repeated conditional groups, which ...)
- pcre3 2:8.38-1
@@ -870374,7 +870374,7 @@ CVE-2015-8383 (PCRE before 8.38 mishandles certain repeated conditional groups,
[squeeze] - pcre3 <not-affected> (vulnerable code introduced in 8.34)
NOTE: Fixed in 8.38
NOTE: https://www.openwall.com/lists/oss-security/2015/11/29/1
- NOTE: Fixed by http://vcs.pcre.org/pcre?view=revision&revision=1557
+ NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1557
NOTE: Introduced by/first bad commit: http://vcs.pcre.org/pcre?view=revision&revision=1365
CVE-2015-8382 (The match function in pcre_exec.c in PCRE before 8.37 mishandles the / ...)
- pcre3 2:8.35-7.2 (bug #794589)
@@ -870399,7 +870399,7 @@ CVE-2015-XXXX [Sidekiq::Web lacks CSRF protection]
- ruby-sidekiq 3.4.2~dfsg-3
[jessie] - ruby-sidekiq <no-dsa> (Minor issue)
NOTE: https://github.com/mperham/sidekiq/pull/2422
- NOTE: Fixed by https://github.com/mperham/sidekiq/commit/cf3c43b2410c4573e05ac119494e41115f4140ad
+ NOTE: Fixed by: https://github.com/mperham/sidekiq/commit/cf3c43b2410c4573e05ac119494e41115f4140ad
NOTE: Fix released in sidekiq 3.4.2
NOTE: Follow-up fix: https://github.com/mperham/sidekiq/commit/75a3524c919857aac16e0541b0cb107f48d00694
NOTE: Follow-up commit not included in 3.4.2~dfsg-1
@@ -870408,14 +870408,14 @@ CVE-2015-XXXX [XSS via job arguments display class in Sidekiq::Web]
- ruby-sidekiq 3.4.2~dfsg-3
[jessie] - ruby-sidekiq <no-dsa> (Minor issue)
NOTE: https://github.com/mperham/sidekiq/pull/2309
- NOTE: Fixed by https://github.com/mperham/sidekiq/commit/54766f336620ca0ce3b0b87a7a56382496e64b61
+ NOTE: Fixed by: https://github.com/mperham/sidekiq/commit/54766f336620ca0ce3b0b87a7a56382496e64b61
NOTE: Fix released in sidekiq 3.4.0
NOTE: CVE Request: https://www.openwall.com/lists/oss-security/2015/08/01/2
CVE-2015-XXXX [XSS via queue name in Sidekiq::Web]
- ruby-sidekiq 3.4.2~dfsg-3
[jessie] - ruby-sidekiq <no-dsa> (Minor issue)
NOTE: https://github.com/mperham/sidekiq/issues/2330
- NOTE: Fixed by https://github.com/mperham/sidekiq/commit/2178d66b6686fbf4430223c34c184a64c9906828
+ NOTE: Fixed by: https://github.com/mperham/sidekiq/commit/2178d66b6686fbf4430223c34c184a64c9906828
NOTE: Fix released in sidekiq 3.4.0
NOTE: CVE Request: https://www.openwall.com/lists/oss-security/2015/08/01/2
CVE-2015-5707 (Integer overflow in the sg_start_req function in drivers/scsi/sg.c in ...)
@@ -870424,8 +870424,8 @@ CVE-2015-5707 (Integer overflow in the sg_start_req function in drivers/scsi/sg.
- linux-2.6 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2015/08/01/6
NOTE: Probably introduced in https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=10db10d144c0248f285242f79daf6b9de6b00a62 (v2.6.28-rc1)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81 (v4.1-rc1)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee (v4.1-rc1)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=451a2886b6bf90e2fb378f7c46c655450fb96e81 (v4.1-rc1)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdc81f45e9f57858da6351836507fbcf1b7583ee (v4.1-rc1)
CVE-2015-5706 (Use-after-free vulnerability in the path_openat function in fs/namei.c ...)
- linux 4.0.4-1
[jessie] - linux 3.16.7-ckt11-1+deb8u3
@@ -871851,7 +871851,7 @@ CVE-2015-5244 (The NSSCipherSuite option with ciphersuites enabled in mod_nss be
[jessie] - libapache2-mod-nss <not-affected> (Vulnerability introduced in 1.0.11)
[wheezy] - libapache2-mod-nss <not-affected> (Vulnerability introduced in 1.0.11)
NOTE: Introduced in https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=2d1650900f4d47dc43400d826c0f7e1a7c5229b8 (1.0.11)
- NOTE: Fixed by https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=34e1ccecb4a7d5054dba2f92b403af9b6ae1e110 (1.0.12)
+ NOTE: Fixed by: https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=34e1ccecb4a7d5054dba2f92b403af9b6ae1e110 (1.0.12)
CVE-2015-5243 (phpWhois allows remote attackers to execute arbitrary code via a craft ...)
NOT-FOR-US: phpWhois
CVE-2015-5242 (OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict u ...)
@@ -871935,7 +871935,7 @@ CVE-2015-5221 (Use-after-free vulnerability in the mif_process_cmpt function in
[wheezy] - jasper <no-dsa> (Minor issue)
[squeeze] - jasper <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2015/08/20/4
- NOTE: Fixed by https://github.com/mdadams/jasper/commit/df5d2867e8004e51e18b89865bc4aa69229227b3
+ NOTE: Fixed by: https://github.com/mdadams/jasper/commit/df5d2867e8004e51e18b89865bc4aa69229227b3
CVE-2015-5220 (The Web Console in Red Hat Enterprise Application Platform (EAP) befor ...)
NOT-FOR-US: JBoss EAP
CVE-2015-5219 (The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not proper ...)
@@ -880395,7 +880395,7 @@ CVE-2015-2666 (Stack-based buffer overflow in the get_matching_model_microcode f
[wheezy] - linux <not-affected> (Introduced in 3.9)
- linux-2.6 <not-affected> (Introduced in 3.9)
NOTE: Introduced by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ec400ddeff200b068ddc6c70f7321f49ecf32ed5 (v3.9-rc1)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4 (v4.0-rc1)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4 (v4.0-rc1)
NOTE: https://www.openwall.com/lists/oss-security/2015/03/18/7
CVE-2015-2684 (Shibboleth Service Provider (SP) before 2.5.4 allows remote authentica ...)
{DSA-3207-1 DLA-259-1}
@@ -880405,7 +880405,7 @@ CVE-2015-2672 (The xsave/xrstor implementation in arch/x86/include/asm/xsave.h i
- linux <not-affected> (Vulnerable code not present)
- linux-2.6 <not-affected> (Vulnerable code not present)
NOTE: Introduced by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f31a9f7c71691569359fa7fb8b0acaa44bce0324 (v3.17-rc1)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=06c8173eb92bbfc03a0fe8bb64315857d0badd06 (v4.0-rc3)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=06c8173eb92bbfc03a0fe8bb64315857d0badd06 (v4.0-rc3)
NOTE: https://www.openwall.com/lists/oss-security/2015/03/18/6
CVE-2015-2331 (Integer overflow in the _zip_cdir_new function in zip_dirent.c in libz ...)
{DSA-3198-1 DLA-212-1}
@@ -880582,7 +880582,7 @@ CVE-2014-9701 (Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.1
- mantis <removed> (bug #780875)
[wheezy] - mantis <no-dsa> (Minor issue)
[squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)
- NOTE: Fixed by https://github.com/mantisbt/mantisbt/commit/d95f070d (1.2.x)
+ NOTE: Fixed by: https://github.com/mantisbt/mantisbt/commit/d95f070d (1.2.x)
NOTE: http://article.gmane.org/gmane.comp.security.oss.general/15022
NOTE: https://www.mantisbt.org/bugs/view.php?id=19493
CVE-2014-9697 (Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attack ...)
@@ -882939,7 +882939,7 @@ CVE-2014-9679 (Integer underflow in the cupsRasterReadPixels function in filter/
NOTE: https://www.openwall.com/lists/oss-security/2015/02/10/15
CVE-2015-1573 (The nft_flush_table function in net/netfilter/nf_tables_api.c in the L ...)
- linux <not-affected> (Vulnerable code introduced in v3.18-rc1, never in the archive outside of experimental)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/pablo/nf.git/commit/?id=a2f18db0c68fec96631c10cad9384c196e9008ac (v3.19-rc5)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/pablo/nf.git/commit/?id=a2f18db0c68fec96631c10cad9384c196e9008ac (v3.19-rc5)
NOTE: Introduced by http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9ac12ef099707f405d7478009564302d7ed8393 (v3.18-rc1)
NOTE: https://bugzilla.kernel.org/show_bug.cgi?id=91441
CVE-2015-2046 (Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later ...)
@@ -888906,7 +888906,7 @@ CVE-2015-0274 (The XFS implementation in the Linux kernel before 3.15 improperly
- linux 3.11.5-1
[wheezy] - linux <not-affected> (Introduced in v3.11-rc1)
- linux-2.6 <not-affected> (Introduced in v3.11-rc1)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59 (v3.15-rc5)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8275cdd0e7ac550dcce2b3ef6d2fb3b808c1ae59 (v3.15-rc5)
NOTE: Introduced by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e461fcb194172b3f709e0b478d2ac1bdac7ab9a3 (v3.11-rc1)
CVE-2015-0273 (Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP ...)
{DSA-3195-1}
@@ -890511,7 +890511,7 @@ CVE-2014-8709 (The ieee80211_fragment function in net/mac80211/tx.c in the Linux
- linux 3.14.2-1
[wheezy] - linux 3.2.57-1
- linux-2.6 <removed>
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=338f977f4eb441e69bb9a46eaa0ac715c931a67f (v3.14-rc3)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=338f977f4eb441e69bb9a46eaa0ac715c931a67f (v3.14-rc3)
NOTE: Introduced by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2de8e0d999b8790861cd3749bec2236ccc1c8110 (v2.6.30-rc1)
CVE-2014-8650 (python-requests-Kerberos through 0.5 does not handle mutual authentica ...)
- python-requests-kerberos 0.5-2 (bug #768408)
@@ -892851,7 +892851,7 @@ CVE-2014-7826 (kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2
- linux 3.16.7-ckt2-1
[wheezy] - linux <not-affected> (Vulnerable code introduced later)
- linux-2.6 <not-affected> (Vulnerable code introduced later)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 (v3.18-rc3)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 (v3.18-rc3)
NOTE: Support for SOFT_DISABLE to syscall events was added in https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d562aff93bfb530b0992141500a402d17081189d (v3.13-rc1)
CVE-2014-7825 (kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does ...)
- linux 3.16.7-ckt2-1
@@ -892859,7 +892859,7 @@ CVE-2014-7825 (kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2
- linux-2.6 <removed>
[squeeze] - linux-2.6 <not-affected> (Affected feature not enabled)
NOTE: CONFIG_FTRACE_SYSCALL not enabled in squeeze
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 (v3.18-rc3)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 (v3.18-rc3)
CVE-2014-7824 (D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9. ...)
{DSA-3099-1}
- dbus 1.8.10-1
@@ -892870,7 +892870,7 @@ CVE-2014-7823 (The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remot
[wheezy] - libvirt <not-affected> (Introduced in v1.0.0)
[squeeze] - libvirt <not-affected> (Introduced in v1.0.0)
NOTE: Introduced in http://libvirt.org/git/?p=libvirt.git;a=commit;h=28f8dfdcccd4c0f69063ef741545b37d8a7f7935 (v1.0.0)
- NOTE: Fixed by http://libvirt.org/git/?p=libvirt.git;a=commit;h=b1674ad5a97441b7e1bd5f5ebaff498ef2fbb11b
+ NOTE: Fixed by: http://libvirt.org/git/?p=libvirt.git;a=commit;h=b1674ad5a97441b7e1bd5f5ebaff498ef2fbb11b
CVE-2014-7822 (The implementation of certain splice_write file operations in the Linu ...)
{DSA-3170-1 DLA-155-1}
- linux 3.16.2-1
@@ -898974,7 +898974,7 @@ CVE-2014-5207 (fs/namespace.c in the Linux kernel through 3.16.1 does not proper
- linux 3.16.2-1
[wheezy] - linux <not-affected> (User namespaces only usable in later kernels)
- linux-2.6 <not-affected> (User namespaces only usable in later kernels)
- NOTE: Fixed by https://git.kernel.org/cgit/linux/kernel/git/ebiederm/user-namespace.git/commit/?h=for-linus&id=9566d6742852c527bf5af38af5cbb878dad75705 (v3.17-rc1)
+ NOTE: Fixed by: https://git.kernel.org/cgit/linux/kernel/git/ebiederm/user-namespace.git/commit/?h=for-linus&id=9566d6742852c527bf5af38af5cbb878dad75705 (v3.17-rc1)
NOTE: and: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ffbc6f0ead47fa5a1dc9642b0331cb75c20a640e (v3.17-rc1)
NOTE: Introduced by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0c55cfc4166d9a0f38de779bd4d75a90afbe7734 (v3.8)
NOTE: Thread starting at https://www.openwall.com/lists/oss-security/2014/08/12/6
@@ -902797,7 +902797,7 @@ CVE-2014-3631 (The assoc_array_gc function in the associative-array implementati
[wheezy] - linux <not-affected> (Vulnerable code introduced later)
- linux-2.6 <not-affected> (Vulnerable code introduced later)
NOTE: Introduced by https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b2a4df200d570b2c33a57e1ebfa5896e4bc81b69 (v3.13)
- NOTE: Fixed by http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=95389b08d93d5c06ec63ab49bd732b0069b7c35e
+ NOTE: Fixed by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=95389b08d93d5c06ec63ab49bd732b0069b7c35e
CVE-2014-3630 (XML external entity (XXE) vulnerability in the Java XML processing fun ...)
NOT-FOR-US: Play framework
CVE-2014-3629 (XML external entity (XXE) vulnerability in the XML Exchange module in ...)
@@ -904821,7 +904821,7 @@ CVE-2014-3122 (The try_to_unmap_cluster function in mm/rmap.c in the Linux kerne
- linux-2.6 <removed>
[squeeze] - linux-2.6 2.6.32-48squeeze8
NOTE: Introduced by https://git.kernel.org/linus/b291f000393f5a0b679012b39d79fbc85c018233
- NOTE: Fixed by https://git.kernel.org/linus/57e68e9cd65b4b8eb4045a1e0d0746458502554c (v3.15-rc1)
+ NOTE: Fixed by: https://git.kernel.org/linus/57e68e9cd65b4b8eb4045a1e0d0746458502554c (v3.15-rc1)
CVE-2014-3985 (The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remo ...)
- miniupnpc 1.6-4 (low; bug #748913)
[wheezy] - miniupnpc <not-affected> (Vulnerable code not present)
@@ -907401,7 +907401,7 @@ CVE-2014-2038 (The nfs_can_extend_write function in fs/nfs/write.c in the Linux
[wheezy] - linux <not-affected> (Introduced in 3.11)
- linux-2.6 <not-affected> (Introduced in 3.11)
NOTE: Introduced by https://git.kernel.org/linus/c7559663e42f4294ffe31fe159da6b6a66b35d61
- NOTE: Fixed by https://git.kernel.org/linus/263b4509ec4d47e0da3e753f85a39ea12d1eff24
+ NOTE: Fixed by: https://git.kernel.org/linus/263b4509ec4d47e0da3e753f85a39ea12d1eff24
CVE-2014-2036
RESERVED
CVE-2014-2035 (Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web C ...)
@@ -907737,7 +907737,7 @@ CVE-2014-1878 (Stack-based buffer overflow in the cmd_submitf function in cgi/cm
{DSA-2956-1 DLA-1615-1 DLA-461-1 DLA-60-1}
- icinga 1.10.3-1
- nagios3 <removed> (bug #823721)
- NOTE: Fixed by https://github.com/Icinga/icinga-core/commit/eedf4f7d88cdc50843572224eb38a2f5c78a2dc5
+ NOTE: Fixed by: https://github.com/Icinga/icinga-core/commit/eedf4f7d88cdc50843572224eb38a2f5c78a2dc5
CVE-2014-1873
RESERVED
CVE-2014-1872
@@ -911876,7 +911876,7 @@ CVE-2013-7205 (Off-by-one error in the process_cgivars function in contrib/daemo
[squeeze] - nagios3 <no-dsa> (Minor issue)
[wheezy] - nagios3 <no-dsa> (Minor issue)
NOTE: additional changed files for nagios3, cf. CVE-2013-7108
- NOTE: Fixed by https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
+ NOTE: Fixed by: https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
NOTE: See also https://github.com/Icinga/icinga-core/issues/1399
CVE-2013-7203 (gitolite before commit fa06a34 might allow local users to read arbitra ...)
- gitolite3 3.5.3.1-1
@@ -912035,7 +912035,7 @@ CVE-2013-7108 (Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earli
[wheezy] - nagios3 <no-dsa> (Minor issue)
NOTE: https://dev.icinga.org/issues/5251
NOTE: separate CVE requested for nagios, https://www.openwall.com/lists/oss-security/2013/12/23/4
- NOTE: Fixed by https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
+ NOTE: Fixed by: https://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/
CVE-2013-7107 (Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1 ...)
{DSA-2956-1}
- icinga 1.10.2-1 (low)
@@ -920688,7 +920688,7 @@ CVE-2013-4270 (The net_ctl_permissions function in net/sysctl_net.c in the Linux
- linux 3.11.5-1
[wheezy] - linux <not-affected> (Introduced in 3.8)
NOTE: Introduced with http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cff109768b2d9c03095848f4cd4b0754117262aa
- NOTE: Fixed by http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2433c8f094a008895e66f25bd1773cdb01c91d01
+ NOTE: Fixed by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2433c8f094a008895e66f25bd1773cdb01c91d01
CVE-2013-4269
REJECTED
CVE-2013-4268
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/02a6602450210cc78e77e917a9e03faecc7a980d...783cc5b965982aebe09e745d77a7864048cf4f37
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/02a6602450210cc78e77e917a9e03faecc7a980d...783cc5b965982aebe09e745d77a7864048cf4f37
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/983c4595/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list