Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 67e6f0ee by Salvatore Bonaccorso at 2024-10-19T16:13:24+02:00 Add buildah references from v1.37.5 tag The commit for CVE-2024-9675 was indeed cherry-picked in the 1.37.4+ds1-1 version as well. Link: https://github.com/containers/buildah/releases/tag/v1.37.5 - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -981,6 +981,7 @@ CVE-2024-9676 (A vulnerability was found in Podman, Buildah, and CRI-O. A symlin - podman <unfixed> NOTE: https://github.com/advisories/GHSA-wq2p-5pc6-wpgf NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2317467 + NOTE: https://github.com/containers/buildah/pull/5786 CVE-2024-9506 (Improper regular expression in Vue's parseHTML function leads to a pot ...) NOT-FOR-US: Vue CVE-2024-5749 (Certain HP DesignJet products may be vulnerable to credential reflecti ...) @@ -2193,6 +2194,7 @@ CVE-2024-9675 (A vulnerability was found in Buildah. Cache mounts do not properl [bookworm] - golang-github-containers-buildah <no-dsa> (Minor issue) [bullseye] - golang-github-containers-buildah <postponed> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2317458 + NOTE: https://github.com/containers/buildah/pull/5780 CVE-2024-9671 (A vulnerability was found in 3Scale. There is no auth mechanism to see ...) NOT-FOR-US: Red Hat 3scale CVE-2024-9575 (Local File Inclusion vulnerability in pretix Widget WordPress plugin p ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67e6f0eec260bf9e0791aebeefb6e55b3b4c97a3 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67e6f0eec260bf9e0791aebeefb6e55b3b4c97a3 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
