Markus Koschany pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3a67ffad by Markus Koschany at 2025-01-28T12:04:51+01:00
CVE-2024-26306,iperf3: link to fixing commit

- - - - -
9c86f89f by Markus Koschany at 2025-01-28T13:46:34+01:00
Reserve DLA-4032-1 for iperf3

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -73235,8 +73235,8 @@ CVE-2024-29212 (Due to an  unsafe de-serialization 
method used by the Veeam Serv
 CVE-2024-26306 (iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a 
server wi ...)
        - iperf3 3.17.1-1 (bug #1071751)
        [bookworm] - iperf3 <ignored> (Minor issue)
-       [bullseye] - iperf3 <no-dsa> (Minor issue)
        [buster] - iperf3 <postponed> (Minor issue; can be fixed in next update)
+       NOTE: Fixed by 
https://github.com/esnet/iperf/commit/299b356df6939f71619bf45bf7a7d2222e17d840
 CVE-2023-5052 (vulnerability in Uniform Server Zero, version 10.2.5, 
consisting of an ...)
        NOT-FOR-US: Uniform Zero Server
 CVE-2024-4799 (A vulnerability, which was classified as critical, was found in 
Kaship ...)
@@ -136405,7 +136405,6 @@ CVE-2023-38404 (The XPRTLD web application in Veritas 
InfoScale Operations Manag
 CVE-2023-7250 (A flaw was found in iperf, a utility for testing network 
performance u ...)
        - iperf3 3.15-1
        [bookworm] - iperf3 <ignored> (Minor issue)
-       [bullseye] - iperf3 <no-dsa> (Minor issue)
        [buster] - iperf3 <no-dsa> (Minor issue)
        NOTE: https://downloads.es.net/pub/iperf/esnet-secadv-2023-0002.txt.asc
        NOTE: 
https://github.com/esnet/iperf/commit/5e3704dd850a5df2fb2b3eafd117963d017d07b4 
(3.15)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[28 Jan 2025] DLA-4032-1 iperf3 - security update
+       {CVE-2023-7250 CVE-2024-26306 CVE-2024-53580}
+       [bullseye] - iperf3 3.9-1+deb11u2
 [28 Jan 2025] DLA-4031-1 git - security update
        {CVE-2024-50349 CVE-2024-52006}
        [bullseye] - git 1:2.30.2-1+deb11u4


=====================================
data/dla-needed.txt
=====================================
@@ -117,9 +117,6 @@ gst-plugins-good1.0 (Adrian Bunk)
   NOTE: 20241213: Added by Front-Desk (lamby)
   NOTE: 20241213: See also gst-plugins-base1.0 (lamby)
 --
-iperf3 (Markus Koschany)
-  NOTE: 20250106: Added by Front-Desk (apo)
---
 ipmctl
   NOTE: 20250112: Added by Front-Desk (ta)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/488c9f2f5da9353e7c1ba35e0b54393075c5cd8a...9c86f89f2b85ef1caaa3db81368a7c37f92e600d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/488c9f2f5da9353e7c1ba35e0b54393075c5cd8a...9c86f89f2b85ef1caaa3db81368a7c37f92e600d
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to