Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9f82e1a7 by Salvatore Bonaccorso at 2023-07-14T23:29:27+02:00
Update status for CVE-2023-38325/python-cryptography
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,9 +9,10 @@ CVE-2023-3434 (Improper Input Validation in the hyperlink
interpretation inSavoi
CVE-2023-3433 (The "nickname" field within Savoir-faire Linux's Jami
application is s ...)
TODO: check
CVE-2023-38325 (The cryptography package before 41.0.2 for Python mishandles
SSH certi ...)
- - python-cryptography <unfixed>
+ - python-cryptography <not-affected> (Vulnerable code not present)
NOTE: https://github.com/pyca/cryptography/issues/9207
NOTE: https://github.com/pyca/cryptography/pull/9208
+ NOTE: Introduced after:
https://github.com/pyca/cryptography/commit/aca8de845e751dd45fe4e48f8492f357d34d1861
(40.0.0)
NOTE: Fixed by:
https://github.com/pyca/cryptography/commit/1ca7adc97b76a9dfbd3d850628b613eb93b78fc3
(main)
NOTE: Fixed by:
https://github.com/pyca/cryptography/commit/e190ef190525999d1f599cf8c3aef5cb7f3a8bc4
(41.0.2)
CVE-2023-38253 (An out-of-bounds read flaw was found in w3m, in the
growbuf_to_Str fun ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9f82e1a7b8be3a490939597f07e94d45d16fd8b2
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9f82e1a7b8be3a490939597f07e94d45d16fd8b2
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits