Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d637fb95 by Salvatore Bonaccorso at 2024-08-21T23:00:24+02:00
Add CVE-2024-43411/ckeditor
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -107,7 +107,14 @@ CVE-2024-5723 (Centreon updateServiceHost SQL Injection
Remote Code Execution Vu
CVE-2024-5335 (The Ultimate Store Kit Elementor Addons, Woocommerce Builder,
EDD Buil ...)
NOT-FOR-US: WordPress plugin
CVE-2024-43411 (CKEditor4 is an open source what-you-see-is-what-you-get HTML
editor. ...)
- TODO: check
+ - ckeditor <unfixed> (unimportant)
+ [bookworm] - ckeditor <not-affected> (Vulnerable code not present)
+ [bullseye] - ckeditor <not-affected> (Vulnerable code not present)
+ NOTE: Introduced after:
https://github.com/ckeditor/ckeditor4/commit/b7b2f4748be71eb01c2f99afefaff002f5061a3e
(4.22.0)
+ NOTE: Fixed by:
https://github.com/ckeditor/ckeditor4/commit/a29e4fd5904da5f2d29dc77da9baac76a14ca266
(4.25.0-lts)
+ NOTE: Fixed by:
https://github.com/ckeditor/ckeditor4/commit/a757c3da466ca01e76505af4b446b3dcde0ae9f5
(4.25.0-lts)
+ NOTE: Fixed by:
https://github.com/ckeditor/ckeditor4/commit/e35bbadc15e2ae76e39b3fc963b851ecc0da4b28
(4.25.0-lts)
+ NOTE: Negligible security impact; feature disabled by default.
CVE-2024-43410 (Russh is a Rust SSH client & server library. Allocating an
untrusted a ...)
TODO: check
CVE-2024-43407 (CKEditor4 is an open source what-you-see-is-what-you-get HTML
editor. ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d637fb95f1a4365feace2e73c90ebca9892c4487
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d637fb95f1a4365feace2e73c90ebca9892c4487
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits