Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits: a8640782 by Sylvain Beucler at 2024-02-27T11:42:15+01:00 CVE-2023-49084/cacti: follow-up patch + mitigation note - - - - - 8d95dc5b by Sylvain Beucler at 2024-02-27T11:43:48+01:00 CVE-2023-49085/cacti: add note - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -12466,6 +12466,7 @@ CVE-2023-49085 (Cacti provides an operational monitoring and fault management fr - cacti 1.2.26+ds1-1 NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-vr3c-38wh-g855 NOTE: https://github.com/Cacti/cacti/commit/5f451bc680d7584525d18026836af2a1e31b2188 (release/1.2.26) + NOTE: Requires multi-pollers setup CVE-2023-48704 (ClickHouse is an open-source column-oriented database management syste ...) - clickhouse <unfixed> (bug #1059367) [bookworm] - clickhouse <no-dsa> (Minor issue) @@ -12587,6 +12588,8 @@ CVE-2023-49084 (Cacti is a robust performance and fault management framework and - cacti 1.2.26+ds1-1 (bug #1059254) NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp NOTE: https://github.com/Cacti/cacti/commit/5f451bc680d7584525d18026836af2a1e31b2188 (release/1.2.26) + NOTE: https://github.com/Cacti/cacti/commit/c3a647e9867ae8e2982e26342630ba9edb2d94b7 (release/1.2.26) + NOTE: Mitigated in Debian by not shipping or creating 'include/content/' CVE-2023-48723 REJECTED CVE-2023-48722 (Student Result Management System v1.0 is vulnerable to multiple Unauth ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c17c219bb6c244fa50ea884d7a0b4c4bcfb0bf05...8d95dc5bec06c31c652bddd8df274941a82fc993 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c17c219bb6c244fa50ea884d7a0b4c4bcfb0bf05...8d95dc5bec06c31c652bddd8df274941a82fc993 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits