Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 442c50d4 by Moritz Muehlenhoff at 2024-11-11T20:47:16+01:00 mark CVE-2023-50782 as fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -89017,7 +89017,7 @@ CVE-2023-40921 (SQL Injection vulnerability in functions/point_list.php in Commo CVE-2023-31546 (Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows atta ...) NOT-FOR-US: DedeBIZ CVE-2023-50782 (A flaw was found in the python-cryptography package. This issue may al ...) - - python-cryptography <unfixed> (bug #1059308) + - python-cryptography 42.0.5-1 (bug #1059308) [bookworm] - python-cryptography <ignored> (Minor issue, fix relies on OpenSSL 3.2 interfaces) [bullseye] - python-cryptography <ignored> (Minor issue, fix relies on OpenSSL 3.2 interfaces) [buster] - python-cryptography <no-dsa> (Minor issue; it's an incomplete fix of CVE-2020-25659) @@ -89025,8 +89025,8 @@ CVE-2023-50782 (A flaw was found in the python-cryptography package. This issue NOTE: https://people.redhat.com/~hkario/marvin/ NOTE: https://github.com/openssl/openssl/pull/13817 NOTE: CVE is for incomplete fix of CVE-2020-25659 - NOTE: The fix relies on OpenSSL 3.2, we can mark this as fixed when openssl 3.2 lands - NOTE: in unstable + NOTE: The fix relies on OpenSSL 3.2, marking the first 42.x upload to unstable as fixed, + NOTE: openssl 3.2 was uploaded to unstable shortly after CVE-2023-50781 (A flaw was found in m2crypto. This issue may allow a remote attacker t ...) - m2crypto <unfixed> (bug #1059292) [bookworm] - m2crypto <postponed> (Minor issue, revisit when fixed upstream) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/442c50d4a5af3a9fb04fa9991b173dd2f279b849 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/442c50d4a5af3a9fb04fa9991b173dd2f279b849 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits