Publish Advisories

GHSA-2phq-x5jx-m4c3
GHSA-2wj7-w2rp-g7h5
GHSA-4c27-wwv3-v6h2
GHSA-7cgc-x5j3-p7hx
GHSA-f43q-2fwm-h7gr
GHSA-pwcp-7wg2-65jc
GHSA-qw7q-8xqj-844w
GHSA-rjh9-hq94-crmg
GHSA-vfcg-3f47-8mgm
GHSA-vrm6-xcmv-x82r
GHSA-4r84-8p56-p7xq
GHSA-mw6j-c5j9-xc24
GHSA-r2qv-vr5x-prgh
GHSA-5gj6-62g7-vmgf
GHSA-mf42-cj9f-vmhp
GHSA-mv5m-45gv-gh97
GHSA-pwf5-mq6w-f36v
GHSA-wh4v-fpr4-x9ph
GHSA-wvjg-h2rj-mw4f
This commit is contained in:
advisory-database[bot]
2023-05-22 03:31:28 +00:00
parent b0fe9dc6b1
commit c92b1993d1
19 changed files with 305 additions and 16 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2phq-x5jx-m4c3",
"modified": "2022-05-24T17:43:53Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:43:53Z",
"aliases": [
"CVE-2021-20246"
],
"details": "A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,6 +28,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wj7-w2rp-g7h5",
"modified": "2022-05-24T17:43:52Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:43:52Z",
"aliases": [
"CVE-2021-20244"
],
"details": "A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,6 +32,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c27-wwv3-v6h2",
"modified": "2022-05-24T17:43:53Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:43:52Z",
"aliases": [
"CVE-2021-20243"
],
"details": "A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,6 +32,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cgc-x5j3-p7hx",
"modified": "2022-05-24T19:02:17Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T19:02:17Z",
"aliases": [
"CVE-2021-20312"
],
"details": "A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,6 +28,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f43q-2fwm-h7gr",
"modified": "2022-05-24T17:43:52Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:43:52Z",
"aliases": [
"CVE-2021-20241"
],
"details": "A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,6 +32,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwcp-7wg2-65jc",
"modified": "2022-05-24T17:43:53Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:43:53Z",
"aliases": [
"CVE-2021-20245"
],
"details": "A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,6 +32,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00018.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjh9-hq94-crmg",
"modified": "2022-05-24T17:41:13Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T17:41:13Z",
"aliases": [
"CVE-2021-20176"
],
"details": "A flaw was found in ImageMagick in MagickCore/gem.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.10-56.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,6 +32,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfcg-3f47-8mgm",
"modified": "2022-05-24T19:02:17Z",
"modified": "2023-05-22T03:30:15Z",
"published": "2022-05-24T19:02:17Z",
"aliases": [
"CVE-2021-20309"
],
"details": "A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,6 +28,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091812"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091813"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091811"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gj6-62g7-vmgf",
"modified": "2023-05-22T03:30:16Z",
"published": "2023-05-22T03:30:16Z",
"aliases": [
"CVE-2023-33264"
],
"details": "In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33264"
},
{
"type": "WEB",
"url": "https://github.com/hazelcast/hazelcast/pull/24266"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf42-cj9f-vmhp",
"modified": "2023-05-22T03:30:16Z",
"published": "2023-05-22T03:30:16Z",
"aliases": [
"CVE-2023-33281"
],
"details": "The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33281"
},
{
"type": "WEB",
"url": "https://chaos-lab.blogspot.com/2023/05/nissan-sylphy-classic-2021-fixed-code.html"
},
{
"type": "WEB",
"url": "https://twitter.com/Kevin2600/status/1658059570806415365"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=GG1utSdYG1k"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/Tsiming/Vulnerabilities/blob/main/SQLite/CVE-2021-31239"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/73XUIHJ6UT75VFPDPLJOXJON7MVIKVZI/"
},
{
"type": "WEB",
"url": "https://www.sqlite.org/cves.html"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwf5-mq6w-f36v",
"modified": "2023-05-22T03:30:16Z",
"published": "2023-05-22T03:30:16Z",
"aliases": [
"CVE-2023-33285"
],
"details": "An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33285"
},
{
"type": "WEB",
"url": "https://codereview.qt-project.org/c/qt/qtbase/+/477644"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wh4v-fpr4-x9ph",
"modified": "2023-05-22T03:30:16Z",
"published": "2023-05-22T03:30:16Z",
"aliases": [
"CVE-2023-32336"
],
"details": "IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32336"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/255285"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6995879"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,51 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvjg-h2rj-mw4f",
"modified": "2023-05-22T03:30:16Z",
"published": "2023-05-22T03:30:16Z",
"aliases": [
"CVE-2023-33288"
],
"details": "An issue was discovered in the Linux kernel before 6.2.9. A use-after-free flaw was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race problem.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33288"
},
{
"type": "WEB",
"url": "https://github.com/torvalds/linux/commit/47c29d69212911f50bdcdd0564b5999a559010d4"
},
{
"type": "WEB",
"url": "https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.9"
},
{
"type": "WEB",
"url": "https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=47c29d69212911f50bdcdd0564b5999a559010d4"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/CAHk-=whcaHLNpb7Mu_QX7ABwPgyRyfW-V8=v4Mv0S22fpjY4JQ@mail.gmail.com/"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/20230309174728.233732-1-zyytlz.wz@163.com/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}