Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bd14594f by Salvatore Bonaccorso at 2022-01-04T14:02:03+01:00
Update information on CVE-2021-45944

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -908,10 +908,10 @@ CVE-2021-45946 (Wasm3 0.5.0 has an out-of-bounds write in 
CompileBlock (called f
 CVE-2021-45945 (uWebSockets 19.0.0 through 20.8.0 has an out-of-bounds write 
in std::_ ...)
        NOT-FOR-US: uWebSockets
 CVE-2021-45944 (Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free 
in sampl ...)
-       - ghostscript <unfixed>
+       - ghostscript 9.54.0~dfsg-5
        NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29903
        NOTE: 
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-237.yaml
-       TODO: check, oss-fuzz "fixing commit" cannot be correct as it only 
removes a documentation snippet.
+       NOTE: 
https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=7861fcad13c497728189feafb41cd57b5b50ea25
 CVE-2021-45943 (GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in 
PCIDSK::C ...)
        [experimental] - gdal 3.4.1~rc1+dfsg-1~exp1
        - gdal <unfixed>



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd14594f4481a1e6b5bdc6877c8bf5c239e0f5ee

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd14594f4481a1e6b5bdc6877c8bf5c239e0f5ee
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to