From c92b1993d1085b9e5df16ce75bdeca756fc55648 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 22 May 2023 03:31:28 +0000 Subject: [PATCH] Publish Advisories GHSA-2phq-x5jx-m4c3 GHSA-2wj7-w2rp-g7h5 GHSA-4c27-wwv3-v6h2 GHSA-7cgc-x5j3-p7hx GHSA-f43q-2fwm-h7gr GHSA-pwcp-7wg2-65jc GHSA-qw7q-8xqj-844w GHSA-rjh9-hq94-crmg GHSA-vfcg-3f47-8mgm GHSA-vrm6-xcmv-x82r GHSA-4r84-8p56-p7xq GHSA-mw6j-c5j9-xc24 GHSA-r2qv-vr5x-prgh GHSA-5gj6-62g7-vmgf GHSA-mf42-cj9f-vmhp GHSA-mv5m-45gv-gh97 GHSA-pwf5-mq6w-f36v GHSA-wh4v-fpr4-x9ph GHSA-wvjg-h2rj-mw4f --- .../GHSA-2phq-x5jx-m4c3.json | 11 +++- .../GHSA-2wj7-w2rp-g7h5.json | 11 +++- .../GHSA-4c27-wwv3-v6h2.json | 11 +++- .../GHSA-7cgc-x5j3-p7hx.json | 11 +++- .../GHSA-f43q-2fwm-h7gr.json | 11 +++- .../GHSA-pwcp-7wg2-65jc.json | 11 +++- .../GHSA-qw7q-8xqj-844w.json | 4 ++ .../GHSA-rjh9-hq94-crmg.json | 11 +++- .../GHSA-vfcg-3f47-8mgm.json | 11 +++- .../GHSA-vrm6-xcmv-x82r.json | 4 ++ .../GHSA-4r84-8p56-p7xq.json | 4 ++ .../GHSA-mw6j-c5j9-xc24.json | 4 ++ .../GHSA-r2qv-vr5x-prgh.json | 4 ++ .../GHSA-5gj6-62g7-vmgf.json | 35 +++++++++++++ .../GHSA-mf42-cj9f-vmhp.json | 43 ++++++++++++++++ .../GHSA-mv5m-45gv-gh97.json | 4 ++ .../GHSA-pwf5-mq6w-f36v.json | 38 ++++++++++++++ .../GHSA-wh4v-fpr4-x9ph.json | 42 +++++++++++++++ .../GHSA-wvjg-h2rj-mw4f.json | 51 +++++++++++++++++++ 19 files changed, 305 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2023/05/GHSA-5gj6-62g7-vmgf/GHSA-5gj6-62g7-vmgf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-mf42-cj9f-vmhp/GHSA-mf42-cj9f-vmhp.json create mode 100644 advisories/unreviewed/2023/05/GHSA-pwf5-mq6w-f36v/GHSA-pwf5-mq6w-f36v.json create mode 100644 advisories/unreviewed/2023/05/GHSA-wh4v-fpr4-x9ph/GHSA-wh4v-fpr4-x9ph.json create mode 100644 advisories/unreviewed/2023/05/GHSA-wvjg-h2rj-mw4f/GHSA-wvjg-h2rj-mw4f.json diff --git a/advisories/unreviewed/2022/05/GHSA-2phq-x5jx-m4c3/GHSA-2phq-x5jx-m4c3.json b/advisories/unreviewed/2022/05/GHSA-2phq-x5jx-m4c3/GHSA-2phq-x5jx-m4c3.json index 2a94304e34c..440a76a481c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2phq-x5jx-m4c3/GHSA-2phq-x5jx-m4c3.json +++ b/advisories/unreviewed/2022/05/GHSA-2phq-x5jx-m4c3/GHSA-2phq-x5jx-m4c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2phq-x5jx-m4c3", - "modified": "2022-05-24T17:43:53Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:43:53Z", "aliases": [ "CVE-2021-20246" ], "details": "A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-2wj7-w2rp-g7h5/GHSA-2wj7-w2rp-g7h5.json b/advisories/unreviewed/2022/05/GHSA-2wj7-w2rp-g7h5/GHSA-2wj7-w2rp-g7h5.json index 5517ebc57c7..f4e1df4d4bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wj7-w2rp-g7h5/GHSA-2wj7-w2rp-g7h5.json +++ b/advisories/unreviewed/2022/05/GHSA-2wj7-w2rp-g7h5/GHSA-2wj7-w2rp-g7h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wj7-w2rp-g7h5", - "modified": "2022-05-24T17:43:52Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:43:52Z", "aliases": [ "CVE-2021-20244" ], "details": "A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,6 +32,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-4c27-wwv3-v6h2/GHSA-4c27-wwv3-v6h2.json b/advisories/unreviewed/2022/05/GHSA-4c27-wwv3-v6h2/GHSA-4c27-wwv3-v6h2.json index 184650c0f22..5adf005585b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c27-wwv3-v6h2/GHSA-4c27-wwv3-v6h2.json +++ b/advisories/unreviewed/2022/05/GHSA-4c27-wwv3-v6h2/GHSA-4c27-wwv3-v6h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4c27-wwv3-v6h2", - "modified": "2022-05-24T17:43:53Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:43:52Z", "aliases": [ "CVE-2021-20243" ], "details": "A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,6 +32,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-7cgc-x5j3-p7hx/GHSA-7cgc-x5j3-p7hx.json b/advisories/unreviewed/2022/05/GHSA-7cgc-x5j3-p7hx/GHSA-7cgc-x5j3-p7hx.json index 66401cc5fe6..ee3e1291186 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cgc-x5j3-p7hx/GHSA-7cgc-x5j3-p7hx.json +++ b/advisories/unreviewed/2022/05/GHSA-7cgc-x5j3-p7hx/GHSA-7cgc-x5j3-p7hx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7cgc-x5j3-p7hx", - "modified": "2022-05-24T19:02:17Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T19:02:17Z", "aliases": [ "CVE-2021-20312" ], "details": "A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-f43q-2fwm-h7gr/GHSA-f43q-2fwm-h7gr.json b/advisories/unreviewed/2022/05/GHSA-f43q-2fwm-h7gr/GHSA-f43q-2fwm-h7gr.json index 37113f0fb4d..d6359f9855e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f43q-2fwm-h7gr/GHSA-f43q-2fwm-h7gr.json +++ b/advisories/unreviewed/2022/05/GHSA-f43q-2fwm-h7gr/GHSA-f43q-2fwm-h7gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f43q-2fwm-h7gr", - "modified": "2022-05-24T17:43:52Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:43:52Z", "aliases": [ "CVE-2021-20241" ], "details": "A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,6 +32,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-pwcp-7wg2-65jc/GHSA-pwcp-7wg2-65jc.json b/advisories/unreviewed/2022/05/GHSA-pwcp-7wg2-65jc/GHSA-pwcp-7wg2-65jc.json index 0ab08bead6c..36c89f41816 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwcp-7wg2-65jc/GHSA-pwcp-7wg2-65jc.json +++ b/advisories/unreviewed/2022/05/GHSA-pwcp-7wg2-65jc/GHSA-pwcp-7wg2-65jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwcp-7wg2-65jc", - "modified": "2022-05-24T17:43:53Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:43:53Z", "aliases": [ "CVE-2021-20245" ], "details": "A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,6 +32,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-qw7q-8xqj-844w/GHSA-qw7q-8xqj-844w.json b/advisories/unreviewed/2022/05/GHSA-qw7q-8xqj-844w/GHSA-qw7q-8xqj-844w.json index c7350c481ea..e4709743437 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw7q-8xqj-844w/GHSA-qw7q-8xqj-844w.json +++ b/advisories/unreviewed/2022/05/GHSA-qw7q-8xqj-844w/GHSA-qw7q-8xqj-844w.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00018.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-rjh9-hq94-crmg/GHSA-rjh9-hq94-crmg.json b/advisories/unreviewed/2022/05/GHSA-rjh9-hq94-crmg/GHSA-rjh9-hq94-crmg.json index 69658897577..e55110056d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjh9-hq94-crmg/GHSA-rjh9-hq94-crmg.json +++ b/advisories/unreviewed/2022/05/GHSA-rjh9-hq94-crmg/GHSA-rjh9-hq94-crmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjh9-hq94-crmg", - "modified": "2022-05-24T17:41:13Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T17:41:13Z", "aliases": [ "CVE-2021-20176" ], "details": "A flaw was found in ImageMagick in MagickCore/gem.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.10-56.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,6 +32,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-vfcg-3f47-8mgm/GHSA-vfcg-3f47-8mgm.json b/advisories/unreviewed/2022/05/GHSA-vfcg-3f47-8mgm/GHSA-vfcg-3f47-8mgm.json index ab2e08812af..7ed5df981bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfcg-3f47-8mgm/GHSA-vfcg-3f47-8mgm.json +++ b/advisories/unreviewed/2022/05/GHSA-vfcg-3f47-8mgm/GHSA-vfcg-3f47-8mgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfcg-3f47-8mgm", - "modified": "2022-05-24T19:02:17Z", + "modified": "2023-05-22T03:30:15Z", "published": "2022-05-24T19:02:17Z", "aliases": [ "CVE-2021-20309" ], "details": "A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-vrm6-xcmv-x82r/GHSA-vrm6-xcmv-x82r.json b/advisories/unreviewed/2022/05/GHSA-vrm6-xcmv-x82r/GHSA-vrm6-xcmv-x82r.json index 5308f0efa77..e15f5888e0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrm6-xcmv-x82r/GHSA-vrm6-xcmv-x82r.json +++ b/advisories/unreviewed/2022/05/GHSA-vrm6-xcmv-x82r/GHSA-vrm6-xcmv-x82r.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/06/GHSA-4r84-8p56-p7xq/GHSA-4r84-8p56-p7xq.json b/advisories/unreviewed/2022/06/GHSA-4r84-8p56-p7xq/GHSA-4r84-8p56-p7xq.json index 262875e1c00..383611ef20f 100644 --- a/advisories/unreviewed/2022/06/GHSA-4r84-8p56-p7xq/GHSA-4r84-8p56-p7xq.json +++ b/advisories/unreviewed/2022/06/GHSA-4r84-8p56-p7xq/GHSA-4r84-8p56-p7xq.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091812" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/06/GHSA-mw6j-c5j9-xc24/GHSA-mw6j-c5j9-xc24.json b/advisories/unreviewed/2022/06/GHSA-mw6j-c5j9-xc24/GHSA-mw6j-c5j9-xc24.json index c6b8faad728..5849391b252 100644 --- a/advisories/unreviewed/2022/06/GHSA-mw6j-c5j9-xc24/GHSA-mw6j-c5j9-xc24.json +++ b/advisories/unreviewed/2022/06/GHSA-mw6j-c5j9-xc24/GHSA-mw6j-c5j9-xc24.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091813" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/06/GHSA-r2qv-vr5x-prgh/GHSA-r2qv-vr5x-prgh.json b/advisories/unreviewed/2022/06/GHSA-r2qv-vr5x-prgh/GHSA-r2qv-vr5x-prgh.json index 264cf5abf13..5d13546ad31 100644 --- a/advisories/unreviewed/2022/06/GHSA-r2qv-vr5x-prgh/GHSA-r2qv-vr5x-prgh.json +++ b/advisories/unreviewed/2022/06/GHSA-r2qv-vr5x-prgh/GHSA-r2qv-vr5x-prgh.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2091811" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-5gj6-62g7-vmgf/GHSA-5gj6-62g7-vmgf.json b/advisories/unreviewed/2023/05/GHSA-5gj6-62g7-vmgf/GHSA-5gj6-62g7-vmgf.json new file mode 100644 index 00000000000..c1bddf64da0 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-5gj6-62g7-vmgf/GHSA-5gj6-62g7-vmgf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gj6-62g7-vmgf", + "modified": "2023-05-22T03:30:16Z", + "published": "2023-05-22T03:30:16Z", + "aliases": [ + "CVE-2023-33264" + ], + "details": "In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33264" + }, + { + "type": "WEB", + "url": "https://github.com/hazelcast/hazelcast/pull/24266" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-mf42-cj9f-vmhp/GHSA-mf42-cj9f-vmhp.json b/advisories/unreviewed/2023/05/GHSA-mf42-cj9f-vmhp/GHSA-mf42-cj9f-vmhp.json new file mode 100644 index 00000000000..62871fc82b9 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-mf42-cj9f-vmhp/GHSA-mf42-cj9f-vmhp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf42-cj9f-vmhp", + "modified": "2023-05-22T03:30:16Z", + "published": "2023-05-22T03:30:16Z", + "aliases": [ + "CVE-2023-33281" + ], + "details": "The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33281" + }, + { + "type": "WEB", + "url": "https://chaos-lab.blogspot.com/2023/05/nissan-sylphy-classic-2021-fixed-code.html" + }, + { + "type": "WEB", + "url": "https://twitter.com/Kevin2600/status/1658059570806415365" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=GG1utSdYG1k" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json b/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json index 55e65070ad1..767dbaaad49 100644 --- a/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json +++ b/advisories/unreviewed/2023/05/GHSA-mv5m-45gv-gh97/GHSA-mv5m-45gv-gh97.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/Tsiming/Vulnerabilities/blob/main/SQLite/CVE-2021-31239" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/73XUIHJ6UT75VFPDPLJOXJON7MVIKVZI/" + }, { "type": "WEB", "url": "https://www.sqlite.org/cves.html" diff --git a/advisories/unreviewed/2023/05/GHSA-pwf5-mq6w-f36v/GHSA-pwf5-mq6w-f36v.json b/advisories/unreviewed/2023/05/GHSA-pwf5-mq6w-f36v/GHSA-pwf5-mq6w-f36v.json new file mode 100644 index 00000000000..4377901c1de --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-pwf5-mq6w-f36v/GHSA-pwf5-mq6w-f36v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwf5-mq6w-f36v", + "modified": "2023-05-22T03:30:16Z", + "published": "2023-05-22T03:30:16Z", + "aliases": [ + "CVE-2023-33285" + ], + "details": "An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33285" + }, + { + "type": "WEB", + "url": "https://codereview.qt-project.org/c/qt/qtbase/+/477644" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-wh4v-fpr4-x9ph/GHSA-wh4v-fpr4-x9ph.json b/advisories/unreviewed/2023/05/GHSA-wh4v-fpr4-x9ph/GHSA-wh4v-fpr4-x9ph.json new file mode 100644 index 00000000000..038ee8f4d59 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-wh4v-fpr4-x9ph/GHSA-wh4v-fpr4-x9ph.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh4v-fpr4-x9ph", + "modified": "2023-05-22T03:30:16Z", + "published": "2023-05-22T03:30:16Z", + "aliases": [ + "CVE-2023-32336" + ], + "details": "IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32336" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/255285" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6995879" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-wvjg-h2rj-mw4f/GHSA-wvjg-h2rj-mw4f.json b/advisories/unreviewed/2023/05/GHSA-wvjg-h2rj-mw4f/GHSA-wvjg-h2rj-mw4f.json new file mode 100644 index 00000000000..776e2015afa --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-wvjg-h2rj-mw4f/GHSA-wvjg-h2rj-mw4f.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvjg-h2rj-mw4f", + "modified": "2023-05-22T03:30:16Z", + "published": "2023-05-22T03:30:16Z", + "aliases": [ + "CVE-2023-33288" + ], + "details": "An issue was discovered in the Linux kernel before 6.2.9. A use-after-free flaw was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race problem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33288" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/47c29d69212911f50bdcdd0564b5999a559010d4" + }, + { + "type": "WEB", + "url": "https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=47c29d69212911f50bdcdd0564b5999a559010d4" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/CAHk-=whcaHLNpb7Mu_QX7ABwPgyRyfW-V8=v4Mv0S22fpjY4JQ@mail.gmail.com/" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/20230309174728.233732-1-zyytlz.wz@163.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file