Markus Koschany pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b2937ef2 by Markus Koschany at 2023-07-30T18:14:56+02:00
CVE-2023-28864,chef: Link to CVE description, impact, remediation

- - - - -
69777e69 by Markus Koschany at 2023-07-30T18:19:38+02:00
Add chef to dla-needed.txt

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -16736,6 +16736,7 @@ CVE-2023-28865
        RESERVED
 CVE-2023-28864 (Progress Chef Infra Server before 15.7 allows a local attacker 
to expl ...)
        - chef <removed>
+       NOTE: 
https://blog.mondoo.com/chef-infra-server-cve-2023-28864-impact-and-remediation
 CVE-2023-28863 (AMI MegaRAC SPx12 and SPx13 devices have Insufficient 
Verification of  ...)
        NOT-FOR-US: AMI
 CVE-2023-28862 (An issue was discovered in LemonLDAP::NG before 2.16.1. Weak 
session I ...)


=====================================
data/dla-needed.txt
=====================================
@@ -28,6 +28,10 @@ cairosvg (gladk)
   NOTE: 20230323: Added by Front-Desk (gladk)
   NOTE: 20230411: Proposed solution for CVE-2023-27586 in Buster to backport 
the --unsafe switch, introduced in 1.0.21, might work (dleidert/inactive)
 --
+chef
+  NOTE: 20230730: Added by Front-Desk (apo)
+  NOTE: 20230730: We could just change the directory permissions to fix this 
problem. (apo)
+--
 cinder
   NOTE: 20230525: Added by Front-Desk (lamby)
   NOTE: 20230525: NB. CVE-2023-2088 filed against python-glance-store, 
python-os-brick, nova and cinder.



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9b292c0b0fb6fa7a0a32a20c64568eed8d52dccf...69777e6973ea60298995886e72699fb2d3496513

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9b292c0b0fb6fa7a0a32a20c64568eed8d52dccf...69777e6973ea60298995886e72699fb2d3496513
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to