Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: e730a4f0 by Moritz Muehlenhoff at 2023-10-28T14:43:05+02:00 bullseye/bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -104,9 +104,13 @@ CVE-2023-4967 (Denial of Service in NetScaler ADC and NetScaler Gateway when con NOT-FOR-US: Citrix CVE-2023-46853 (In Memcached before 1.6.22, an off-by-one error exists when processing ...) - memcached 1.6.22-1 + [bookworm] - memcached <no-dsa> (Minor issue) + [bullseye] - memcached <no-dsa> (Minor issue) NOTE: https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa (1.6.22) CVE-2023-46852 (In Memcached before 1.6.22, a buffer overflow exists when processing m ...) - memcached 1.6.22-1 + [bookworm] - memcached <no-dsa> (Minor issue) + [bullseye] - memcached <no-dsa> (Minor issue) NOTE: https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767 (1.6.22) CVE-2023-46604 (Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerabili ...) TODO: check @@ -5199,6 +5203,8 @@ CVE-2023-5256 (In certain scenarios, Drupal's JSON:API module will output error - drupal7 <removed> CVE-2023-5215 (A flaw was found in libnbd. A server can reply with a block size large ...) - libnbd 1.16.5-1 + [bookworm] - libnbd <no-dsa> (Minor issue) + [bullseye] - libnbd <no-dsa> (Minor issue) NOTE: https://listman.redhat.com/archives/libguestfs/2023-September/032635.html NOTE: Fixed by: https://gitlab.com/nbdkit/libnbd/-/commit/0f8ee8c6bd6dd93de771e6d4da87ec5a59504aae (v1.18.0) NOTE: Fixed by: https://gitlab.com/nbdkit/libnbd/-/commit/f03330181229360a1a97a264aa956fea54c657de (v1.16.5) @@ -13374,6 +13380,8 @@ CVE-2023-4067 (The Bus Ticket Booking with Seat Reservation plugin for WordPress NOT-FOR-US: Bus Ticket Booking with Seat Reservation plugin for WordPress CVE-2023-3978 (Text nodes not in the HTML namespace are incorrectly literally rendere ...) - golang-golang-x-net 1:0.14.0-1 (bug #1043163) + [bookworm] - golang-golang-x-net <no-dsa> (Minor issue) + [bullseye] - golang-golang-x-net <no-dsa> (Minor issue) - golang-golang-x-net-dev <removed> [buster] - golang-golang-x-net-dev <postponed> (Limited support, follow bullseye DSAs/point-releases) NOTE: https://go.dev/cl/514896 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e730a4f0cf1bc421d202ffc2e99341fbd9021c98 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e730a4f0cf1bc421d202ffc2e99341fbd9021c98 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits