Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 2e92b0db by Moritz Muehlenhoff at 2024-12-11T10:32:16+01:00 bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1097,6 +1097,7 @@ CVE-2024-55565 (nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. NOTE: https://github.com/ai/nanoid/commit/d643045f40d6dc8afa000a644d857da1436ed08c (3.3.8) CVE-2024-55564 (The POSIX::2008 package before 0.24 for Perl has a potential _execve50 ...) - libposix-2008-perl 0.24-1 + [bookworm] - libposix-2008-perl <no-dsa> (Minor issue) CVE-2024-55563 (Bitcoin Core through 27.2 allows transaction-relay jamming via an off- ...) - bitcoin <removed> CVE-2024-55560 (MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh ...) @@ -11782,6 +11783,7 @@ CVE-2024-47939 (Stack-based buffer overflow vulnerability exists in multiple Ric NOT-FOR-US: Ricoh CVE-2024-21510 (Versions of the package sinatra from 0.0.0 are vulnerable to Reliance ...) - ruby-sinatra <unfixed> (bug #1087290) + [bookworm] - ruby-sinatra <ignored> (Minor issue, too intrusive to backport) NOTE: https://security.snyk.io/vuln/SNYK-RUBY-SINATRA-6483832 NOTE: https://github.com/sinatra/sinatra/pull/2053 NOTE: Rejected upstream fix: https://github.com/sinatra/sinatra/pull/2010 @@ -13411,6 +13413,7 @@ CVE-2024-49767 (Werkzeug is a Web Server Gateway Interface web application libra [bookworm] - python-werkzeug <no-dsa> (Minor issue; can be fixed via point release) [bullseye] - python-werkzeug <not-affected> (Vulnerable code introduced later) - quart 0.19.9-1 (bug #1086063) + [bookworm] - quart <no-dsa> (Minor issue) NOTE: https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2 NOTE: Introduced by: https://github.com/pallets/werkzeug/commit/cbb446fdcada7685fce936ded01b76c08dbd6eb5 (2.0.0rc1) NOTE: Fixed by: https://github.com/pallets/werkzeug/commit/8760275afb72bd10b57d92cb4d52abf759b2f3a7 (3.0.6) @@ -32003,6 +32006,7 @@ CVE-2024-42370 (Litestar is an Asynchronous Server Gateway Interface (ASGI) fram NOT-FOR-US: litestar CVE-2024-42367 (aiohttp is an asynchronous HTTP client/server framework for asyncio an ...) - python-aiohttp 3.10.3-2 + [bookworm] - python-aiohttp <no-dsa> (Minor issue) NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jwhx-xcg6-8xhj NOTE: https://github.com/aio-libs/aiohttp/pull/8653 NOTE: https://github.com/aio-libs/aiohttp/commit/ce2e9758814527589b10759a20783fb03b98339f (v3.10.2) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e92b0db91c5b997fff1f189af1f20a9ba119482 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e92b0db91c5b997fff1f189af1f20a9ba119482 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits