Publish Advisories

GHSA-6f7j-jmxj-m9g3
GHSA-3chx-g7jg-4263
GHSA-3vrx-27jg-h7pf
GHSA-h5hf-5wcj-6hmf
GHSA-q6p8-m5f4-4vmp
GHSA-8f7j-g5xp-rc4p
GHSA-q2wj-pp48-fpgj
This commit is contained in:
advisory-database[bot]
2023-11-06 00:31:28 +00:00
parent 7ed50a8816
commit 7c0defd62f
7 changed files with 125 additions and 8 deletions
@@ -40,6 +40,10 @@
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/01/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/05/4"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3chx-g7jg-4263",
"modified": "2023-07-06T19:24:12Z",
"modified": "2023-11-06T00:30:16Z",
"published": "2023-07-06T19:24:12Z",
"aliases": [
"CVE-2023-1073"
],
"details": "A memory corruption flaw was found in the Linux kernels human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -26,16 +29,33 @@
"type": "WEB",
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/id=b12fece4c64857e5fab4290bf01b2e0317a88456"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/osssecurity/2023/01/17/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/05/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/11/05/3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-27T21:15:00Z"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5hf-5wcj-6hmf",
"modified": "2023-11-01T09:30:53Z",
"modified": "2023-11-06T00:30:16Z",
"published": "2023-10-27T06:31:02Z",
"aliases": [
"CVE-2023-34058"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34058"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5543"
@@ -41,6 +45,6 @@
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-27T05:15:38Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6p8-m5f4-4vmp",
"modified": "2023-11-01T09:30:53Z",
"modified": "2023-11-06T00:30:16Z",
"published": "2023-10-27T06:31:02Z",
"aliases": [
"CVE-2023-34059"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34059"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5543"
@@ -45,6 +49,6 @@
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-27T05:15:39Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f7j-g5xp-rc4p",
"modified": "2023-11-06T00:30:16Z",
"published": "2023-11-06T00:30:16Z",
"aliases": [
"CVE-2023-47271"
],
"details": "PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47271"
},
{
"type": "WEB",
"url": "https://github.com/pkp/pkp-lib/issues/9464"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-06T00:15:09Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2wj-pp48-fpgj",
"modified": "2023-11-06T00:30:16Z",
"published": "2023-11-06T00:30:16Z",
"aliases": [
"CVE-2023-47272"
],
"details": "Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47272"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/commit/5ec496885e18ec6af956e8c0d627856c2257ba2d"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/releases/tag/1.5.6"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.5"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-06T00:15:09Z"
}
}