Publish Advisories

GHSA-2268-w43v-j544
GHSA-8w32-6chg-qv5f
GHSA-f8j4-pwp4-c58m
GHSA-g5x6-xpv4-w4mm
GHSA-g8p4-4qgr-rf4f
GHSA-qh94-pjxq-88v7
GHSA-w2wv-53w9-5r3r
GHSA-wgw3-5w65-2g45
This commit is contained in:
advisory-database[bot]
2024-07-03 18:50:57 +00:00
parent 35246cdaf8
commit 47805e5d0f
8 changed files with 330 additions and 0 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2268-w43v-j544",
"modified": "2024-07-03T18:48:32Z",
"published": "2024-07-03T18:48:32Z",
"aliases": [
"CVE-2024-5887"
],
"details": "Cross-Site Request Forgery (CSRF) in stitionai/devika",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5887"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/aa4f1c38-5b38-4cdc-91e1-68d3ec2350f2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:06Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w32-6chg-qv5f",
"modified": "2024-07-03T18:48:29Z",
"published": "2024-07-03T18:48:29Z",
"aliases": [
"CVE-2024-29509"
],
"details": "Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \\000 byte in the middle.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29509"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510"
},
{
"type": "WEB",
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=917b3a71fb20748965254631199ad98210d6c2fb"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8j4-pwp4-c58m",
"modified": "2024-07-03T18:48:31Z",
"published": "2024-07-03T18:48:31Z",
"aliases": [
"CVE-2024-5821"
],
"details": "Improper Access Control in stitionai/devika",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5821"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/6b729046-b9e1-4fa2-a0c5-603745a6db6b"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:05Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5x6-xpv4-w4mm",
"modified": "2024-07-03T18:48:29Z",
"published": "2024-07-03T18:48:29Z",
"aliases": [
"CVE-2024-29506"
],
"details": "Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29506"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510"
},
{
"type": "WEB",
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=77dc7f699beba606937b7ea23b50cf5974fa64b1"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8p4-4qgr-rf4f",
"modified": "2024-07-03T18:48:28Z",
"published": "2024-07-03T18:48:28Z",
"aliases": [
"CVE-2023-52169"
],
"details": "The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52169"
},
{
"type": "WEB",
"url": "https://sourceforge.net/p/sevenzip/bugs/2402"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/10"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qh94-pjxq-88v7",
"modified": "2024-07-03T18:48:27Z",
"published": "2024-07-03T18:48:27Z",
"aliases": [
"CVE-2024-39844"
],
"details": "In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39844"
},
{
"type": "WEB",
"url": "https://github.com/znc/znc/releases/tag/znc-1.9.1"
},
{
"type": "WEB",
"url": "https://wiki.znc.in/Category:ChangeLog"
},
{
"type": "WEB",
"url": "https://wiki.znc.in/ChangeLog/1.9.1"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/9"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T17:15:04Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2wv-53w9-5r3r",
"modified": "2024-07-03T18:48:30Z",
"published": "2024-07-03T18:48:30Z",
"aliases": [
"CVE-2024-29508"
],
"details": "Artifex Ghostscript before 10.0.3.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29508"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510"
},
{
"type": "WEB",
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgw3-5w65-2g45",
"modified": "2024-07-03T18:48:28Z",
"published": "2024-07-03T18:48:28Z",
"aliases": [
"CVE-2023-52168"
],
"details": "The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52168"
},
{
"type": "WEB",
"url": "https://sourceforge.net/p/sevenzip/bugs/2402"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/10"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
}
}