🏡 index : github.com/captn3m0/photon-os-advisories.git

author github-actions[bot] <github-actions[bot]@users.noreply.github.com> 2024-08-22 5:37:40.0 +00:00:00
committer github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> 2024-08-22 5:37:40.0 +00:00:00
commit
85b739f23f6bc6554a71c41c61f60465711b9df1 [patch]
tree
2cc26fcd004e0b56e215b661e6d56daa2d010a29
parent
2320d180bc6c6edcdec1700c6d52baf4c010252f
download
85b739f23f6bc6554a71c41c61f60465711b9df1.tar.gz

Update Advisories



Diff

 advisories/PHSA-2024-3.0-0772.json |  5 +++--
 advisories/PHSA-2024-3.0-0783.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-4.0-0670.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-4.0-0671.json | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0345.json | 22 +++++++++++++++++++++-
 advisories/PHSA-2024-5.0-0350.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0351.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0352.json | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 8 files changed, 271 insertions(+), 4 deletions(-)

diff --git a/advisories/PHSA-2024-3.0-0772.json b/advisories/PHSA-2024-3.0-0772.json
index 6724bbd..19ad9e8 100644
--- a/advisories/PHSA-2024-3.0-0772.json
+++ a/advisories/PHSA-2024-3.0-0772.json
@@ -45,7 +45,7 @@
        }

    ],

    "id": "PHSA-2024-3.0-0772",
    "modified": "2024-08-08T05:24:47Z",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-07-17T00:00:00Z",
    "references": [
        {
@@ -55,6 +55,7 @@
    ],

    "related": [
        "CVE-2024-34402",
        "CVE-2024-40902"
        "CVE-2024-40902",
        "CVE-2024-41087"
    ]

}
diff --git a/advisories/PHSA-2024-3.0-0783.json b/advisories/PHSA-2024-3.0-0783.json
new file mode 100644
index 0000000..96bfeb6 100644
--- /dev/null
+++ a/advisories/PHSA-2024-3.0-0783.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:3.0",
                "name": "go",
                "purl": "pkg:rpm/vmware/go?distro=photon-3"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.20.14-2.ph3"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-3.0-0783",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-21T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-3.0-783"
        }

    ],

    "related": [
        "CVE-2024-24784"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0670.json b/advisories/PHSA-2024-4.0-0670.json
new file mode 100644
index 0000000..c227741 100644
--- /dev/null
+++ a/advisories/PHSA-2024-4.0-0670.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "nginx",
                "purl": "pkg:rpm/vmware/nginx?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.26.2-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0670",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-21T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-4.0-670"
        }

    ],

    "related": [
        "CVE-2024-7347"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0671.json b/advisories/PHSA-2024-4.0-0671.json
new file mode 100644
index 0000000..192e16b 100644
--- /dev/null
+++ a/advisories/PHSA-2024-4.0-0671.json
@@ -1,0 +1,56 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "unbound",
                "purl": "pkg:rpm/vmware/unbound?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.16.3-3.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "vim",
                "purl": "pkg:rpm/vmware/vim?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "9.1.0682-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0671",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-21T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-4.0-671"
        }

    ],

    "related": [
        "CVE-2024-43167",
        "CVE-2024-41965",
        "CVE-2024-41957",
        "CVE-2024-43168",
        "CVE-2024-43374"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0345.json b/advisories/PHSA-2024-5.0-0345.json
index 5fc0555..4828fd6 100644
--- a/advisories/PHSA-2024-5.0-0345.json
+++ a/advisories/PHSA-2024-5.0-0345.json
@@ -52,7 +52,7 @@
        }

    ],

    "id": "PHSA-2024-5.0-0345",
    "modified": "2024-08-20T05:25:16Z",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-09T00:00:00Z",
    "references": [
        {
@@ -67,6 +67,24 @@
        "CVE-2024-42246",
        "CVE-2024-42247",
        "CVE-2024-42225",
        "CVE-2024-42161"
        "CVE-2024-42161",
        "CVE-2024-41027",
        "CVE-2024-42153",
        "CVE-2024-41049",
        "CVE-2024-41048",
        "CVE-2024-41055",
        "CVE-2024-41076",
        "CVE-2024-41060",
        "CVE-2024-41069",
        "CVE-2024-41058",
        "CVE-2024-41063",
        "CVE-2024-41062",
        "CVE-2024-41078",
        "CVE-2024-41038",
        "CVE-2024-41073",
        "CVE-2024-41050",
        "CVE-2024-41072",
        "CVE-2024-41079",
        "CVE-2024-42157"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0350.json b/advisories/PHSA-2024-5.0-0350.json
new file mode 100644
index 0000000..c68fd34 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0350.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "nginx",
                "purl": "pkg:rpm/vmware/nginx?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.26.2-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0350",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-19T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-350"
        }

    ],

    "related": [
        "CVE-2024-7347"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0351.json b/advisories/PHSA-2024-5.0-0351.json
new file mode 100644
index 0000000..a853978 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0351.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "grpc",
                "purl": "pkg:rpm/vmware/grpc?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.59.5-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0351",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-21T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-351"
        }

    ],

    "related": [
        "CVE-2024-7246"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0352.json b/advisories/PHSA-2024-5.0-0352.json
new file mode 100644
index 0000000..352f6b8 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0352.json
@@ -1,0 +1,56 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "unbound",
                "purl": "pkg:rpm/vmware/unbound?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.17.0-5.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "vim",
                "purl": "pkg:rpm/vmware/vim?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "9.1.0682-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0352",
    "modified": "2024-08-22T05:25:28Z",
    "published": "2024-08-21T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-352"
        }

    ],

    "related": [
        "CVE-2024-43167",
        "CVE-2024-41965",
        "CVE-2024-41957",
        "CVE-2024-43168",
        "CVE-2024-43374"
    ]

}