Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 53762a70 by Salvatore Bonaccorso at 2024-11-01T20:51:57+01:00 Ignore CVE-2023-30571/libarchive for bookworm We actually might even demote this to unimportant, but needs to be discussed, for details see the discussion in the upstream issue https://github.com/libarchive/libarchive/issues/1876 . - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -120256,10 +120256,13 @@ CVE-2023-30572 RESERVED CVE-2023-30571 (Libarchive through 3.6.2 can cause directories to have world-writable ...) - libarchive <unfixed> (bug #1037093) - [bookworm] - libarchive <no-dsa> (Minor issue) + [bookworm] - libarchive <ignored> (Minor issue; libarchive does not officially support multi-threaded use archive_read_disk and archive_write_disk API functions) [bullseye] - libarchive <no-dsa> (Minor issue) [buster] - libarchive <no-dsa> (Minor issue) NOTE: https://github.com/libarchive/libarchive/issues/1876 + NOTE: libarchive does not officially support multi-threaded use archive_read_disk + NOTE: and archive_write_disk API functions. Upstream aims to clarify the documentation: + NOTE: https://github.com/libarchive/libarchive/issues/1876#issuecomment-1627767567 CVE-2023-29504 (Uncontrolled search path element in some Intel(R) RealSense(TM) Dynami ...) NOT-FOR-US: Intel CVE-2023-29500 (Exposure of sensitive information to an unauthorized actor in BIOS fir ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53762a70d78b0ba5f36530ae7a79f3ccd73c625d -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/53762a70d78b0ba5f36530ae7a79f3ccd73c625d You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits