From e226dd7f6cee6703aa18d52cec2ba12435579084 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 28 Feb 2024 03:31:53 +0000 Subject: [PATCH] Publish Advisories GHSA-72xf-g2v4-qvf3 GHSA-x9w5-v3q2-3rhw GHSA-8c82-xj9x-mxgj GHSA-hm4h-jq5c-c933 GHSA-28p7-rxh6-3h6x GHSA-63f3-2rgp-79qx GHSA-67p4-4qm6-h6gq GHSA-6pc7-4x73-wwc6 GHSA-7pp5-c4g8-xxc4 GHSA-cr7m-mx45-3638 GHSA-fm2x-2crw-hf7h GHSA-fq97-hv4f-crm6 GHSA-j66f-jc3v-93vp GHSA-j737-8h5g-42g9 GHSA-jg84-v5xw-8m52 GHSA-rjjw-vjj8-q96x GHSA-xf63-228h-qhch GHSA-xjjp-35cq-88wh --- .../GHSA-72xf-g2v4-qvf3.json | 10 ++++- .../GHSA-x9w5-v3q2-3rhw.json | 18 +++++++- .../GHSA-8c82-xj9x-mxgj.json | 6 ++- .../GHSA-hm4h-jq5c-c933.json | 6 ++- .../GHSA-28p7-rxh6-3h6x.json | 6 ++- .../GHSA-63f3-2rgp-79qx.json | 10 ++++- .../GHSA-67p4-4qm6-h6gq.json | 42 +++++++++++++++++++ .../GHSA-6pc7-4x73-wwc6.json | 6 ++- .../GHSA-7pp5-c4g8-xxc4.json | 10 ++++- .../GHSA-cr7m-mx45-3638.json | 38 +++++++++++++++++ .../GHSA-fm2x-2crw-hf7h.json | 38 +++++++++++++++++ .../GHSA-fq97-hv4f-crm6.json | 10 ++++- .../GHSA-j66f-jc3v-93vp.json | 10 ++++- .../GHSA-j737-8h5g-42g9.json | 10 ++++- .../GHSA-jg84-v5xw-8m52.json | 38 +++++++++++++++++ .../GHSA-rjjw-vjj8-q96x.json | 10 ++++- .../GHSA-xf63-228h-qhch.json | 6 ++- .../GHSA-xjjp-35cq-88wh.json | 38 +++++++++++++++++ 18 files changed, 299 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-67p4-4qm6-h6gq/GHSA-67p4-4qm6-h6gq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cr7m-mx45-3638/GHSA-cr7m-mx45-3638.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fm2x-2crw-hf7h/GHSA-fm2x-2crw-hf7h.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jg84-v5xw-8m52/GHSA-jg84-v5xw-8m52.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xjjp-35cq-88wh/GHSA-xjjp-35cq-88wh.json diff --git a/advisories/github-reviewed/2023/07/GHSA-72xf-g2v4-qvf3/GHSA-72xf-g2v4-qvf3.json b/advisories/github-reviewed/2023/07/GHSA-72xf-g2v4-qvf3/GHSA-72xf-g2v4-qvf3.json index 9305da05b60..d469dc7379b 100644 --- a/advisories/github-reviewed/2023/07/GHSA-72xf-g2v4-qvf3/GHSA-72xf-g2v4-qvf3.json +++ b/advisories/github-reviewed/2023/07/GHSA-72xf-g2v4-qvf3/GHSA-72xf-g2v4-qvf3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72xf-g2v4-qvf3", - "modified": "2023-07-07T21:39:57Z", + "modified": "2024-02-28T03:30:30Z", "published": "2023-07-01T06:30:16Z", "aliases": [ "CVE-2023-26136" @@ -65,6 +65,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00010.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ" + }, { "type": "WEB", "url": "https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873" diff --git a/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json b/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json index f5d5bc1a517..58a83216011 100644 --- a/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json +++ b/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9w5-v3q2-3rhw", - "modified": "2023-10-26T20:53:21Z", + "modified": "2024-02-28T03:30:30Z", "published": "2023-10-26T20:53:21Z", "aliases": [ "CVE-2023-46234" @@ -59,6 +59,22 @@ { "type": "PACKAGE", "url": "https://github.com/browserify/browserify-sign" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00040.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5539" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-8c82-xj9x-mxgj/GHSA-8c82-xj9x-mxgj.json b/advisories/unreviewed/2024/01/GHSA-8c82-xj9x-mxgj/GHSA-8c82-xj9x-mxgj.json index 45c0f158b4f..1f478f14d73 100644 --- a/advisories/unreviewed/2024/01/GHSA-8c82-xj9x-mxgj/GHSA-8c82-xj9x-mxgj.json +++ b/advisories/unreviewed/2024/01/GHSA-8c82-xj9x-mxgj/GHSA-8c82-xj9x-mxgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c82-xj9x-mxgj", - "modified": "2024-01-30T00:30:29Z", + "modified": "2024-02-28T03:30:29Z", "published": "2024-01-23T09:30:22Z", "aliases": [ "CVE-2024-23850" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23850" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/6a80cb4b32af89787dadee728310e5e2ca85343f.1705741883.git.wqu%40suse.com" diff --git a/advisories/unreviewed/2024/01/GHSA-hm4h-jq5c-c933/GHSA-hm4h-jq5c-c933.json b/advisories/unreviewed/2024/01/GHSA-hm4h-jq5c-c933/GHSA-hm4h-jq5c-c933.json index 6bee6e0ccff..132f9f49707 100644 --- a/advisories/unreviewed/2024/01/GHSA-hm4h-jq5c-c933/GHSA-hm4h-jq5c-c933.json +++ b/advisories/unreviewed/2024/01/GHSA-hm4h-jq5c-c933/GHSA-hm4h-jq5c-c933.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm4h-jq5c-c933", - "modified": "2024-01-30T00:30:29Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-01-23T09:30:22Z", "aliases": [ "CVE-2024-23851" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23851" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, { "type": "WEB", "url": "https://www.spinics.net/lists/dm-devel/msg56574.html" diff --git a/advisories/unreviewed/2024/02/GHSA-28p7-rxh6-3h6x/GHSA-28p7-rxh6-3h6x.json b/advisories/unreviewed/2024/02/GHSA-28p7-rxh6-3h6x/GHSA-28p7-rxh6-3h6x.json index be2230f5857..d150c2d09ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-28p7-rxh6-3h6x/GHSA-28p7-rxh6-3h6x.json +++ b/advisories/unreviewed/2024/02/GHSA-28p7-rxh6-3h6x/GHSA-28p7-rxh6-3h6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28p7-rxh6-3h6x", - "modified": "2024-02-27T06:30:31Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-27T06:30:31Z", "aliases": [ "CVE-2023-7033" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://jvn.jp/vu/JVNVU96145466/index.html" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-058-01" + }, { "type": "WEB", "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-023_en.pdf" diff --git a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json index a0e53e7ec42..4ca930271aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json +++ b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63f3-2rgp-79qx", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26585" @@ -29,6 +29,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-67p4-4qm6-h6gq/GHSA-67p4-4qm6-h6gq.json b/advisories/unreviewed/2024/02/GHSA-67p4-4qm6-h6gq/GHSA-67p4-4qm6-h6gq.json new file mode 100644 index 00000000000..6bcb187a809 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-67p4-4qm6-h6gq/GHSA-67p4-4qm6-h6gq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67p4-4qm6-h6gq", + "modified": "2024-02-28T03:30:30Z", + "published": "2024-02-28T03:30:30Z", + "aliases": [ + "CVE-2023-50303" + ], + "details": "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273333.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50303" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/273333" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7116120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-28T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json index 87b6e8376b7..4f72f79aaa5 100644 --- a/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json +++ b/advisories/unreviewed/2024/02/GHSA-6pc7-4x73-wwc6/GHSA-6pc7-4x73-wwc6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pc7-4x73-wwc6", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26606" @@ -49,6 +49,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/dd64bb8329ce0ea27bc557e4160c2688835402ac" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json index 6051f411b47..1fd6a39677d 100644 --- a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json +++ b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pp5-c4g8-xxc4", - "modified": "2024-02-23T12:30:31Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-23T12:30:31Z", "aliases": [ "CVE-2024-26593" @@ -45,6 +45,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/d074d5ff5ae77b18300e5079c6bda6342a4d44b7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-cr7m-mx45-3638/GHSA-cr7m-mx45-3638.json b/advisories/unreviewed/2024/02/GHSA-cr7m-mx45-3638/GHSA-cr7m-mx45-3638.json new file mode 100644 index 00000000000..d372878705d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cr7m-mx45-3638/GHSA-cr7m-mx45-3638.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr7m-mx45-3638", + "modified": "2024-02-28T03:30:30Z", + "published": "2024-02-28T03:30:30Z", + "aliases": [ + "CVE-2023-50734" + ], + "details": "A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50734" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-28T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fm2x-2crw-hf7h/GHSA-fm2x-2crw-hf7h.json b/advisories/unreviewed/2024/02/GHSA-fm2x-2crw-hf7h/GHSA-fm2x-2crw-hf7h.json new file mode 100644 index 00000000000..e11907332b5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fm2x-2crw-hf7h/GHSA-fm2x-2crw-hf7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm2x-2crw-hf7h", + "modified": "2024-02-28T03:30:30Z", + "published": "2024-02-28T03:30:30Z", + "aliases": [ + "CVE-2023-50736" + ], + "details": "A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50736" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-28T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json b/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json index d12a20b0c11..405acc83db2 100644 --- a/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json +++ b/advisories/unreviewed/2024/02/GHSA-fq97-hv4f-crm6/GHSA-fq97-hv4f-crm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq97-hv4f-crm6", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26603" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/d877550eaf2dc9090d782864c96939397a3c6835" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json b/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json index 6e77694d122..4587b40d0fd 100644 --- a/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json +++ b/advisories/unreviewed/2024/02/GHSA-j66f-jc3v-93vp/GHSA-j66f-jc3v-93vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j66f-jc3v-93vp", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26582" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/d684763534b969cca1022e2a28645c7cc91f7fa5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json b/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json index 1b2d00abdf1..f7511a51ba2 100644 --- a/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json +++ b/advisories/unreviewed/2024/02/GHSA-j737-8h5g-42g9/GHSA-j737-8h5g-42g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j737-8h5g-42g9", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26583" @@ -33,6 +33,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-jg84-v5xw-8m52/GHSA-jg84-v5xw-8m52.json b/advisories/unreviewed/2024/02/GHSA-jg84-v5xw-8m52/GHSA-jg84-v5xw-8m52.json new file mode 100644 index 00000000000..b1882599ef5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jg84-v5xw-8m52/GHSA-jg84-v5xw-8m52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg84-v5xw-8m52", + "modified": "2024-02-28T03:30:30Z", + "published": "2024-02-28T03:30:30Z", + "aliases": [ + "CVE-2023-50737" + ], + "details": "The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50737" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-28T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json index e8efd51c3b3..4d9c9c89bc8 100644 --- a/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json +++ b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjjw-vjj8-q96x", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26584" @@ -29,6 +29,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/ab6397f072e5097f267abf5cb08a8004e6b17694" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OX4EWCYDZRTOEMC2C6OF7ZACAP23SUB5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json b/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json index 932e4bef712..5ce968f561e 100644 --- a/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json +++ b/advisories/unreviewed/2024/02/GHSA-xf63-228h-qhch/GHSA-xf63-228h-qhch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xf63-228h-qhch", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-02-28T03:30:30Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26604" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/b746d52ce7bcac325a2fa264216ead85b7fbbfaa" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-xjjp-35cq-88wh/GHSA-xjjp-35cq-88wh.json b/advisories/unreviewed/2024/02/GHSA-xjjp-35cq-88wh/GHSA-xjjp-35cq-88wh.json new file mode 100644 index 00000000000..27a512a98c3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xjjp-35cq-88wh/GHSA-xjjp-35cq-88wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjjp-35cq-88wh", + "modified": "2024-02-28T03:30:30Z", + "published": "2024-02-28T03:30:30Z", + "aliases": [ + "CVE-2023-50735" + ], + "details": "A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50735" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-28T03:15:07Z" + } +} \ No newline at end of file