Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a6eaadfb by Chris Lamb at 2021-08-06T10:02:25+01:00
Triage CVE-2021-3622 in hivex for stretch LTS.
- - - - -
9f9018ac by Chris Lamb at 2021-08-06T10:02:48+01:00
Triage CVE-2021-38115 in libgd2 for stretch LTS.
- - - - -
e1f56a4d by Chris Lamb at 2021-08-06T10:03:16+01:00
Triage CVE-2021-37832 & CVE-2021-37833 in hoteldruid for stretch LTS.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -72,6 +72,7 @@ CVE-2021-38115 (read_header_tga in gd_tga.c in the GD
Graphics Library (aka LibG
- libgd2 <unfixed> (bug #991912)
[bullseye] - libgd2 <no-dsa> (Minor issue)
[buster] - libgd2 <no-dsa> (Minor issue)
+ [stretch] - libgd2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgd/libgd/issues/697
NOTE:
https://github.com/libgd/libgd/commit/8b111b2b4a4842179be66db68d84dda91a246032
CVE-2021-38114 (libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return
value of ...)
@@ -681,11 +682,13 @@ CVE-2021-37833 (A reflected cross-site scripting (XSS)
vulnerability exists in m
- hoteldruid <unfixed> (bug #991910)
[bullseye] - hoteldruid <no-dsa> (Minor issue)
[buster] - hoteldruid <no-dsa> (Minor issue)
+ [stretch] - hoteldruid <no-dsa> (Minor issue)
NOTE: https://github.com/dievus/CVE-2021-37833
CVE-2021-37832 (A SQL injection vulnerability exists in version 3.0.2 of Hotel
Druid w ...)
- hoteldruid <unfixed> (bug #991910)
[bullseye] - hoteldruid <no-dsa> (Minor issue)
[buster] - hoteldruid <no-dsa> (Minor issue)
+ [stretch] - hoteldruid <no-dsa> (Minor issue)
NOTE: https://github.com/dievus/CVE-2021-37832
CVE-2021-37831
RESERVED
@@ -5894,6 +5897,7 @@ CVE-2021-3622
- hivex <unfixed> (bug #991860)
[bullseye] - hivex <no-dsa> (Minor issue)
[buster] - hivex <no-dsa> (Minor issue)
+ [stretch] - hivex <no-dsa> (Minor issue)
NOTE:
https://listman.redhat.com/archives/libguestfs/2021-August/msg00002.html
NOTE:
https://github.com/libguestfs/hivex/commit/771728218dac2fbf6997a7e53225e75a4c6b7255
CVE-2021-35501 (PandoraFMS <=7.54 allows Stored XSS by placing a payload in
the nam ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/72a0612b3cec2f059aa81f4cc35b203775bdf7bf...e1f56a4d5649631e449c662474e9cb90b0c29622
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/72a0612b3cec2f059aa81f4cc35b203775bdf7bf...e1f56a4d5649631e449c662474e9cb90b0c29622
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits