mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-5473-w6gq-5r5g GHSA-8mvv-2pq8-4996 GHSA-chwc-9rjv-x7mh GHSA-wgx8-xhfh-5ph4 GHSA-2x8c-95vh-gfv4 GHSA-3jcc-xr22-5w89 GHSA-3xr3-vrm2-6jc7 GHSA-9q47-7r9c-r8qg GHSA-fwqv-2c76-c44x GHSA-g8p4-4qgr-rf4f GHSA-g9m4-vfq7-w439 GHSA-h538-6ch9-fvph GHSA-mjm5-gj95-f347 GHSA-mq7h-fm69-h6xq GHSA-qh94-pjxq-88v7 GHSA-r824-gq56-gjgx GHSA-v6hc-9c6c-f599 GHSA-wgw3-5w65-2g45 GHSA-wm9w-rjj3-j356
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5473-w6gq-5r5g",
|
||||
"modified": "2024-04-28T00:30:23Z",
|
||||
"modified": "2024-07-03T21:39:42Z",
|
||||
"published": "2024-04-28T00:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52722"
|
||||
@@ -21,6 +21,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/06/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8mvv-2pq8-4996",
|
||||
"modified": "2024-04-29T03:30:46Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-04-29T03:30:46Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4298"
|
||||
@@ -21,6 +21,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4298"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.chtsecurity.com/news/4559fabd-43d1-4324-a0b3-f459a05c2290"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.chtsecurity.com/news/f67fd9b5-cb7a-42e4-bcb7-cc1c73d1f851"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.twcert.org.tw/tw/cp-132-7769-0773a-1.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-chwc-9rjv-x7mh",
|
||||
"modified": "2024-07-03T18:37:53Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-04-30T21:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3411"
|
||||
@@ -25,6 +25,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://kb.cert.org/vuls/id/163057"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-US/000226504/dsa-2024-295-security-update-for-dell-idrac8-ipmi-session-vulnerability"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.intel.la/content/dam/www/public/us/en/documents/specification-updates/ipmi-intelligent-platform-mgt-interface-spec-2nd-gen-v2-0-spec-update.pdf"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wgx8-xhfh-5ph4",
|
||||
"modified": "2024-04-29T06:30:41Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-04-29T06:30:41Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4299"
|
||||
@@ -21,6 +21,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4299"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.chtsecurity.com/news/4559fabd-43d1-4324-a0b3-f459a05c2290"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.chtsecurity.com/news/f67fd9b5-cb7a-42e4-bcb7-cc1c73d1f851"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.twcert.org.tw/tw/cp-132-7771-36c50-1.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2x8c-95vh-gfv4",
|
||||
"modified": "2024-07-03T18:47:42Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-01T15:32:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6387"
|
||||
@@ -21,53 +21,33 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6387"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/oracle/oracle-linux/issues/149"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rapier1/hpn-ssh/issues/87"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.theregister.com/2024/07/01/regresshion_openssh"
|
||||
"url": "https://github.com/oracle/oracle-linux/issues/149"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.suse.com/security/cve/CVE-2024-6387.html"
|
||||
"url": "https://github.com/microsoft/azurelinux/issues/9555"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"
|
||||
"url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2249"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openssh.com/txt/release-9.8"
|
||||
"url": "https://github.com/AlmaLinux/updates/issues/629"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc"
|
||||
"url": "https://github.com/Azure/AKS/issues/4379"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://ubuntu.com/security/notices/USN-6859-1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://ubuntu.com/security/CVE-2024-6387"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240701-0001"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security-tracker.debian.org/tracker/CVE-2024-6387"
|
||||
"url": "https://news.ycombinator.com/item?id=40843778"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
@@ -75,7 +55,43 @@
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://news.ycombinator.com/item?id=40843778"
|
||||
"url": "https://security-tracker.debian.org/tracker/CVE-2024-6387"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20240701-0001"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://ubuntu.com/security/CVE-2024-6387"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://ubuntu.com/security/notices/USN-6859-1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openssh.com/txt/release-9.8"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.suse.com/security/cve/CVE-2024-6387.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.theregister.com/2024/07/01/regresshion_openssh"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
@@ -89,6 +105,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/zgzhang/cve-2024-6387-poc"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/PowerShell/Win32-OpenSSH/discussions/2248"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc"
|
||||
@@ -105,6 +125,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1"
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3jcc-xr22-5w89",
|
||||
"modified": "2024-07-03T21:39:45Z",
|
||||
"published": "2024-07-03T21:39:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6461"
|
||||
],
|
||||
"details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6461"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T21:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3xr3-vrm2-6jc7",
|
||||
"modified": "2024-07-03T21:39:44Z",
|
||||
"published": "2024-07-03T21:39:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33870"
|
||||
],
|
||||
"details": "An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33870"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707686"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/06/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9q47-7r9c-r8qg",
|
||||
"modified": "2024-07-03T21:39:45Z",
|
||||
"published": "2024-07-03T21:39:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6464"
|
||||
],
|
||||
"details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6464"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T21:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fwqv-2c76-c44x",
|
||||
"modified": "2024-07-03T21:39:45Z",
|
||||
"published": "2024-07-03T21:39:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6463"
|
||||
],
|
||||
"details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6463"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T21:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g8p4-4qgr-rf4f",
|
||||
"modified": "2024-07-03T18:48:28Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T18:48:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52169"
|
||||
@@ -25,6 +25,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/10"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/07/03/10"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g9m4-vfq7-w439",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T21:39:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29511"
|
||||
],
|
||||
"details": "Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29511"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h538-6ch9-fvph",
|
||||
"modified": "2024-07-03T21:39:44Z",
|
||||
"published": "2024-07-03T21:39:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-6488"
|
||||
],
|
||||
"details": "Rejected reason: REJECTED",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6488"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mjm5-gj95-f347",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T21:39:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29507"
|
||||
],
|
||||
"details": "Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29507"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=7745dbe24514"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mq7h-fm69-h6xq",
|
||||
"modified": "2024-07-03T21:39:44Z",
|
||||
"published": "2024-07-03T21:39:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33871"
|
||||
],
|
||||
"details": "An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33871"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707754"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=7145885041bb52cc23964f0aa2aec1b1c82b5908"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/06/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qh94-pjxq-88v7",
|
||||
"modified": "2024-07-03T18:48:27Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T18:48:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39844"
|
||||
@@ -33,6 +33,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/9"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/07/03/9"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r824-gq56-gjgx",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T21:39:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29510"
|
||||
],
|
||||
"details": "Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29510"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707662"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/7"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v6hc-9c6c-f599",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T21:39:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-33869"
|
||||
],
|
||||
"details": "An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33869"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=707691"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/06/28/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T19:15:03Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wgw3-5w65-2g45",
|
||||
"modified": "2024-07-03T18:48:28Z",
|
||||
"modified": "2024-07-03T21:39:43Z",
|
||||
"published": "2024-07-03T18:48:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52168"
|
||||
@@ -25,6 +25,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2024/07/03/10"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2024/07/03/10"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wm9w-rjj3-j356",
|
||||
"modified": "2024-07-03T21:39:44Z",
|
||||
"published": "2024-07-03T21:39:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-34750"
|
||||
],
|
||||
"details": "Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.\n\nUsers are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.\n\n",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34750"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-07-03T20:15:04Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user