diff --git a/advisories/github-reviewed/2019/07/GHSA-xfhh-rx56-rxcr/GHSA-xfhh-rx56-rxcr.json b/advisories/github-reviewed/2019/07/GHSA-xfhh-rx56-rxcr/GHSA-xfhh-rx56-rxcr.json index eabbe62feb1..9ce3dba611d 100644 --- a/advisories/github-reviewed/2019/07/GHSA-xfhh-rx56-rxcr/GHSA-xfhh-rx56-rxcr.json +++ b/advisories/github-reviewed/2019/07/GHSA-xfhh-rx56-rxcr/GHSA-xfhh-rx56-rxcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfhh-rx56-rxcr", - "modified": "2021-07-27T20:57:14Z", + "modified": "2024-03-07T00:30:48Z", "published": "2019-07-02T15:28:38Z", "aliases": [ "CVE-2019-1020001" @@ -47,6 +47,10 @@ { "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-xfhh-rx56-rxcr" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00006.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-8mq4-9jjh-9xrc/GHSA-8mq4-9jjh-9xrc.json b/advisories/github-reviewed/2024/02/GHSA-8mq4-9jjh-9xrc/GHSA-8mq4-9jjh-9xrc.json index 1efd8edd78b..2ff70415f58 100644 --- a/advisories/github-reviewed/2024/02/GHSA-8mq4-9jjh-9xrc/GHSA-8mq4-9jjh-9xrc.json +++ b/advisories/github-reviewed/2024/02/GHSA-8mq4-9jjh-9xrc/GHSA-8mq4-9jjh-9xrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mq4-9jjh-9xrc", - "modified": "2024-03-01T16:47:19Z", + "modified": "2024-03-07T00:30:48Z", "published": "2024-02-28T18:57:19Z", "aliases": [ "CVE-2024-27285" @@ -67,6 +67,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/yard/CVE-2024-27285.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00006.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json index 5740f60c82e..7a1ec1519c7 100644 --- a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json +++ b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv98-48f2-5vjr", - "modified": "2024-03-03T00:30:33Z", + "modified": "2024-03-07T00:30:48Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2024-26621" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/7432376c913381c5f24d373a87ff629bbde94b47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87632bc9ecff5ded93433bc0fca428019bdd1cfe" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json new file mode 100644 index 00000000000..393e62cf7de --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2gx-4fh8-wm9f", + "modified": "2024-03-07T00:30:49Z", + "published": "2024-03-07T00:30:49Z", + "aliases": [ + "CVE-2024-2236" + ], + "details": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-2236" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268268" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T22:15:57Z" + } +} \ No newline at end of file