Thorsten Alteholz pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b86ff3aa by Thorsten Alteholz at 2025-06-05T23:22:15+02:00
add catdoc

- - - - -
44821199 by Thorsten Alteholz at 2025-06-05T23:25:08+02:00
add modsecurity-apache

- - - - -
780060fe by Thorsten Alteholz at 2025-06-05T23:33:38+02:00
mark some CVEs of python3.9 as not-affected

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -607,6 +607,7 @@ CVE-2025-4517 (Allows arbitrary filesystem writes outside 
the extraction directo
        - python3.12 <unfixed>
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 
3.12)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
        - jython <unfixed>
@@ -624,6 +625,7 @@ CVE-2025-4435 (When using a TarFile.errorlevel = 0and 
extracting with a filter t
        - python3.12 <unfixed>
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 
3.12)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
        - jython <unfixed>
@@ -645,6 +647,7 @@ CVE-2025-4330 (Allows the extraction filter to be ignored, 
allowing symlink targ
        - python3.12 <unfixed>
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 
3.12)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
        - jython <unfixed>
@@ -664,6 +667,7 @@ CVE-2025-4138 (Allows the extraction filter to be ignored, 
allowing symlink targ
        - python3.12 <unfixed>
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 
3.12)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
        - jython <unfixed>
@@ -763,6 +767,7 @@ CVE-2024-12718 (Allows modifying some file metadata (e.g. 
last modified) with fi
        - python3.12 <unfixed>
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (Vulnerable code introduced in 
3.12)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOLed in Bullseye)
        - jython <unfixed>


=====================================
data/dla-needed.txt
=====================================
@@ -55,6 +55,9 @@ busybox
   NOTE: 20250425: Added by Front-Desk (rouca)
   NOTE: 20250519: Asked maintainers about any pending work and offered help.  
(spwhitton)
 --
+catdoc
+  NOTE: 20250605: Added by Front-Desk (ta)
+--
 ceph
   NOTE: 20241205: Added by Front-Desk (santiago)
   NOTE: 20241205: maintainer is preparing an update: 
https://lists.debian.org/debian-lts/2024/12/msg00008.html (santiago/front-desk)
@@ -211,6 +214,9 @@ mina2
   NOTE: 20250114: Patches for CVE-2024-52046 
https://github.com/apache/mina/commit/f9cc5ada6ebef4ee7cc51aac824e42e2e422310e 
(2.2.4) and ... (dleidert)
   NOTE: 20250114: ... 
https://github.com/apache/mina/commit/cdb59eb6131696a440870ab89ad0e20804eb5ca7 
(2.1.10) (dleidert)
 --
+modsecurity-apache
+  NOTE: 20250605: Added by Front-Desk (ta)
+--
 nagvis
   NOTE: 20250117: Added by Front-Desk (rouca)
   NOTE: 20250119: Also check/fix https://bugs.debian.org/1061044



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aecc2f87d3e04c570232a2b417eee61dbde40c57...780060fe6c86f949d9b937e016cf8e07c915b5ff

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aecc2f87d3e04c570232a2b417eee61dbde40c57...780060fe6c86f949d9b937e016cf8e07c915b5ff
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to