Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d800e5e6 by Sylvain Beucler at 2023-12-23T09:48:25+01:00
CVE-2023-50250/cacti: buster not-affected
- - - - -
a65dc34d by Sylvain Beucler at 2023-12-23T09:49:01+01:00
CVE-2023-50569/cacti: most likely duplicate of CVE-2023-50250
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -104,6 +104,7 @@ CVE-2023-50708 (yii2-authclient is an extension that adds
OpenID, OAuth, OAuth2
CVE-2023-50569 (Reflected Cross Site Scripting (XSS) vulnerability in Cacti
v1.2.25, a ...)
- cacti <unfixed>
NOTE: https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf
+ NOTE: Exact same text as GHSA-xwqc-7jc4-xm73 / CVE-2023-50250.
CVE-2023-50259 (Medusa is an automatic video library manager for TV shows.
Versions pr ...)
TODO: check
CVE-2023-50258 (Medusa is an automatic video library manager for TV shows.
Versions pr ...)
@@ -112,7 +113,9 @@ CVE-2023-50254 (Deepin Linux's default document reader
`deepin-reader` software
- deepin-reader <itp> (bug #970218)
CVE-2023-50250 (Cacti is an open source operational monitoring and fault
management fr ...)
- cacti <unfixed>
+ [buster] - cacti <not-affected> (Vulnerable code introduced later)
NOTE:
https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73
+ NOTE: Introduced by:
https://github.com/Cacti/cacti/commit/27a36d48e1cea172b0750c970324208b39d2bec5
(release/1.2.23)
CVE-2023-50147 (There is an arbitrary command execution vulnerability in the
setDiagno ...)
NOT-FOR-US: TOTOLINK
CVE-2023-49792 (Nextcloud Server provides data storage for Nextcloud, an open
source c ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits