Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 613c76f6 by Moritz Muehlenhoff at 2024-01-31T10:02:22+01:00 bookworm/bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: ===================================== data/CVE/list ===================================== @@ -695,6 +695,8 @@ CVE-2024-0918 (A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and class NOT-FOR-US: TRENDnet CVE-2022-48622 (In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows ...) - gdk-pixbuf <unfixed> + [bookworm] - gdk-pixbuf <postponed> (Revisit once fixed upstream) + [bullseye] - gdk-pixbuf <postponed> (Revisit once fixed upstream) [buster] - gdk-pixbuf <postponed> (Minor issue, recheck when fixed upstream) NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/202 CVE-2024-24399 (An arbitrary file upload vulnerability in LeptonCMS v7.0.0 allows auth ...) @@ -1647,11 +1649,13 @@ CVE-2020-36771 (CloudLinux CageFS 7.1.1-1 or below passes the authentication to NOT-FOR-US: CloudLinux CageFS CVE-2023-46840 [VT-d: Failure to quarantine devices in !HVM builds] - xen <unfixed> + [bookworm] - xen <postponed> (Fix along in next update) [bullseye] - xen <not-affected> (Vulnerable code not present) [buster] - xen <not-affected> (Vulnerable code not present) NOTE: https://xenbits.xen.org/xsa/advisory-450.html CVE-2023-46839 [pci: phantom functions assigned to incorrect contexts] - xen <unfixed> + [bookworm] - xen <postponed> (Fix along in next update) [bullseye] - xen <end-of-life> (EOLed in Bullseye) [buster] - xen <end-of-life> (DSA 4677-1) NOTE: https://xenbits.xen.org/xsa/advisory-449.html @@ -27438,8 +27442,10 @@ CVE-2023-40217 (An issue was discovered in Python before 3.8.18, 3.9.x before 3. {DLA-3614-1 DLA-3575-1} - python3.12 3.12.0~rc1-2 - python3.11 3.11.5-1 + [bookworm] - python3.11 <no-dsa> (Minor issue) - python3.10 3.10.13-1 - python3.9 <removed> + [bullseye] - python3.9 <no-dsa> (Minor issue) - python3.7 <removed> - python2.7 <removed> [bullseye] - python2.7 2.7.18-8+deb11u1 ===================================== data/dsa-needed.txt ===================================== @@ -51,11 +51,9 @@ php-horde-turba/oldstable -- phppgadmin -- -py7zr/oldstable --- -python3.11/stable +pillow (jmm) -- -python3.9/oldstable +py7zr/oldstable -- python-asyncssh -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/613c76f6b375190ae32acbebe5783b2e88b939f4 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/613c76f6b375190ae32acbebe5783b2e88b939f4 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits