🏡 index : github.com/captn3m0/photon-os-advisories.git

author github-actions[bot] <github-actions[bot]@users.noreply.github.com> 2024-09-04 5:38:23.0 +00:00:00
committer github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> 2024-09-04 5:38:23.0 +00:00:00
commit
ccf30a01c984ff03ee93b9a711e48b0c4ce50a51 [patch]
tree
ce0ff8a5d68968addefdae9214c9a28da057356d
parent
aa9c0e200a6a6f9df9fbb5951249a2f46ce10607
download
ccf30a01c984ff03ee93b9a711e48b0c4ce50a51.tar.gz

Update Advisories



Diff

 advisories/PHSA-2024-3.0-0788.json | 23 +++++++++++++++++++++--
 advisories/PHSA-2024-3.0-0789.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-4.0-0669.json | 23 +++++++++++++++++++++--
 advisories/PHSA-2024-4.0-0673.json | 24 ++++++++++++++++++++++--
 advisories/PHSA-2024-4.0-0677.json | 90 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-4.0-0678.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-4.0-0679.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0345.json | 11 +++++++++--
 advisories/PHSA-2024-5.0-0354.json | 42 ++++++++++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0355.json | 35 +++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0357.json | 34 ++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0359.json | 94 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 advisories/PHSA-2024-5.0-0360.json | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++
 13 files changed, 520 insertions(+), 10 deletions(-)

diff --git a/advisories/PHSA-2024-3.0-0788.json b/advisories/PHSA-2024-3.0-0788.json
index ffb9b1b..18f2b45 100644
--- a/advisories/PHSA-2024-3.0-0788.json
+++ a/advisories/PHSA-2024-3.0-0788.json
@@ -99,10 +99,28 @@
                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:3.0",
                "name": "linux-secure",
                "purl": "pkg:rpm/vmware/linux-secure?distro=photon-3"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "4.19.320-1.ph3"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-3.0-0788",
    "modified": "2024-08-31T05:25:08Z",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-28T00:00:00Z",
    "references": [
        {
@@ -115,6 +133,7 @@
        "CVE-2024-42271",
        "CVE-2024-42285",
        "CVE-2024-43858",
        "CVE-2024-42301"
        "CVE-2024-42301",
        "CVE-2024-27397"
    ]

}
diff --git a/advisories/PHSA-2024-3.0-0789.json b/advisories/PHSA-2024-3.0-0789.json
new file mode 100644
index 0000000..ae5b16d 100644
--- /dev/null
+++ a/advisories/PHSA-2024-3.0-0789.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:3.0",
                "name": "unbound",
                "purl": "pkg:rpm/vmware/unbound?distro=photon-3"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.21.0-1.ph3"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-3.0-0789",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-28T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-3.0-789"
        }

    ],

    "related": [
        "CVE-2024-33655"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0669.json b/advisories/PHSA-2024-4.0-0669.json
index 2b61e0a..7f00066 100644
--- a/advisories/PHSA-2024-4.0-0669.json
+++ a/advisories/PHSA-2024-4.0-0669.json
@@ -17,10 +17,28 @@
                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "linux-aws",
                "purl": "pkg:rpm/vmware/linux-aws?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "5.10.223-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0669",
    "modified": "2024-08-27T05:25:47Z",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-19T00:00:00Z",
    "references": [
        {
@@ -36,6 +54,7 @@
        "CVE-2024-41091",
        "CVE-2024-41063",
        "CVE-2024-41022",
        "CVE-2024-41012"
        "CVE-2024-41012",
        "CVE-2024-36938"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0673.json b/advisories/PHSA-2024-4.0-0673.json
index 61097de..469b14a 100644
--- a/advisories/PHSA-2024-4.0-0673.json
+++ a/advisories/PHSA-2024-4.0-0673.json
@@ -17,10 +17,28 @@
                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "python3",
                "purl": "pkg:rpm/vmware/python3?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "3.10.11-10.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0673",
    "modified": "2024-08-24T05:25:37Z",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-23T00:00:00Z",
    "references": [
        {
@@ -29,6 +47,8 @@
        }

    ],

    "related": [
        "CVE-2024-7006"
        "CVE-2024-7006",
        "CVE-2024-6923",
        "CVE-2023-6597"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0677.json b/advisories/PHSA-2024-4.0-0677.json
new file mode 100644
index 0000000..07d258d 100644
--- /dev/null
+++ a/advisories/PHSA-2024-4.0-0677.json
@@ -1,0 +1,90 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "linux",
                "purl": "pkg:rpm/vmware/linux?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "5.10.224-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "unbound",
                "purl": "pkg:rpm/vmware/unbound?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.21.0-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "linux-aws",
                "purl": "pkg:rpm/vmware/linux-aws?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "5.10.224-1.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0677",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-28T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-4.0-677"
        }

    ],

    "related": [
        "CVE-2024-43828",
        "CVE-2024-43839",
        "CVE-2024-43830",
        "CVE-2024-42285",
        "CVE-2024-43880",
        "CVE-2024-41042",
        "CVE-2024-43834",
        "CVE-2024-33655",
        "CVE-2024-43908",
        "CVE-2024-42284",
        "CVE-2024-43893",
        "CVE-2024-43907",
        "CVE-2024-42302",
        "CVE-2024-42126",
        "CVE-2024-44935",
        "CVE-2024-42301",
        "CVE-2024-42271",
        "CVE-2024-43914",
        "CVE-2024-43889",
        "CVE-2024-43856",
        "CVE-2024-43894"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0678.json b/advisories/PHSA-2024-4.0-0678.json
new file mode 100644
index 0000000..abc8e74 100644
--- /dev/null
+++ a/advisories/PHSA-2024-4.0-0678.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "linux",
                "purl": "pkg:rpm/vmware/linux?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "5.10.224-2.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0678",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-29T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-4.0-678"
        }

    ],

    "related": [
        "CVE-2024-41073"
    ]

}
diff --git a/advisories/PHSA-2024-4.0-0679.json b/advisories/PHSA-2024-4.0-0679.json
new file mode 100644
index 0000000..03ae268 100644
--- /dev/null
+++ a/advisories/PHSA-2024-4.0-0679.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:4.0",
                "name": "krb5",
                "purl": "pkg:rpm/vmware/krb5?distro=photon-4"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.17-12.ph4"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-4.0-0679",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-09-02T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-4.0-679"
        }

    ],

    "related": [
        "CVE-2024-37371"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0345.json b/advisories/PHSA-2024-5.0-0345.json
index 8459dd3..80dd9ce 100644
--- a/advisories/PHSA-2024-5.0-0345.json
+++ a/advisories/PHSA-2024-5.0-0345.json
@@ -52,7 +52,7 @@
        }

    ],

    "id": "PHSA-2024-5.0-0345",
    "modified": "2024-08-24T05:25:37Z",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-09T00:00:00Z",
    "references": [
        {
@@ -108,6 +108,13 @@
        "CVE-2024-42103",
        "CVE-2024-42148",
        "CVE-2024-42101",
        "CVE-2024-42119"
        "CVE-2024-42119",
        "CVE-2024-42145",
        "CVE-2024-42229",
        "CVE-2024-42120",
        "CVE-2024-42109",
        "CVE-2024-42152",
        "CVE-2024-42226",
        "CVE-2024-42131"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0354.json b/advisories/PHSA-2024-5.0-0354.json
index 3be7ec1..2f19e3a 100644
--- a/advisories/PHSA-2024-5.0-0354.json
+++ a/advisories/PHSA-2024-5.0-0354.json
@@ -17,10 +17,46 @@
                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "libxml2",
                "purl": "pkg:rpm/vmware/libxml2?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "2.12.6-3.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "python3",
                "purl": "pkg:rpm/vmware/python3?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "3.11.9-3.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0354",
    "modified": "2024-08-24T05:25:37Z",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-24T00:00:00Z",
    "references": [
        {
@@ -29,6 +65,8 @@
        }

    ],

    "related": [
        "CVE-2024-7006"
        "CVE-2024-7006",
        "CVE-2024-6923",
        "CVE-2024-40896"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0355.json b/advisories/PHSA-2024-5.0-0355.json
new file mode 100644
index 0000000..4164ea0 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0355.json
@@ -1,0 +1,35 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "krb5",
                "purl": "pkg:rpm/vmware/krb5?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.20.2-4.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0355",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-26T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-355"
        }

    ],

    "related": [
        "CVE-2024-37370",
        "CVE-2024-37371"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0357.json b/advisories/PHSA-2024-5.0-0357.json
new file mode 100644
index 0000000..b0a43c8 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0357.json
@@ -1,0 +1,34 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "unbound",
                "purl": "pkg:rpm/vmware/unbound?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "1.21.0-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0357",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-27T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-357"
        }

    ],

    "related": [
        "CVE-2024-33655"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0359.json b/advisories/PHSA-2024-5.0-0359.json
new file mode 100644
index 0000000..18b53b1 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0359.json
@@ -1,0 +1,94 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "linux",
                "purl": "pkg:rpm/vmware/linux?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "6.1.106-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "linux-rt",
                "purl": "pkg:rpm/vmware/linux-rt?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "6.1.106-1.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0359",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-28T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-359"
        }

    ],

    "related": [
        "CVE-2024-43828",
        "CVE-2024-43839",
        "CVE-2024-42313",
        "CVE-2024-43830",
        "CVE-2024-43905",
        "CVE-2024-43870",
        "CVE-2024-43858",
        "CVE-2024-43833",
        "CVE-2024-43909",
        "CVE-2024-42285",
        "CVE-2024-44934",
        "CVE-2024-43902",
        "CVE-2024-42283",
        "CVE-2024-43853",
        "CVE-2024-43880",
        "CVE-2024-41042",
        "CVE-2024-43834",
        "CVE-2024-43890",
        "CVE-2024-43837",
        "CVE-2024-43908",
        "CVE-2024-42284",
        "CVE-2024-43900",
        "CVE-2024-43860",
        "CVE-2024-43867",
        "CVE-2024-43863",
        "CVE-2024-43903",
        "CVE-2024-43879",
        "CVE-2024-43873",
        "CVE-2024-43855",
        "CVE-2024-43907",
        "CVE-2023-52889",
        "CVE-2024-42302",
        "CVE-2024-43854",
        "CVE-2024-44935",
        "CVE-2024-42301",
        "CVE-2024-43871",
        "CVE-2024-43817",
        "CVE-2024-43861",
        "CVE-2024-42271",
        "CVE-2024-43889",
        "CVE-2024-43869",
        "CVE-2024-43856",
        "CVE-2024-43882"
    ]

}
diff --git a/advisories/PHSA-2024-5.0-0360.json b/advisories/PHSA-2024-5.0-0360.json
new file mode 100644
index 0000000..9754193 100644
--- /dev/null
+++ a/advisories/PHSA-2024-5.0-0360.json
@@ -1,0 +1,52 @@
{
    "affected": [
        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "linux",
                "purl": "pkg:rpm/vmware/linux?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "6.1.106-2.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        },

        {
            "package": {
                "ecosystem": "Photon OS:5.0",
                "name": "linux-rt",
                "purl": "pkg:rpm/vmware/linux-rt?distro=photon-5"
            },

            "ranges": {
                "events": [
                    {
                        "introduced": "0"
                    },

                    {
                        "fixed": "6.1.106-2.ph5"
                    }

                ],

                "type": "ECOSYSTEM"
            }

        }

    ],

    "id": "PHSA-2024-5.0-0360",
    "modified": "2024-09-04T05:26:24Z",
    "published": "2024-08-29T00:00:00Z",
    "references": [
        {
            "type": "ADVISORY",
            "url": "https://github.com/vmware/photon/wiki/Security-Update-5.0-360"
        }

    ],

    "related": [
        "CVE-2024-42314"
    ]

}