Alberto Garcia pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b3071dbb by Alberto Garcia at 2024-10-14T23:43:06+02:00
Some Apple-only WebKit CVEs were incorrectly assigned to WebKitGTK

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5690,12 +5690,7 @@ CVE-2024-40860 (A logic issue was addressed with 
improved checks. This issue is
 CVE-2024-40859 (A permissions issue was addressed with additional 
restrictions. This i ...)
        NOT-FOR-US: Apple
 CVE-2024-40857 (This issue was addressed through improved state management. 
This issue ...)
-       - webkit2gtk 2.46.0-1
-       [buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
-       - wpewebkit 2.46.1-1
-       [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Bookworm)
-       [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
-       NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
+       NOT-FOR-US: Apple
 CVE-2024-40856 (An integrity issue was addressed with Beacon Protection. This 
issue is ...)
        NOT-FOR-US: Apple
 CVE-2024-40852 (This issue was addressed by restricting options offered on a 
locked de ...)
@@ -29682,13 +29677,7 @@ CVE-2024-27851 (The issue was addressed with improved 
bounds checks. This issue
        [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
        NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27850 (This issue was addressed with improvements to the noise 
injection algo ...)
-       {DSA-5695-1}
-       - webkit2gtk 2.44.2-1
-       [buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
-       - wpewebkit 2.44.2-1
-       [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Bookworm)
-       [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
-       NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
+       NOT-FOR-US: Apple
 CVE-2024-27848 (This issue was addressed with improved permissions checking. 
This issu ...)
        NOT-FOR-US: Apple
 CVE-2024-27845 (A privacy issue was addressed with improved handling of 
temporary file ...)
@@ -29720,13 +29709,7 @@ CVE-2024-27832 (The issue was addressed with improved 
checks. This issue is fixe
 CVE-2024-27831 (An out-of-bounds write issue was addressed with improved input 
validat ...)
        NOT-FOR-US: Apple
 CVE-2024-27830 (This issue was addressed through improved state management. 
This issue ...)
-       {DSA-5762-1}
-       - webkit2gtk 2.44.3-1
-       [buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
-       - wpewebkit 2.44.3-1
-       [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Bookworm)
-       [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be 
sensibly backported)
-       NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
+       NOT-FOR-US: Apple
 CVE-2024-27828 (The issue was addressed with improved memory handling. This 
issue is f ...)
        NOT-FOR-US: Apple
 CVE-2024-27820 (The issue was addressed with improved memory handling. This 
issue is f ...)


=====================================
data/DSA/list
=====================================
@@ -90,7 +90,7 @@
        {CVE-2024-23346}
        [bookworm] - pymatgen 2022.11.7+dfsg1-11+deb12u1
 [30 Aug 2024] DSA-5762-1 webkit2gtk - security update
-       {CVE-2024-4558 CVE-2024-40776 CVE-2024-40779 CVE-2024-40780 
CVE-2024-40782 CVE-2024-40785 CVE-2024-40789 CVE-2024-40794 CVE-2024-27830 
CVE-2024-27838 CVE-2024-27851}
+       {CVE-2024-4558 CVE-2024-40776 CVE-2024-40779 CVE-2024-40780 
CVE-2024-40782 CVE-2024-40785 CVE-2024-40789 CVE-2024-40794 CVE-2024-27838 
CVE-2024-27851}
        [bookworm] - webkit2gtk 2.44.3-1~deb12u1
 [29 Aug 2024] DSA-5761-1 chromium - security update
        {CVE-2024-7969 CVE-2024-8193 CVE-2024-8194 CVE-2024-8198}
@@ -323,7 +323,7 @@
        {CVE-2024-5157 CVE-2024-5158 CVE-2024-5159 CVE-2024-5160}
        [bookworm] - chromium 125.0.6422.76-1~deb12u1
 [22 May 2024] DSA-5695-1 webkit2gtk - security update
-       {CVE-2024-27834 CVE-2024-27808 CVE-2024-27820 CVE-2024-27833 
CVE-2024-27850}
+       {CVE-2024-27834 CVE-2024-27808 CVE-2024-27820 CVE-2024-27833}
        [bullseye] - webkit2gtk 2.44.2-1~deb11u1
        [bookworm] - webkit2gtk 2.44.2-1~deb12u1
 [17 May 2024] DSA-5694-1 chromium - security update



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3071dbbe1511219b60035c6c0eded0a8708eed9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3071dbbe1511219b60035c6c0eded0a8708eed9
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to