From 7c0defd62f20aec18b13ef671e343e2920f9dffc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 6 Nov 2023 00:31:28 +0000 Subject: [PATCH] Publish Advisories GHSA-6f7j-jmxj-m9g3 GHSA-3chx-g7jg-4263 GHSA-3vrx-27jg-h7pf GHSA-h5hf-5wcj-6hmf GHSA-q6p8-m5f4-4vmp GHSA-8f7j-g5xp-rc4p GHSA-q2wj-pp48-fpgj --- .../GHSA-6f7j-jmxj-m9g3.json | 4 ++ .../GHSA-3chx-g7jg-4263.json | 28 +++++++++-- .../GHSA-3vrx-27jg-h7pf.json | 4 ++ .../GHSA-h5hf-5wcj-6hmf.json | 8 +++- .../GHSA-q6p8-m5f4-4vmp.json | 8 +++- .../GHSA-8f7j-g5xp-rc4p.json | 35 ++++++++++++++ .../GHSA-q2wj-pp48-fpgj.json | 46 +++++++++++++++++++ 7 files changed, 125 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q2wj-pp48-fpgj/GHSA-q2wj-pp48-fpgj.json diff --git a/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json b/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json index d31909efc72..e19c0496049 100644 --- a/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json +++ b/advisories/unreviewed/2023/03/GHSA-6f7j-jmxj-m9g3/GHSA-6f7j-jmxj-m9g3.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2023/01/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/05/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json b/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json index 7a963ddf76d..16213bbf5a8 100644 --- a/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json +++ b/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3chx-g7jg-4263", - "modified": "2023-07-06T19:24:12Z", + "modified": "2023-11-06T00:30:16Z", "published": "2023-07-06T19:24:12Z", "aliases": [ "CVE-2023-1073" ], "details": "A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -26,16 +29,33 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/id=b12fece4c64857e5fab4290bf01b2e0317a88456" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/osssecurity/2023/01/17/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/05/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/05/3" } ], "database_specific": { "cwe_ids": [ - + "CWE-119", + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-27T21:15:00Z" diff --git a/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json b/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json index a6cafdfb554..ab1acd6cbeb 100644 --- a/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json +++ b/advisories/unreviewed/2023/10/GHSA-3vrx-27jg-h7pf/GHSA-3vrx-27jg-h7pf.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/" diff --git a/advisories/unreviewed/2023/10/GHSA-h5hf-5wcj-6hmf/GHSA-h5hf-5wcj-6hmf.json b/advisories/unreviewed/2023/10/GHSA-h5hf-5wcj-6hmf/GHSA-h5hf-5wcj-6hmf.json index 87de81277f7..1bfca7b12cb 100644 --- a/advisories/unreviewed/2023/10/GHSA-h5hf-5wcj-6hmf/GHSA-h5hf-5wcj-6hmf.json +++ b/advisories/unreviewed/2023/10/GHSA-h5hf-5wcj-6hmf/GHSA-h5hf-5wcj-6hmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5hf-5wcj-6hmf", - "modified": "2023-11-01T09:30:53Z", + "modified": "2023-11-06T00:30:16Z", "published": "2023-10-27T06:31:02Z", "aliases": [ "CVE-2023-34058" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34058" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5543" @@ -41,6 +45,6 @@ "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-27T05:15:38Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q6p8-m5f4-4vmp/GHSA-q6p8-m5f4-4vmp.json b/advisories/unreviewed/2023/10/GHSA-q6p8-m5f4-4vmp/GHSA-q6p8-m5f4-4vmp.json index ed1a01ad867..7c9c378d502 100644 --- a/advisories/unreviewed/2023/10/GHSA-q6p8-m5f4-4vmp/GHSA-q6p8-m5f4-4vmp.json +++ b/advisories/unreviewed/2023/10/GHSA-q6p8-m5f4-4vmp/GHSA-q6p8-m5f4-4vmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6p8-m5f4-4vmp", - "modified": "2023-11-01T09:30:53Z", + "modified": "2023-11-06T00:30:16Z", "published": "2023-10-27T06:31:02Z", "aliases": [ "CVE-2023-34059" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34059" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00002.html" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5543" @@ -45,6 +49,6 @@ "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-27T05:15:39Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json b/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json new file mode 100644 index 00000000000..52b30050df1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8f7j-g5xp-rc4p/GHSA-8f7j-g5xp-rc4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f7j-g5xp-rc4p", + "modified": "2023-11-06T00:30:16Z", + "published": "2023-11-06T00:30:16Z", + "aliases": [ + "CVE-2023-47271" + ], + "details": "PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47271" + }, + { + "type": "WEB", + "url": "https://github.com/pkp/pkp-lib/issues/9464" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q2wj-pp48-fpgj/GHSA-q2wj-pp48-fpgj.json b/advisories/unreviewed/2023/11/GHSA-q2wj-pp48-fpgj/GHSA-q2wj-pp48-fpgj.json new file mode 100644 index 00000000000..afb1801fd5c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q2wj-pp48-fpgj/GHSA-q2wj-pp48-fpgj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2wj-pp48-fpgj", + "modified": "2023-11-06T00:30:16Z", + "published": "2023-11-06T00:30:16Z", + "aliases": [ + "CVE-2023-47272" + ], + "details": "Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47272" + }, + { + "type": "WEB", + "url": "https://github.com/roundcube/roundcubemail/commit/5ec496885e18ec6af956e8c0d627856c2257ba2d" + }, + { + "type": "WEB", + "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.5.6" + }, + { + "type": "WEB", + "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T00:15:09Z" + } +} \ No newline at end of file