From 00a9ae21c75a111368448e0c2957d11e4f7f3f33 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 21 Nov 2024 22:14:34 +0000 Subject: [PATCH] Publish Advisories GHSA-jcjp-qqpq-pc54 GHSA-jvp9-phwp-p738 GHSA-jcjp-qqpq-pc54 GHSA-jvp9-phwp-p738 --- .../GHSA-jcjp-qqpq-pc54.json | 116 ++++++++++++++++++ .../GHSA-jvp9-phwp-p738.json | 65 ++++++++++ .../GHSA-jcjp-qqpq-pc54.json | 79 ------------ .../GHSA-jvp9-phwp-p738.json | 38 ------ 4 files changed, 181 insertions(+), 117 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json create mode 100644 advisories/github-reviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json delete mode 100644 advisories/unreviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json diff --git a/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json b/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json new file mode 100644 index 00000000000..9b2f2fac3e6 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json @@ -0,0 +1,116 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcjp-qqpq-pc54", + "modified": "2024-11-21T22:13:08Z", + "published": "2022-05-01T07:09:18Z", + "aliases": [ + "CVE-2006-3458" + ], + "summary": "Zope allows local users to read arbitrary files", + "details": "Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the \"raw\" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "Zope2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Zope2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Zope2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.9.0" + }, + { + "fixed": "2.9.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2006-3458" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27636" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zope2/PYSEC-2006-7.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/zopefoundation/Zope" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/317-1" + }, + { + "type": "WEB", + "url": "http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2006/dsa-1113" + }, + { + "type": "WEB", + "url": "http://www.novell.com/linux/security/advisories/2006_19_sr.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-11-21T22:13:08Z", + "nvd_published_at": "2006-07-07T23:05:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json b/advisories/github-reviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json new file mode 100644 index 00000000000..f443314129b --- /dev/null +++ b/advisories/github-reviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvp9-phwp-p738", + "modified": "2024-11-21T22:14:08Z", + "published": "2022-11-18T00:30:18Z", + "aliases": [ + "CVE-2022-43171" + ], + "summary": "LIEF heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind", + "details": "A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF prior to version 0.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lief" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43171" + }, + { + "type": "WEB", + "url": "https://github.com/lief-project/LIEF/issues/782" + }, + { + "type": "PACKAGE", + "url": "https://github.com/lief-project/LIEF" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/lief/PYSEC-2022-43140.yaml" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-11-21T22:14:08Z", + "nvd_published_at": "2022-11-17T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json b/advisories/unreviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json deleted file mode 100644 index 39ee1f4c9d3..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-jcjp-qqpq-pc54/GHSA-jcjp-qqpq-pc54.json +++ /dev/null @@ -1,79 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-jcjp-qqpq-pc54", - "modified": "2022-05-01T07:09:18Z", - "published": "2022-05-01T07:09:18Z", - "aliases": [ - "CVE-2006-3458" - ], - "details": "Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the \"raw\" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2006-3458" - }, - { - "type": "WEB", - "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27636" - }, - { - "type": "WEB", - "url": "https://usn.ubuntu.com/317-1" - }, - { - "type": "WEB", - "url": "http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/20988" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/21025" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/21130" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/21459" - }, - { - "type": "WEB", - "url": "http://www.debian.org/security/2006/dsa-1113" - }, - { - "type": "WEB", - "url": "http://www.novell.com/linux/security/advisories/2006_19_sr.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/18856" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2006/2681" - }, - { - "type": "WEB", - "url": "http://www.zope.org/Products/Zope/Hotfix-2006-07-05/Hotfix-20060705/README.txt" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2006-07-07T23:05:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json b/advisories/unreviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json deleted file mode 100644 index 30d7fc55914..00000000000 --- a/advisories/unreviewed/2022/11/GHSA-jvp9-phwp-p738/GHSA-jvp9-phwp-p738.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-jvp9-phwp-p738", - "modified": "2022-11-21T21:30:14Z", - "published": "2022-11-18T00:30:18Z", - "aliases": [ - "CVE-2022-43171" - ], - "details": "A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43171" - }, - { - "type": "WEB", - "url": "https://github.com/lief-project/LIEF/issues/782" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-787" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-11-17T23:15:00Z" - } -} \ No newline at end of file