Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits: 3b45831c by Sylvain Beucler at 2023-12-16T11:09:42+01:00 Revert "CVE-2023-39366/cacti: all the code path for the CVE vector appears to be present and similar, re-mark for fix in bullseye & buster" This reverts commit 5c29eb62b001508c57d05b2a6bd48d8baee4b67f. The 'org.val()' bit triggers the vulnerability and is indeed not present in bullseye. - - - - - 9e1f8ac4 by Sylvain Beucler at 2023-12-16T11:09:46+01:00 CVE-2023-39366/cacti: buster not-affected + introductory commit - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -17207,9 +17207,11 @@ CVE-2023-39510 (Cacti is an open source operational monitoring and fault managem CVE-2023-39366 (Cacti is an open source operational monitoring and fault management fr ...) - cacti 1.2.25+ds1-1 [bookworm] - cacti 1.2.24+ds1-1+deb12u1 - [bullseye] - cacti <no-dsa> (Minor issue) + [bullseye] - cacti <not-affected> (Vulnerable code not present) + [buster] - cacti <not-affected> (Vulnerable code introduced later) NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-rwhh-xxm6-vcrv NOTE: https://github.com/Cacti/cacti/commit/c67daa614d91c8592b8792298da8e3aa017c4009 + NOTE: Introduced by: https://github.com/Cacti/cacti/commit/befc9005e99fdb44aa4b09b87fadced2f21539a6 (release/1.2.20) CVE-2023-39365 (Cacti is an open source operational monitoring and fault management fr ...) {DSA-5550-1} - cacti 1.2.25+ds1-1 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a48de1ef8cbcde225409b21afc331b41565b93b4...9e1f8ac45de4d5f13c4c673c105d856635291f13 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a48de1ef8cbcde225409b21afc331b41565b93b4...9e1f8ac45de4d5f13c4c673c105d856635291f13 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits