Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: bd14594f by Salvatore Bonaccorso at 2022-01-04T14:02:03+01:00 Update information on CVE-2021-45944 - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -908,10 +908,10 @@ CVE-2021-45946 (Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called f CVE-2021-45945 (uWebSockets 19.0.0 through 20.8.0 has an out-of-bounds write in std::_ ...) NOT-FOR-US: uWebSockets CVE-2021-45944 (Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampl ...) - - ghostscript <unfixed> + - ghostscript 9.54.0~dfsg-5 NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29903 NOTE: https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-237.yaml - TODO: check, oss-fuzz "fixing commit" cannot be correct as it only removes a documentation snippet. + NOTE: https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=7861fcad13c497728189feafb41cd57b5b50ea25 CVE-2021-45943 (GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::C ...) [experimental] - gdal 3.4.1~rc1+dfsg-1~exp1 - gdal <unfixed> View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd14594f4481a1e6b5bdc6877c8bf5c239e0f5ee -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd14594f4481a1e6b5bdc6877c8bf5c239e0f5ee You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits