From 7a803f1c89262cd3d92cb3e244e898e9ea58b3a6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 18 Feb 2024 03:31:42 +0000 Subject: [PATCH] Publish Advisories GHSA-62rj-gv2c-8ghr GHSA-4r65-ggqx-8rh6 GHSA-4rw3-758f-qx63 GHSA-8459-gg55-8qjj GHSA-g7c7-4h8w-p4x9 GHSA-gpp8-r7jq-fh8v GHSA-jxp6-f9wg-m536 GHSA-prp3-rrcq-rrx9 GHSA-pv4h-p8jr-6cv2 GHSA-rgfh-pm48-24wc GHSA-wr66-4wc3-frfh GHSA-wwq2-fw7h-68fc --- .../GHSA-62rj-gv2c-8ghr.json | 12 ++++-- .../GHSA-4r65-ggqx-8rh6.json | 39 +++++++++++++++++++ .../GHSA-4rw3-758f-qx63.json | 39 +++++++++++++++++++ .../GHSA-8459-gg55-8qjj.json | 6 ++- .../GHSA-g7c7-4h8w-p4x9.json | 39 +++++++++++++++++++ .../GHSA-gpp8-r7jq-fh8v.json | 39 +++++++++++++++++++ .../GHSA-jxp6-f9wg-m536.json | 39 +++++++++++++++++++ .../GHSA-prp3-rrcq-rrx9.json | 39 +++++++++++++++++++ .../GHSA-pv4h-p8jr-6cv2.json | 6 ++- .../GHSA-rgfh-pm48-24wc.json | 39 +++++++++++++++++++ .../GHSA-wr66-4wc3-frfh.json | 39 +++++++++++++++++++ .../GHSA-wwq2-fw7h-68fc.json | 39 +++++++++++++++++++ 12 files changed, 369 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-4r65-ggqx-8rh6/GHSA-4r65-ggqx-8rh6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4rw3-758f-qx63/GHSA-4rw3-758f-qx63.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g7c7-4h8w-p4x9/GHSA-g7c7-4h8w-p4x9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json create mode 100644 advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wwq2-fw7h-68fc/GHSA-wwq2-fw7h-68fc.json diff --git a/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json b/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json index eddec106a99..f10a45684d3 100644 --- a/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json +++ b/advisories/unreviewed/2023/12/GHSA-62rj-gv2c-8ghr/GHSA-62rj-gv2c-8ghr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62rj-gv2c-8ghr", - "modified": "2024-02-08T12:30:48Z", + "modified": "2024-02-18T03:30:23Z", "published": "2023-12-22T18:30:30Z", "aliases": [ "CVE-2023-42465" @@ -35,7 +35,11 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R4Q23NHCKCLFIHSNY6KJ27GM7FSCEVXM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ" }, { "type": "WEB", @@ -43,7 +47,7 @@ }, { "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20240208-0002/" + "url": "https://security.netapp.com/advisory/ntap-20240208-0002" }, { "type": "WEB", @@ -51,7 +55,7 @@ }, { "type": "WEB", - "url": "https://www.sudo.ws/releases/changelog/" + "url": "https://www.sudo.ws/releases/changelog" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-4r65-ggqx-8rh6/GHSA-4r65-ggqx-8rh6.json b/advisories/unreviewed/2024/02/GHSA-4r65-ggqx-8rh6/GHSA-4r65-ggqx-8rh6.json new file mode 100644 index 00000000000..7f9c22b14ba --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4r65-ggqx-8rh6/GHSA-4r65-ggqx-8rh6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r65-ggqx-8rh6", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52097" + ], + "details": "Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52097" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4rw3-758f-qx63/GHSA-4rw3-758f-qx63.json b/advisories/unreviewed/2024/02/GHSA-4rw3-758f-qx63/GHSA-4rw3-758f-qx63.json new file mode 100644 index 00000000000..d2ddc79c033 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4rw3-758f-qx63/GHSA-4rw3-758f-qx63.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rw3-758f-qx63", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52362" + ], + "details": "Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52362" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json index 269b7c78978..170350e1cec 100644 --- a/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json +++ b/advisories/unreviewed/2024/02/GHSA-8459-gg55-8qjj/GHSA-8459-gg55-8qjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8459-gg55-8qjj", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-02-18T03:30:23Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50387" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50387" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" + }, { "type": "WEB", "url": "https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html" diff --git a/advisories/unreviewed/2024/02/GHSA-g7c7-4h8w-p4x9/GHSA-g7c7-4h8w-p4x9.json b/advisories/unreviewed/2024/02/GHSA-g7c7-4h8w-p4x9/GHSA-g7c7-4h8w-p4x9.json new file mode 100644 index 00000000000..e5a3d6c8bfc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g7c7-4h8w-p4x9/GHSA-g7c7-4h8w-p4x9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7c7-4h8w-p4x9", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52357" + ], + "details": "Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52357" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json b/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json new file mode 100644 index 00000000000..09d088f8c33 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpp8-r7jq-fh8v", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52365" + ], + "details": "Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52365" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json b/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json new file mode 100644 index 00000000000..fe9aced2734 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxp6-f9wg-m536", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52361" + ], + "details": "The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52361" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json new file mode 100644 index 00000000000..d9d847b1842 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prp3-rrcq-rrx9", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52387" + ], + "details": "Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52387" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json index ccb3f1b12e9..1f6479a0027 100644 --- a/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json +++ b/advisories/unreviewed/2024/02/GHSA-pv4h-p8jr-6cv2/GHSA-pv4h-p8jr-6cv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv4h-p8jr-6cv2", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-02-18T03:30:23Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2023-50868" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-50868" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP" + }, { "type": "WEB", "url": "https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html" diff --git a/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json b/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json new file mode 100644 index 00000000000..103923e4eef --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgfh-pm48-24wc", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52363" + ], + "details": "Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52363" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json b/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json new file mode 100644 index 00000000000..27b27475a60 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr66-4wc3-frfh", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52360" + ], + "details": "Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52360" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + }, + { + "type": "WEB", + "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wwq2-fw7h-68fc/GHSA-wwq2-fw7h-68fc.json b/advisories/unreviewed/2024/02/GHSA-wwq2-fw7h-68fc/GHSA-wwq2-fw7h-68fc.json new file mode 100644 index 00000000000..a7cab7089b2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wwq2-fw7h-68fc/GHSA-wwq2-fw7h-68fc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwq2-fw7h-68fc", + "modified": "2024-02-18T03:30:24Z", + "published": "2024-02-18T03:30:24Z", + "aliases": [ + "CVE-2023-52358" + ], + "details": "Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52358" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/2" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-18T03:15:08Z" + } +} \ No newline at end of file