From d97c6f4168806f234309c0316af5ad197397b697 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jul 2024 21:40:43 +0000 Subject: [PATCH] Publish Advisories GHSA-5473-w6gq-5r5g GHSA-8mvv-2pq8-4996 GHSA-chwc-9rjv-x7mh GHSA-wgx8-xhfh-5ph4 GHSA-2x8c-95vh-gfv4 GHSA-3jcc-xr22-5w89 GHSA-3xr3-vrm2-6jc7 GHSA-9q47-7r9c-r8qg GHSA-fwqv-2c76-c44x GHSA-g8p4-4qgr-rf4f GHSA-g9m4-vfq7-w439 GHSA-h538-6ch9-fvph GHSA-mjm5-gj95-f347 GHSA-mq7h-fm69-h6xq GHSA-qh94-pjxq-88v7 GHSA-r824-gq56-gjgx GHSA-v6hc-9c6c-f599 GHSA-wgw3-5w65-2g45 GHSA-wm9w-rjj3-j356 --- .../GHSA-5473-w6gq-5r5g.json | 6 +- .../GHSA-8mvv-2pq8-4996.json | 10 ++- .../GHSA-chwc-9rjv-x7mh.json | 6 +- .../GHSA-wgx8-xhfh-5ph4.json | 10 ++- .../GHSA-2x8c-95vh-gfv4.json | 80 ++++++++++++------- .../GHSA-3jcc-xr22-5w89.json | 31 +++++++ .../GHSA-3xr3-vrm2-6jc7.json | 39 +++++++++ .../GHSA-9q47-7r9c-r8qg.json | 31 +++++++ .../GHSA-fwqv-2c76-c44x.json | 31 +++++++ .../GHSA-g8p4-4qgr-rf4f.json | 6 +- .../GHSA-g9m4-vfq7-w439.json | 43 ++++++++++ .../GHSA-h538-6ch9-fvph.json | 31 +++++++ .../GHSA-mjm5-gj95-f347.json | 43 ++++++++++ .../GHSA-mq7h-fm69-h6xq.json | 43 ++++++++++ .../GHSA-qh94-pjxq-88v7.json | 6 +- .../GHSA-r824-gq56-gjgx.json | 43 ++++++++++ .../GHSA-v6hc-9c6c-f599.json | 39 +++++++++ .../GHSA-wgw3-5w65-2g45.json | 6 +- .../GHSA-wm9w-rjj3-j356.json | 35 ++++++++ 19 files changed, 504 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-3jcc-xr22-5w89/GHSA-3jcc-xr22-5w89.json create mode 100644 advisories/unreviewed/2024/07/GHSA-3xr3-vrm2-6jc7/GHSA-3xr3-vrm2-6jc7.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9q47-7r9c-r8qg/GHSA-9q47-7r9c-r8qg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fwqv-2c76-c44x/GHSA-fwqv-2c76-c44x.json create mode 100644 advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json create mode 100644 advisories/unreviewed/2024/07/GHSA-h538-6ch9-fvph/GHSA-h538-6ch9-fvph.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v6hc-9c6c-f599/GHSA-v6hc-9c6c-f599.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wm9w-rjj3-j356/GHSA-wm9w-rjj3-j356.json diff --git a/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json b/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json index 51be7574326..f0ec589a158 100644 --- a/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json +++ b/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5473-w6gq-5r5g", - "modified": "2024-04-28T00:30:23Z", + "modified": "2024-07-03T21:39:42Z", "published": "2024-04-28T00:30:23Z", "aliases": [ "CVE-2023-52722" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/06/28/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-8mvv-2pq8-4996/GHSA-8mvv-2pq8-4996.json b/advisories/unreviewed/2024/04/GHSA-8mvv-2pq8-4996/GHSA-8mvv-2pq8-4996.json index 2c9ac049f24..7f5319e735a 100644 --- a/advisories/unreviewed/2024/04/GHSA-8mvv-2pq8-4996/GHSA-8mvv-2pq8-4996.json +++ b/advisories/unreviewed/2024/04/GHSA-8mvv-2pq8-4996/GHSA-8mvv-2pq8-4996.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mvv-2pq8-4996", - "modified": "2024-04-29T03:30:46Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-04-29T03:30:46Z", "aliases": [ "CVE-2024-4298" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4298" }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/4559fabd-43d1-4324-a0b3-f459a05c2290" + }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/f67fd9b5-cb7a-42e4-bcb7-cc1c73d1f851" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/tw/cp-132-7769-0773a-1.html" diff --git a/advisories/unreviewed/2024/04/GHSA-chwc-9rjv-x7mh/GHSA-chwc-9rjv-x7mh.json b/advisories/unreviewed/2024/04/GHSA-chwc-9rjv-x7mh/GHSA-chwc-9rjv-x7mh.json index e00707c8d49..22a77417975 100644 --- a/advisories/unreviewed/2024/04/GHSA-chwc-9rjv-x7mh/GHSA-chwc-9rjv-x7mh.json +++ b/advisories/unreviewed/2024/04/GHSA-chwc-9rjv-x7mh/GHSA-chwc-9rjv-x7mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chwc-9rjv-x7mh", - "modified": "2024-07-03T18:37:53Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-04-30T21:30:32Z", "aliases": [ "CVE-2024-3411" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://kb.cert.org/vuls/id/163057" }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-US/000226504/dsa-2024-295-security-update-for-dell-idrac8-ipmi-session-vulnerability" + }, { "type": "WEB", "url": "https://www.intel.la/content/dam/www/public/us/en/documents/specification-updates/ipmi-intelligent-platform-mgt-interface-spec-2nd-gen-v2-0-spec-update.pdf" diff --git a/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json b/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json index f21ee55f560..ed11698f8b9 100644 --- a/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json +++ b/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgx8-xhfh-5ph4", - "modified": "2024-04-29T06:30:41Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-04-29T06:30:41Z", "aliases": [ "CVE-2024-4299" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4299" }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/4559fabd-43d1-4324-a0b3-f459a05c2290" + }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/f67fd9b5-cb7a-42e4-bcb7-cc1c73d1f851" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/tw/cp-132-7771-36c50-1.html" diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index d497f24adbf..8a5fae6b84c 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-03T18:47:42Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -21,53 +21,33 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6387" }, - { - "type": "WEB", - "url": "https://github.com/oracle/oracle-linux/issues/149" - }, { "type": "WEB", "url": "https://github.com/rapier1/hpn-ssh/issues/87" }, { "type": "WEB", - "url": "https://www.theregister.com/2024/07/01/regresshion_openssh" + "url": "https://github.com/oracle/oracle-linux/issues/149" }, { "type": "WEB", - "url": "https://www.suse.com/security/cve/CVE-2024-6387.html" + "url": "https://github.com/microsoft/azurelinux/issues/9555" }, { "type": "WEB", - "url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" + "url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2249" }, { "type": "WEB", - "url": "https://www.openssh.com/txt/release-9.8" + "url": "https://github.com/AlmaLinux/updates/issues/629" }, { "type": "WEB", - "url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc" + "url": "https://github.com/Azure/AKS/issues/4379" }, { "type": "WEB", - "url": "https://ubuntu.com/security/notices/USN-6859-1" - }, - { - "type": "WEB", - "url": "https://ubuntu.com/security/CVE-2024-6387" - }, - { - "type": "WEB", - "url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20240701-0001" - }, - { - "type": "WEB", - "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" + "url": "https://news.ycombinator.com/item?id=40843778" }, { "type": "WEB", @@ -75,7 +55,43 @@ }, { "type": "WEB", - "url": "https://news.ycombinator.com/item?id=40843778" + "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240701-0001" + }, + { + "type": "WEB", + "url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/CVE-2024-6387" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-6859-1" + }, + { + "type": "WEB", + "url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-9.8" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" + }, + { + "type": "WEB", + "url": "https://www.suse.com/security/cve/CVE-2024-6387.html" + }, + { + "type": "WEB", + "url": "https://www.theregister.com/2024/07/01/regresshion_openssh" }, { "type": "WEB", @@ -89,6 +105,10 @@ "type": "WEB", "url": "https://github.com/zgzhang/cve-2024-6387-poc" }, + { + "type": "WEB", + "url": "https://github.com/PowerShell/Win32-OpenSSH/discussions/2248" + }, { "type": "WEB", "url": "https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc" @@ -105,6 +125,10 @@ "type": "WEB", "url": "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server" }, + { + "type": "WEB", + "url": "https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux" + }, { "type": "WEB", "url": "https://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1" diff --git a/advisories/unreviewed/2024/07/GHSA-3jcc-xr22-5w89/GHSA-3jcc-xr22-5w89.json b/advisories/unreviewed/2024/07/GHSA-3jcc-xr22-5w89/GHSA-3jcc-xr22-5w89.json new file mode 100644 index 00000000000..1b083849eba --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3jcc-xr22-5w89/GHSA-3jcc-xr22-5w89.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jcc-xr22-5w89", + "modified": "2024-07-03T21:39:45Z", + "published": "2024-07-03T21:39:44Z", + "aliases": [ + "CVE-2024-6461" + ], + "details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6461" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-3xr3-vrm2-6jc7/GHSA-3xr3-vrm2-6jc7.json b/advisories/unreviewed/2024/07/GHSA-3xr3-vrm2-6jc7/GHSA-3xr3-vrm2-6jc7.json new file mode 100644 index 00000000000..34fc5049281 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3xr3-vrm2-6jc7/GHSA-3xr3-vrm2-6jc7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xr3-vrm2-6jc7", + "modified": "2024-07-03T21:39:44Z", + "published": "2024-07-03T21:39:43Z", + "aliases": [ + "CVE-2024-33870" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33870" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707686" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/06/28/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9q47-7r9c-r8qg/GHSA-9q47-7r9c-r8qg.json b/advisories/unreviewed/2024/07/GHSA-9q47-7r9c-r8qg/GHSA-9q47-7r9c-r8qg.json new file mode 100644 index 00000000000..f4a90ef46bd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9q47-7r9c-r8qg/GHSA-9q47-7r9c-r8qg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q47-7r9c-r8qg", + "modified": "2024-07-03T21:39:45Z", + "published": "2024-07-03T21:39:45Z", + "aliases": [ + "CVE-2024-6464" + ], + "details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6464" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fwqv-2c76-c44x/GHSA-fwqv-2c76-c44x.json b/advisories/unreviewed/2024/07/GHSA-fwqv-2c76-c44x/GHSA-fwqv-2c76-c44x.json new file mode 100644 index 00000000000..a7fd4a0cf8f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fwqv-2c76-c44x/GHSA-fwqv-2c76-c44x.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwqv-2c76-c44x", + "modified": "2024-07-03T21:39:45Z", + "published": "2024-07-03T21:39:45Z", + "aliases": [ + "CVE-2024-6463" + ], + "details": "Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6463" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json b/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json index 60a6cf76c9b..2d32d9c97e7 100644 --- a/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json +++ b/advisories/unreviewed/2024/07/GHSA-g8p4-4qgr-rf4f/GHSA-g8p4-4qgr-rf4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8p4-4qgr-rf4f", - "modified": "2024-07-03T18:48:28Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-07-03T18:48:28Z", "aliases": [ "CVE-2023-52169" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/03/10" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/10" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json b/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json new file mode 100644 index 00000000000..8ff7b5966e1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g9m4-vfq7-w439/GHSA-g9m4-vfq7-w439.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9m4-vfq7-w439", + "modified": "2024-07-03T21:39:43Z", + "published": "2024-07-03T21:39:43Z", + "aliases": [ + "CVE-2024-29511" + ], + "details": "Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29511" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h538-6ch9-fvph/GHSA-h538-6ch9-fvph.json b/advisories/unreviewed/2024/07/GHSA-h538-6ch9-fvph/GHSA-h538-6ch9-fvph.json new file mode 100644 index 00000000000..869abf65dba --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h538-6ch9-fvph/GHSA-h538-6ch9-fvph.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h538-6ch9-fvph", + "modified": "2024-07-03T21:39:44Z", + "published": "2024-07-03T21:39:44Z", + "aliases": [ + "CVE-2024-6488" + ], + "details": "Rejected reason: REJECTED", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6488" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json b/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json new file mode 100644 index 00000000000..68c443058bc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjm5-gj95-f347", + "modified": "2024-07-03T21:39:43Z", + "published": "2024-07-03T21:39:43Z", + "aliases": [ + "CVE-2024-29507" + ], + "details": "Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29507" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707510" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=7745dbe24514" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json b/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json new file mode 100644 index 00000000000..b95b08a265d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mq7h-fm69-h6xq/GHSA-mq7h-fm69-h6xq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq7h-fm69-h6xq", + "modified": "2024-07-03T21:39:44Z", + "published": "2024-07-03T21:39:44Z", + "aliases": [ + "CVE-2024-33871" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33871" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707754" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=7145885041bb52cc23964f0aa2aec1b1c82b5908" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/06/28/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json index 29a52249a08..141ced7dd45 100644 --- a/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json +++ b/advisories/unreviewed/2024/07/GHSA-qh94-pjxq-88v7/GHSA-qh94-pjxq-88v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qh94-pjxq-88v7", - "modified": "2024-07-03T18:48:27Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-07-03T18:48:27Z", "aliases": [ "CVE-2024-39844" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/03/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json new file mode 100644 index 00000000000..7671009f1d1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r824-gq56-gjgx/GHSA-r824-gq56-gjgx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r824-gq56-gjgx", + "modified": "2024-07-03T21:39:43Z", + "published": "2024-07-03T21:39:43Z", + "aliases": [ + "CVE-2024-29510" + ], + "details": "Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29510" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707662" + }, + { + "type": "WEB", + "url": "https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v6hc-9c6c-f599/GHSA-v6hc-9c6c-f599.json b/advisories/unreviewed/2024/07/GHSA-v6hc-9c6c-f599/GHSA-v6hc-9c6c-f599.json new file mode 100644 index 00000000000..3bc216eadbd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v6hc-9c6c-f599/GHSA-v6hc-9c6c-f599.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6hc-9c6c-f599", + "modified": "2024-07-03T21:39:43Z", + "published": "2024-07-03T21:39:43Z", + "aliases": [ + "CVE-2024-33869" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33869" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707691" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/06/28/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json b/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json index 72fd92a74fc..7fa8633c3e3 100644 --- a/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json +++ b/advisories/unreviewed/2024/07/GHSA-wgw3-5w65-2g45/GHSA-wgw3-5w65-2g45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgw3-5w65-2g45", - "modified": "2024-07-03T18:48:28Z", + "modified": "2024-07-03T21:39:43Z", "published": "2024-07-03T18:48:28Z", "aliases": [ "CVE-2023-52168" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/03/10" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/10" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-wm9w-rjj3-j356/GHSA-wm9w-rjj3-j356.json b/advisories/unreviewed/2024/07/GHSA-wm9w-rjj3-j356/GHSA-wm9w-rjj3-j356.json new file mode 100644 index 00000000000..33d6e628740 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wm9w-rjj3-j356/GHSA-wm9w-rjj3-j356.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm9w-rjj3-j356", + "modified": "2024-07-03T21:39:44Z", + "published": "2024-07-03T21:39:44Z", + "aliases": [ + "CVE-2024-34750" + ], + "details": "Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.\n\nUsers are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34750" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T20:15:04Z" + } +} \ No newline at end of file