Publish Advisories

GHSA-jp4x-w63m-7wgm
GHSA-2888-q29x-2g3p
GHSA-fxjr-wp58-m6x4
GHSA-mh23-v522-9fqx
GHSA-w6wj-g5cv-fh4w
GHSA-whfc-j75v-mxjv
This commit is contained in:
advisory-database[bot]
2023-04-11 00:32:06 +00:00
parent ccd3eb3860
commit 344a64eee3
6 changed files with 157 additions and 1 deletions
@@ -91,7 +91,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-471"
"CWE-1321"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2888-q29x-2g3p",
"modified": "2023-04-11T00:30:24Z",
"published": "2023-04-11T00:30:24Z",
"aliases": [
"CVE-2023-26467"
],
"details": "A man in the middle can redirect traffic to a malicious server in a compromised configuration.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26467"
},
{
"type": "WEB",
"url": "https://support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T22:15:00Z"
}
}
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://twitter.com/retrymp3"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/171705/Monitorr-1.7.6-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh23-v522-9fqx",
"modified": "2023-04-11T00:30:24Z",
"published": "2023-04-11T00:30:24Z",
"aliases": [
"CVE-2023-1916"
],
"details": "A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1916"
},
{
"type": "WEB",
"url": "https://gitlab.com/libtiff/libtiff/-/issues/536,"
},
{
"type": "WEB",
"url": "https://gitlab.com/libtiff/libtiff/-/issues/537"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T22:15:00Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6wj-g5cv-fh4w",
"modified": "2023-04-11T00:30:24Z",
"published": "2023-04-11T00:30:24Z",
"aliases": [
"CVE-2023-1668"
],
"details": "A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1668"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2137666"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/04/06/1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T22:15:00Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whfc-j75v-mxjv",
"modified": "2023-04-11T00:30:24Z",
"published": "2023-04-11T00:30:24Z",
"aliases": [
"CVE-2023-24721"
],
"details": "A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24721"
},
{
"type": "WEB",
"url": "https://github.com/marcovntr/CVE/blob/main/2023/CVE-2023-24721/CVE-2023-24721.md"
},
{
"type": "WEB",
"url": "http://liveaction.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-10T22:15:00Z"
}
}