Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b91c790d by Moritz Muehlenhoff at 2023-08-25T18:39:58+02:00
bullseye/bookworm triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -159586,13 +159586,15 @@ CVE-2021-33391 (An issue in HTACG HTML Tidy v5.7.28
allows attacker to execute a
NOTE: https://github.com/htacg/tidy-html5/issues/946
NOTE:
https://github.com/htacg/tidy-html5/commit/efa61528aa500a1efbd2768121820742d3bb709b
CVE-2021-33390 (dpic 2021.04.10 has a use-after-free in thedeletestringbox()
function ...)
- - dpic 2021.11.01-1
+ - dpic 2021.11.01-1 (unimportant)
NOTE: https://gitlab.com/aplevich/dpic/-/issues/10
NOTE: Fixed by:
https://gitlab.com/aplevich/dpic/-/commit/32c26bb3996511662029c961f5e83fb696c087d4
+ NOTE: Crash in CLI tool, no security impact
CVE-2021-33389
RESERVED
CVE-2021-33388 (dpic 2021.04.10 has a Heap Buffer Overflow in themakevar()
function in ...)
- dpic 2021.11.01-1
+ [bullseye] - dpic <no-dsa> (Minor issue)
NOTE: https://gitlab.com/aplevich/dpic/-/issues/8
NOTE: Fixed by:
https://gitlab.com/aplevich/dpic/-/commit/32c26bb3996511662029c961f5e83fb696c087d4
CVE-2021-33387 (Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows
attacker t ...)
@@ -162214,15 +162216,18 @@ CVE-2021-32424 (In TrendNet TW100-S4W1CA 2.3.32,
due to a lack of proper session
CVE-2021-32423
RESERVED
CVE-2021-32422 (dpic 2021.01.01 has a Global buffer overflow in theyylex()
function in ...)
- - dpic 2021.11.01-1
+ - dpic 2021.11.01-1 (unimportant)
NOTE: https://gitlab.com/aplevich/dpic/-/issues/6
NOTE: Fixed by:
https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
+ NOTE: Crash in CLI tool, no security impact
CVE-2021-32421 (dpic 2021.01.01 has a Heap Use-After-Free in
thedeletestringbox() func ...)
- - dpic 2021.11.01-1
+ - dpic 2021.11.01-1 (unimportant)
NOTE: https://gitlab.com/aplevich/dpic/-/issues/7
NOTE: Fixed by:
https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
+ NOTE: Crash in CLI tool, no security impact
CVE-2021-32420 (dpic 2021.01.01 has a Heap-based Buffer Overflow in
thestorestring fun ...)
- dpic 2021.11.01-1
+ [bullseye] - dpic <no-dsa> (Minor issue)
NOTE: https://gitlab.com/aplevich/dpic/-/issues/5
NOTE: Fixed by:
https://gitlab.com/aplevich/dpic/-/commit/d317e4066c17f9ceb359b3af13264c32f6fb43cf
CVE-2021-32419 (An issue in Schism Tracker v20200412 fixed in v.20200412
allows attack ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -52,6 +52,10 @@ php-horde-turba/oldstable
--
py7zr/oldstable
--
+python3.11/stable
+--
+python3.9/oldstable
+--
python-glance-store/oldstable
--
python-os-brick/oldstable
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b91c790df6aa973246eeb72b286a0bb13255687a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b91c790df6aa973246eeb72b286a0bb13255687a
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits