Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2baea94 by Chris Lamb at 2023-12-31T12:16:40+00:00
Triage CVE-2023-48795 in filezilla for buster LTS.

- - - - -
36f36cc3 by Chris Lamb at 2023-12-31T12:17:05+00:00
Triage CVE-2023-51714 in qtbase-opensource-src for buster LTS.

- - - - -
7d3d77b8 by Chris Lamb at 2023-12-31T12:18:19+00:00
data/dla-needed.txt: Triage tiff for buster LTS (CVE-2023-3576)

- - - - -
7de46bd4 by Chris Lamb at 2023-12-31T12:22:16+00:00
Add upstream commit references for CVE-2023-49093 in htmlunit & 
jenkins-htmlunit-core-js

- - - - -
46294fe9 by Chris Lamb at 2023-12-31T12:27:45+00:00
data/dla-needed.txt: Triage jenkins-htmlunit-core-js for buster LTS 
(CVE-2023-49093)

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -803,6 +803,7 @@ CVE-2023-51714 (An issue was discovered in the HTTP2 
implementation in Qt before
        - qtbase-opensource-src <unfixed>
        [bookworm] - qtbase-opensource-src <no-dsa> (Minor issue)
        [bullseye] - qtbase-opensource-src <no-dsa> (Minor issue)
+       [buster] - qtbase-opensource-src <no-dsa> (Minor issue)
        - qtbase-opensource-src-gles <unfixed>
        [bookworm] - qtbase-opensource-src-gles <no-dsa> (Minor issue)
        [bullseye] - qtbase-opensource-src-gles <no-dsa> (Minor issue)
@@ -2147,6 +2148,7 @@ CVE-2023-48795 (The SSH transport protocol with certain 
OpenSSH extensions, foun
        - filezilla 3.66.4-1
        [bookworm] - filezilla <no-dsa> (Minor issue)
        [bullseye] - filezilla <no-dsa> (Minor issue)
+       [buster] - filezilla <no-dsa> (Minor issue)
        - golang-go.crypto <unfixed> (bug #1059003)
        - jsch <not-affected> (ChaCha20-Poly1305 support introduced in 0.1.61; 
*-EtM support introduced in 0.1.58)
        - libssh 0.10.6-1 (bug #1059004)
@@ -5284,6 +5286,8 @@ CVE-2023-49093 (HtmlUnit is a GUI-less browser for Java 
programs. HtmlUnit is vu
        - jenkins-htmlunit-core-js <removed>
        - htmlunit <removed>
        NOTE: 
https://github.com/HtmlUnit/htmlunit/security/advisories/GHSA-37vq-hr2f-g7h7
+       NOTE: 
https://github.com/HtmlUnit/htmlunit/commit/e015082aa909fd9e1c2b5f9b26553ddc0ddbbcab
+       NOTE: 
https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b
 CVE-2023-47701 (IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect 
Server) 10.5 ...)
        NOT-FOR-US: IBM
 CVE-2023-46167 (IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect 
Server) 11.5 ...)


=====================================
data/dla-needed.txt
=====================================
@@ -98,6 +98,14 @@ imagemagick
   NOTE: 20230622: Requested by maintainer (rouca) to tidy remaining open CVEs 
(Beuc/front-desk)
   NOTE: 20231014: Some work under git branch debian/buster but unease
 --
+jenkins-htmlunit-core-js
+  NOTE: 20231231: Added by Front-Desk (lamby)
+  NOTE: 20231231: Needs checking that this is definitely vulnerable: a quick 
glance
+  NOTE: 20231231: … suggests that the embedded copy of htmlunit is very old 
and may
+  NOTE: 20231231: … not even support XLST processing. However, it does use the
+  NOTE: 20231231: … TransformerFactory without setting the ~secure flag, so it 
may
+  NOTE: 20231231: … indeed be vulnerable. (lamby)
+--
 keystone
   NOTE: 20231102: Added by Front-Desk (lamby)
   NOTE: 20231102: Sync (eg. CVE-2021-38155) with stable etc. (lamby)
@@ -250,6 +258,10 @@ suricata (Adrian Bunk)
   NOTE: 20231016: Still reviewing+testing CVEs. (bunk)
   NOTE: 20231120: DLA coming soon. (bunk)
 --
+tiff
+  NOTE: 20231231: Added by Front-Desk (lamby)
+  NOTE: 20231231: CVE-2023-3576 already fixed in bullseye via DSA or point 
release(s). (lamby)
+--
 tinymce
   NOTE: 20231123: Added by Front-Desk (ola)
   NOTE: 20231216: Someone with more XSS experience needed to assess the



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ca8ce7390e8ffa33ef93fccee9734db8047563ec...46294fe95d55a442c022843bb1b143758a1d7bca

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ca8ce7390e8ffa33ef93fccee9734db8047563ec...46294fe95d55a442c022843bb1b143758a1d7bca
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to