From 3110388b2c4e502c6df975cbf45c63be8e43e859 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 Feb 2024 03:31:45 +0000 Subject: [PATCH] Publish Advisories GHSA-v95c-p5hm-xq8f GHSA-rcjv-mgp8-qvmr GHSA-8459-gg55-8qjj GHSA-8mxm-4gjm-vrc7 GHSA-j9jp-j2w9-gw9c GHSA-p647-4jrw-p827 GHSA-pv4h-p8jr-6cv2 GHSA-v5qp-mx94-j49v GHSA-x57x-3c65-5f3j GHSA-xcvq-77qq-2wpx --- .../GHSA-v95c-p5hm-xq8f.json | 6 ++- .../GHSA-rcjv-mgp8-qvmr.json | 6 ++- .../GHSA-8459-gg55-8qjj.json | 10 ++++- .../GHSA-8mxm-4gjm-vrc7.json | 6 ++- .../GHSA-j9jp-j2w9-gw9c.json | 39 +++++++++++++++++ .../GHSA-p647-4jrw-p827.json | 43 +++++++++++++++++++ .../GHSA-pv4h-p8jr-6cv2.json | 10 ++++- .../GHSA-v5qp-mx94-j49v.json | 6 ++- .../GHSA-x57x-3c65-5f3j.json | 6 ++- .../GHSA-xcvq-77qq-2wpx.json | 6 ++- 10 files changed, 130 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json diff --git a/advisories/github-reviewed/2021/12/GHSA-v95c-p5hm-xq8f/GHSA-v95c-p5hm-xq8f.json b/advisories/github-reviewed/2021/12/GHSA-v95c-p5hm-xq8f/GHSA-v95c-p5hm-xq8f.json index 351e5be0be2..5026da9003b 100644 --- a/advisories/github-reviewed/2021/12/GHSA-v95c-p5hm-xq8f/GHSA-v95c-p5hm-xq8f.json +++ b/advisories/github-reviewed/2021/12/GHSA-v95c-p5hm-xq8f/GHSA-v95c-p5hm-xq8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v95c-p5hm-xq8f", - "modified": "2023-08-29T22:55:54Z", + "modified": "2024-02-19T03:30:23Z", "published": "2021-12-07T21:22:39Z", "aliases": [ "CVE-2021-43784" @@ -72,6 +72,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00005.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00005.html" + }, { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2022-0274" diff --git a/advisories/github-reviewed/2023/10/GHSA-rcjv-mgp8-qvmr/GHSA-rcjv-mgp8-qvmr.json b/advisories/github-reviewed/2023/10/GHSA-rcjv-mgp8-qvmr/GHSA-rcjv-mgp8-qvmr.json index 32d2c45649d..a8e94b4b371 100644 --- a/advisories/github-reviewed/2023/10/GHSA-rcjv-mgp8-qvmr/GHSA-rcjv-mgp8-qvmr.json +++ b/advisories/github-reviewed/2023/10/GHSA-rcjv-mgp8-qvmr/GHSA-rcjv-mgp8-qvmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcjv-mgp8-qvmr", - "modified": "2023-10-20T16:17:49Z", + "modified": "2024-02-19T03:30:24Z", "published": "2023-10-16T14:01:54Z", "aliases": [ "CVE-2023-45142" @@ -189,6 +189,10 @@ { "type": "WEB", "url": "https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2UTRJ54INZG3OC2FTAN6AFB2RYNY2GAD" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json index 170350e1cec..95cbf29bccf 100644 --- a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json +++ b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8459-gg55-8qjj", - "modified": "2024-02-18T03:30:23Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50387" @@ -42,6 +42,14 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50387" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" diff --git a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json index 33d5483c084..8254452e737 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json +++ b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mxm-4gjm-vrc7", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-6516" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-6516" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json b/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json new file mode 100644 index 00000000000..6db5aeb6219 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9jp-j2w9-gw9c", + "modified": "2024-02-19T03:30:24Z", + "published": "2024-02-19T03:30:24Z", + "aliases": [ + "CVE-2020-36774" + ], + "details": "plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36774" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/glade/-/commit/7acdd3c6f6934f47b8974ebc2190a59ea5d2ed17" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/glade/-/issues/479" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-19T02:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json b/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json new file mode 100644 index 00000000000..5fd715ad69c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p647-4jrw-p827", + "modified": "2024-02-19T03:30:24Z", + "published": "2024-02-19T03:30:24Z", + "aliases": [ + "CVE-2022-48624" + ], + "details": "close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48624" + }, + { + "type": "WEB", + "url": "https://github.com/gwsw/less/commit/c6ac6de49698be84d264a0c4c0c40bb870b10144" + }, + { + "type": "WEB", + "url": "https://github.com/gwsw/less/compare/v605...v606" + }, + { + "type": "WEB", + "url": "https://greenwoodsoftware.com/less" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-19T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json index 1f6479a0027..0b1fef3955a 100644 --- a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json +++ b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv4h-p8jr-6cv2", - "modified": "2024-02-18T03:30:23Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50868" @@ -42,6 +42,14 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50868" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index 352992110c6..8759a364782 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5qp-mx94-j49v", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5679" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5679" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json index f5204239c69..c7b7bba4811 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json +++ b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x57x-3c65-5f3j", - "modified": "2024-02-13T18:38:22Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-4408" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-4408" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" diff --git a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json index 3bbe24c20eb..979fbf01412 100644 --- a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json +++ b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcvq-77qq-2wpx", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-02-19T03:30:24Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5517" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5517" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1"