Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 650f425c by Salvatore Bonaccorso at 2023-02-04T09:36:50+01:00 Track fixed version for two CVEs in php-dompdf One is actually unlear if the older version are affected: CVE-2023-23924, which may affect only a specific version. Needs review. - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -3279,7 +3279,7 @@ CVE-2023-23926 CVE-2023-23925 (Switcher Client is a JavaScript SDK to work with Switcher API which is ...) TODO: check CVE-2023-23924 (Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 ...) - - php-dompdf <undetermined> + - php-dompdf 2.0.2+dfsg-1 NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg NOTE: https://github.com/dompdf/dompdf/commit/7558f07f693b2ac3266089f21051e6b78c6a0c85 CVE-2023-23923 @@ -46860,7 +46860,7 @@ CVE-2022-2402 (The vulnerability in the driver dlpfde.sys enables a user logged CVE-2022-2401 (Unrestricted information disclosure of all users in Mattermost version ...) - mattermost-server <itp> (bug #823556) CVE-2022-2400 (External Control of File Name or Path in GitHub repository dompdf/domp ...) - - php-dompdf <unfixed> (bug #1015874) + - php-dompdf 2.0.2+dfsg-1 (bug #1015874) NOTE: https://huntr.dev/bounties/a6da5e5e-86be-499a-a3c3-2950f749202a NOTE: https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6a CVE-2022-2399 (Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allow ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/650f425cee682a5f47ae4ebe6ccc25ffb66caf86 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/650f425cee682a5f47ae4ebe6ccc25ffb66caf86 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits