Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3316523f by Salvatore Bonaccorso at 2020-11-29T21:08:05+01:00
Track fixed version for older CVE-2013-4363/CVE-2013-4287
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -325837,7 +325837,7 @@ CVE-2013-4365 (Heap-based buffer overflow in the
fcgid_header_bucket_read functi
CVE-2013-4364 ((1) oo-analytics-export and (2) oo-analytics-import in the
openshift-o ...)
NOT-FOR-US: OpenShift
CVE-2013-4363 (Algorithmic complexity vulnerability in
Gem::Version::ANCHORED_VERSION ...)
- - rubygems <unfixed> (unimportant; bug #722361)
+ - rubygems 3.2.0~rc.1-1 (unimportant; bug #722361)
- libgems-ruby <removed> (unimportant; bug #722361)
NOTE: Non-issue, you trust the site providing the gem with installing
arbitrary code, allowing
NOTE: it a potential elevated CPU consumption doesn't add any extra harm
@@ -326131,7 +326131,7 @@ CVE-2013-4288 (Race condition in PolicyKit (aka
polkit) allows local users to by
[squeeze] - policykit-1 <no-dsa> (The update only deprecates an API and
introduces a new option for pkcheck, no src package uses this API)
[wheezy] - policykit-1 <no-dsa> (The update only deprecates an API and
introduces a new option for pkcheck, no src package uses this API)
CVE-2013-4287 (Algorithmic complexity vulnerability in
Gem::Version::VERSION_PATTERN ...)
- - rubygems <unfixed> (unimportant; bug #722361)
+ - rubygems 3.2.0~rc.1-1 (unimportant; bug #722361)
- libgems-ruby <removed> (unimportant; bug #722361)
NOTE: Non-issue, you trust the site providing the gem with installing
arbitrary code, allowing
NOTE: it a potential elevated CPU consumption doesn't add any extra harm
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3316523f7c8dc0d1b622b5d0dfcf2ccf41f1f52b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3316523f7c8dc0d1b622b5d0dfcf2ccf41f1f52b
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits