2515 lines
83 KiB
Text
2515 lines
83 KiB
Text
<!DOCTYPE html>
|
|
|
|
<html lang="en">
|
|
<head>
|
|
|
|
|
|
|
|
<title>NVD - CVE-2023-2004</title>
|
|
|
|
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />
|
|
<meta http-equiv="content-style-type" content="text/css" />
|
|
<meta http-equiv="content-script-type" content="text/javascript" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|
|
|
|
|
<link href="/site-scripts/font-awesome/css/font-awesome.min.css"
|
|
type="text/css" rel="stylesheet" />
|
|
<link href="/site-media/bootstrap/css/bootstrap.min.css"
|
|
type="text/css" rel="stylesheet" />
|
|
<link href="/site-media/bootstrap/css/bootstrap-theme.min.css"
|
|
type="text/css" rel="stylesheet" />
|
|
<link
|
|
href="/site-scripts/eonasdan-bootstrap-datetimepicker/build/css/bootstrap-datetimepicker.min.css"
|
|
type="text/css" rel="stylesheet" />
|
|
|
|
|
|
<link href="/site-media/css/nist-fonts.css" type="text/css"
|
|
rel="stylesheet" />
|
|
<link href="/site-media/css/base-style.css" type="text/css"
|
|
rel="stylesheet" />
|
|
<link href="/site-media/css/media-resize.css" type="text/css"
|
|
rel="stylesheet" />
|
|
|
|
|
|
<meta name="theme-color" content="#000000">
|
|
|
|
|
|
<script src="/site-scripts/jquery/dist/jquery.min.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-scripts/jquery-visible/jquery.visible.min.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-scripts/underscore/underscore-min.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-media/bootstrap/js/bootstrap.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-scripts/moment/min/moment.min.js"
|
|
type="text/javascript"></script>
|
|
<script
|
|
src="/site-scripts/eonasdan-bootstrap-datetimepicker/build/js/bootstrap-datetimepicker.min.js"
|
|
type="text/javascript"></script>
|
|
|
|
|
|
<script src="/site-media/js/megamenu.js" type="text/javascript"></script>
|
|
<script src="/site-media/js/nist-exit-script.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-media/js/forms.js" type="text/javascript"></script>
|
|
|
|
<script
|
|
src="/site-media/js/federated-analytics.all.min.js?agency=NIST&subagency=nvd&pua=UA-37115410-41&yt=true"
|
|
type="text/javascript" id="_fed_an_js_tag"></script>
|
|
|
|
<!-- Google tag (gtag.js) -->
|
|
<script async src="https://www.googletagmanager.com/gtag/js?id=G-4KKFZP12LQ"></script>
|
|
<script> window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('js', new Date()); gtag('config', 'G-4KKFZP12LQ'); </script>
|
|
|
|
|
|
<style id="antiClickjack">
|
|
body>* {
|
|
display: none !important;
|
|
}
|
|
|
|
#antiClickjack {
|
|
display: block !important;
|
|
}
|
|
</style>
|
|
<noscript>
|
|
<style id="antiClickjackNoScript">
|
|
body>* {
|
|
display: block !important;
|
|
}
|
|
|
|
#antiClickjack {
|
|
display: none !important;
|
|
}
|
|
</style>
|
|
</noscript>
|
|
<script type="text/javascript" id="antiClickjackScript">
|
|
if (self === top) {
|
|
// no clickjacking
|
|
var antiClickjack = document.getElementById("antiClickjack");
|
|
antiClickjack.parentNode.removeChild(antiClickjack);
|
|
} else {
|
|
setTimeout(tryForward(), 5000);
|
|
}
|
|
|
|
function tryForward() {
|
|
top.location = self.location;
|
|
}
|
|
</script>
|
|
<meta charset="UTF-8">
|
|
|
|
<link href="/site-media/css/nvd-style.css" type="text/css"
|
|
rel="stylesheet" />
|
|
<link href="/site-media/images/favicons/apple-touch-icon.png"
|
|
rel="apple-touch-icon" type="image/png" sizes="180x180" />
|
|
<link href="/site-media/images/favicons/favicon-32x32.png"
|
|
rel="icon" type="image/png" sizes="32x32" />
|
|
<link href="/site-media/images/favicons/favicon-16x16.png"
|
|
rel="icon" type="image/png" sizes="16x16" />
|
|
<link href="/site-media/images/favicons/manifest.json"
|
|
rel="manifest" />
|
|
<link href="/site-media/images/favicons/safari-pinned-tab.svg"
|
|
rel="mask-icon" color="#000000" />
|
|
<link href="/site-media/images/favicons/favicon.ico"
|
|
rel="shortcut icon" />
|
|
<meta name="msapplication-config" content="/site-media/images/favicons/browserconfig.xml" />
|
|
<link href="/site-media/images/favicons/favicon.ico"
|
|
rel="shortcut icon" type="image/x-icon" />
|
|
<link href="/site-media/images/favicons/favicon.ico" rel="icon"
|
|
type="image/x-icon" />
|
|
<meta charset="UTF-8">
|
|
<script src="/site-media/js/vulnerability/vulnDetail.js"
|
|
type="text/javascript"></script>
|
|
<script src="/site-media/js/vulnerability/cvssVulnDetail.js"
|
|
type="text/javascript"></script>
|
|
|
|
</head>
|
|
<body>
|
|
<header role="banner" title="Site Banner">
|
|
<div id="antiClickjack" style="display: none">
|
|
<h1>You are viewing this page in an unauthorized frame window.</h1>
|
|
<p>
|
|
This is a potential security issue, you are being redirected to
|
|
<a href="https://nvd.nist.gov">https://nvd.nist.gov</a>
|
|
</p>
|
|
</div>
|
|
<div>
|
|
<section class="usa-banner" aria-label="Official government website">
|
|
<div class="usa-accordion container">
|
|
<header class="usa-banner__header">
|
|
<noscript>
|
|
<p style="font-size: 0.85rem; font-weight: bold;">You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.</p>
|
|
</noscript>
|
|
<img class="usa-banner__header-flag"
|
|
src="/site-media/images/usbanner/us_flag_small.png" alt="U.S. flag">
|
|
|
|
<span class="usa-banner__header-text">An official website of the United States government</span>
|
|
|
|
<button id="gov-banner-button" class="usa-accordion__button usa-banner__button" data-toggle="collapse" data-target="#gov-banner" aria-expanded="false" aria-controls="gov-banner">
|
|
<span class="usa-banner__button-text">Here's how you know</span>
|
|
</button>
|
|
</header>
|
|
<div class="usa-banner__content usa-accordion__content collapse" role="tabpanel" id="gov-banner" aria-expanded="true">
|
|
<div class="row">
|
|
<div class="col-md-5 col-sm-12">
|
|
<div class="row">
|
|
<div class="col-sm-2 col-xs-3">
|
|
<img class="usa-banner__icon usa-media-block__img"
|
|
src="/site-media/images/usbanner/icon-dot-gov.svg" alt="Dot gov">
|
|
</div>
|
|
<div class="col-sm-10 col-xs-9">
|
|
<p>
|
|
<strong>Official websites use .gov</strong>
|
|
<br>
|
|
A <strong>.gov</strong> website belongs to an official government organization in the United States.
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-md-5 col-sm-12">
|
|
<div class="row">
|
|
<div class="col-sm-2 col-xs-3">
|
|
<img class="usa-banner__icon usa-media-block__img"
|
|
src="/site-media/images/usbanner/icon-https.svg" alt="Https">
|
|
</div>
|
|
<div class="col-sm-10 col-xs-9">
|
|
<p>
|
|
<strong>Secure .gov websites use HTTPS</strong>
|
|
<br>
|
|
A <strong>lock</strong> (<img class="usa-banner__lock"
|
|
src="/site-media/images/usbanner/lock.svg" alt="Dot gov">) or <strong>https://</strong> means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
</div>
|
|
<div>
|
|
<div>
|
|
<nav id="navbar" class="navbar">
|
|
<div id="nist-menu-container" class="container">
|
|
<div class="row">
|
|
<!-- Brand -->
|
|
<div class="col-xs-6 col-md-4 navbar-header"
|
|
style="height:104px">
|
|
<a class="navbar-brand"
|
|
href="https://www.nist.gov"
|
|
target="_blank" rel="noopener noreferrer"
|
|
id="navbar-brand-image"
|
|
style="padding-top: 36px">
|
|
|
|
<img alt="National Institute of Standards and Technology"
|
|
src="/site-media/images/nist/nist-logo.svg"
|
|
width="110" height="30">
|
|
</a>
|
|
</div>
|
|
<div class="col-xs-6 col-md-8 navbar-nist-logo">
|
|
<span id="nvd-menu-button" class="pull-right" style="margin-top: 26px"> <a href="#">
|
|
<span class="fa fa-bars"></span> <span id="nvd-menu-full-text"><span
|
|
class="hidden-xxs">NVD </span>MENU</span>
|
|
</a>
|
|
</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="main-menu-row container">
|
|
<!-- Collect the nav links, forms, and other content for toggling -->
|
|
<div id="main-menu-drop" class="col-lg-12" style="display: none;">
|
|
<ul>
|
|
|
|
<li><a href="/general"> General <span
|
|
class="expander fa fa-plus" id="nvd-header-menu-general"
|
|
data-expander-name="general" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="general">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/general/nvd-dashboard">NVD Dashboard</a>
|
|
</p>
|
|
<p>
|
|
<a href="https://www.nist.gov/itl/nvd">News and Status Updates</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/general/faq">FAQ</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/general/visualizations">Visualizations</a>
|
|
</p>
|
|
<p>
|
|
<a href="/general/legal-disclaimer">Legal Disclaimer</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div></li>
|
|
<li><a href="/vuln"> Vulnerabilities <span
|
|
class="expander fa fa-plus"
|
|
id="nvd-header-menu-vulnerabilities"
|
|
data-expander-name="vulnerabilities" data-expanded="false">
|
|
<span class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="vulnerabilities">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln/search">Search & Statistics</a>
|
|
</p>
|
|
<p>
|
|
<a href="/vuln/categories">Weakness Types</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln/data-feeds">Legacy Data Feeds</a>
|
|
</p>
|
|
<p>
|
|
<a href="/vuln/vendor-comments">Vendor Comments</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln/cvmap">CVMAP</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div></li>
|
|
<li><a href="/vuln-metrics/cvss#"> Vulnerability Metrics <span
|
|
class="expander fa fa-plus" id="nvd-header-menu-metrics"
|
|
data-expander-name="metrics" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="metrics">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln-metrics/cvss/v4-calculator">CVSS v4.0
|
|
Calculators</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln-metrics/cvss/v3-calculator">CVSS v3.x
|
|
Calculators</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln-metrics/cvss/v2-calculator">CVSS v2.0
|
|
Calculator</a>
|
|
</p>
|
|
|
|
</div>
|
|
</div>
|
|
</div></li>
|
|
<li><a href="/products"> Products <span
|
|
class="expander fa fa-plus" id="nvd-header-menu-products"
|
|
data-expander-name="products" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="products">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/products/cpe">CPE Dictionary</a>
|
|
</p>
|
|
<p>
|
|
<a href="/products/cpe/search">CPE Search</a>
|
|
</p>
|
|
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/products/cpe/statistics">CPE Statistics</a>
|
|
</p>
|
|
<p>
|
|
<a href="/products/swid">SWID</a>
|
|
</p>
|
|
|
|
</div>
|
|
<div class="col-lg-4"></div>
|
|
</div>
|
|
</div></li>
|
|
<li>
|
|
<a href="/developers">Developers<span
|
|
class="expander fa fa-plus" id="nvd-header-menu-developers"
|
|
data-expander-name="developers" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="developers">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/developers/start-here">Start Here</a>
|
|
</p>
|
|
<p>
|
|
<a href="/developers/request-an-api-key">Request an API Key</a>
|
|
</p>
|
|
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/developers/vulnerabilities">Vulnerabilities</a>
|
|
</p>
|
|
<p>
|
|
<a href="/developers/products">Products</a>
|
|
</p>
|
|
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/developers/data-sources">Data Sources</a>
|
|
</p>
|
|
<p>
|
|
<a href="/developers/terms-of-use">Terms of Use</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</li>
|
|
<li><a href="/contact"> Contact NVD </a></li>
|
|
<li><a href="/other"> Other Sites <span
|
|
class="expander fa fa-plus" id="nvd-header-menu-othersites"
|
|
data-expander-name="otherSites" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="otherSites">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="https://ncp.nist.gov">Checklist (NCP) Repository</a>
|
|
</p>
|
|
<p>
|
|
<a href="https://ncp.nist.gov/cce">Configurations (CCE)</a>
|
|
</p>
|
|
<p>
|
|
<a href="https://csrc.nist.gov/Projects/risk-management/sp800-53-controls/release-search">800-53 Controls</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a
|
|
href="https://csrc.nist.gov/projects/scap-validation-program">SCAP
|
|
Validated Tools</a>
|
|
</p>
|
|
<p>
|
|
<a
|
|
href="https://csrc.nist.gov/projects/security-content-automation-protocol">SCAP</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a
|
|
href="https://csrc.nist.gov/projects/united-states-government-configuration-baseline">USGCB</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div></li>
|
|
|
|
<li><a href="/search"> Search <span
|
|
class="expander fa fa-plus" id="nvd-header-menu-search"
|
|
data-expander-name="search" data-expanded="false"> <span
|
|
class="element-invisible">Expand or Collapse</span>
|
|
</span>
|
|
</a>
|
|
<div style="display: none;" class="sub-menu"
|
|
data-expander-trigger="search">
|
|
<div class="row">
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/vuln/search">Vulnerability Search</a>
|
|
</p>
|
|
</div>
|
|
<div class="col-lg-4">
|
|
<p>
|
|
<a href="/products/cpe/search">CPE Search</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div></li>
|
|
|
|
|
|
|
|
|
|
</ul>
|
|
</div>
|
|
<!-- /#mobile-nav-container -->
|
|
</div>
|
|
|
|
</nav>
|
|
<section id="itl-header" class="has-menu">
|
|
<div class="container">
|
|
<div class="row">
|
|
<div class="col-sm-12 col-md-8">
|
|
<h2 class="hidden-xs hidden-sm">
|
|
<a href="https://www.nist.gov/itl" target="_blank" rel="noopener noreferrer">Information Technology Laboratory</a>
|
|
</h2>
|
|
<h1 class="hidden-xs hidden-sm">
|
|
<a id="nvd-header-link"
|
|
href="/">National Vulnerability Database</a>
|
|
</h1>
|
|
<h1 class="hidden-xs text-center hidden-md hidden-lg"
|
|
>National Vulnerability Database</h1>
|
|
<h1 class="hidden-sm hidden-md hidden-lg text-center"
|
|
>NVD</h1>
|
|
|
|
</div>
|
|
<div class="col-sm-12 col-md-4">
|
|
<a style="width: 100%; text-align: center; display: block;padding-top: 14px">
|
|
<img id="img-logo-nvd-lg"
|
|
alt="National Vulnerability Database"
|
|
src="/site-media/images/F_NIST-Logo-NVD-white.svg"
|
|
width="500" height="100">
|
|
</a>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
|
|
</div>
|
|
</div>
|
|
</header>
|
|
<main>
|
|
<div>
|
|
<div id="body-section" class="container">
|
|
<div class="row">
|
|
<ol class="breadcrumb">
|
|
<li><a href="/vuln" class="CMSBreadCrumbsLink">Vulnerabilities</a></li>
|
|
</ol>
|
|
</div>
|
|
<div>
|
|
<style>
|
|
/* wrap the words for CVSS v4 */
|
|
#nistv4Metric {
|
|
word-wrap: break-word;
|
|
}
|
|
</style>
|
|
|
|
<script>
|
|
/*<![CDATA[*/
|
|
var vuln = {
|
|
nistV4Present: false,
|
|
cnaV4Present: false,
|
|
nistV3Present: false,
|
|
cnaV3Present: false,
|
|
nistV2Present: false,
|
|
cnaV2Present: false
|
|
};
|
|
/*]]>*/
|
|
</script>
|
|
|
|
|
|
<div>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div id="vulnDetailPanel">
|
|
<table id="vulnDetailTableView" style="border-collapse: collapse;">
|
|
<tr>
|
|
<td colspan="2">
|
|
|
|
<h2 data-testid="page-header">
|
|
<i class="fa fa-bug fa-flip-vertical"></i><span
|
|
data-testid="page-header-vuln-id">CVE-2023-2004</span>
|
|
Detail
|
|
</h2>
|
|
|
|
|
|
|
|
<div class="row">
|
|
<div class="col-lg-9 col-md-7 col-sm-12">
|
|
<div id="vulnShowWarningDiv"
|
|
data-testid="vuln-warning-container">
|
|
<div
|
|
role="alert" data-testid="vuln-warning-alert-container" class="bs-callout bs-callout-danger">
|
|
<strong class="h4Size"><span
|
|
data-testid="vuln-warning-status-name">Rejected</span></strong>
|
|
<hr/>
|
|
<p data-testid="vuln-warning-banner-content">This CVE has been marked Rejected in the CVE List. These CVEs are stored in the NVD, but do not show up in search results by default.</p>
|
|
</div>
|
|
</div>
|
|
|
|
|
|
<h3 id="vulnDescriptionTitle"
|
|
data-testid="vuln-description-title">Current Description </h3>
|
|
<p data-testid="vuln-description">Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</p><br/>
|
|
|
|
|
|
|
|
<p>
|
|
<a href="#vulnCurrentDescriptionTitle"
|
|
style="text-decoration: underline" id="showVulnAnalysis"><i
|
|
class="fa fa-plus"></i>View Analysis Description</a>
|
|
</p>
|
|
<div id="vulnAnalysisDescription" style="display: none;">
|
|
<h3 data-testid="vuln-analysis-description-title">Analysis
|
|
Description</h3>
|
|
<p data-testid="vuln-analysis-description">An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c.</p>
|
|
</div>
|
|
|
|
|
|
|
|
<!-- CVSS Severity and Vector Strings -->
|
|
<div id="vulnCvssPanel" data-testid="vuln-cvss-container"
|
|
class="row bs-callout bs-callout-success cvssVulnDetail">
|
|
<h3 style="display: inline" title="CVSS is not a measure of risk">Metrics</h3>
|
|
 
|
|
<div id="cvssVulnDetailBtn" class="btn-group">
|
|
<button id="btn-cvss4" type="button" title="Click here to view CVSS 4.0 data"
|
|
class="btn default btn-lg cvssBtn">CVSS Version 4.0
|
|
</button>
|
|
<button id="btn-cvss3" type="button" title="Click here to view CVSS 3.x data"
|
|
class="btn default btn-lg cvssBtn">CVSS Version 3.x
|
|
</button>
|
|
<button id="btn-cvss2" type="button" title="Click here to view CVSS 2.0 data"
|
|
class="btn default btn-lg cvssBtn">CVSS Version 2.0
|
|
</button>
|
|
</div>
|
|
|
|
|
|
<div id="cvssEnrichmentNotes">
|
|
<i>
|
|
<small>
|
|
NVD enrichment efforts reference publicly available information to associate
|
|
vector strings. CVSS information contributed by other sources is also
|
|
displayed.
|
|
</small>
|
|
</i>
|
|
</div>
|
|
|
|
<!-- CVSS v4.0 -->
|
|
<div class="container-fluid" id="Vuln4CvssPanel" data-testid="vuln-cvss4-panel">
|
|
<strong>CVSS 4.0 Severity and Vector Strings:</strong>
|
|
<!-- NIST -->
|
|
<div class="row no-gutters">
|
|
<br/>
|
|
<div class="col-lg-3 col-sm-6">
|
|
<div class="row">
|
|
<div class="col-lg-3 col-sm-6">
|
|
<img
|
|
src="/site-media/images/NVD_NVD_Stack_Plain.svg"
|
|
class="cvssNvdIcon" alt="NIST CVSS score">
|
|
</div>
|
|
<div class="col-lg-9 col-sm-6">
|
|
<strong>NIST:</strong> <span class="wrapData"
|
|
data-testid="vuln-cvss4-source-nvd">NVD</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-lg-3 col-sm-6">
|
|
<span><strong> </strong><span
|
|
class="severityDetail"> <a
|
|
id="Cvss4NistCalculatorAnchorNA"
|
|
class="label label-default"
|
|
data-testid="vuln-cvss4-panel-score-na">N/A</a></span></span>
|
|
</div>
|
|
<div class="col-lg-6 col-sm-12">
|
|
|
|
<span> <span
|
|
data-testid="vuln-cvss4-nist-vector-na">NVD assessment
|
|
not yet provided.</span></span> <input type="hidden"
|
|
id="nistV4MetricHidden"
|
|
value=""/>
|
|
</div>
|
|
</div>
|
|
<!-- CNA -->
|
|
|
|
|
|
<!-- ADP -->
|
|
|
|
|
|
|
|
|
|
</div>
|
|
|
|
|
|
<!-- CVSS V3.x -->
|
|
<div class="container-fluid" id="Vuln3CvssPanel" data-testid="vuln-cvss3-panel"
|
|
style="display: none;">
|
|
<strong>CVSS 3.x Severity and Vector Strings:</strong>
|
|
<!-- NIST -->
|
|
<div class="row no-gutters">
|
|
<br/>
|
|
|
|
<div class="col-lg-3 col-sm-6">
|
|
<div class="row">
|
|
<div class="col-lg-3 col-sm-6">
|
|
<img
|
|
src="/site-media/images/NVD_NVD_Stack_Plain.svg"
|
|
class="cvssNvdIcon" alt="NIST CVSS score">
|
|
|
|
|
|
</div>
|
|
<div class="col-lg-9 col-sm-6">
|
|
<strong>NIST:</strong> <span class="wrapData"
|
|
data-testid="vuln-cvss3-source-nvd">NVD</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-lg-3 col-sm-6">
|
|
<span><strong>Base
|
|
Score:</strong> <span class="severityDetail"> <a
|
|
id="Cvss3NistCalculatorAnchorNA"
|
|
class="label label-default"
|
|
data-testid="vuln-cvss3-panel-score-na">N/A</a></span></span>
|
|
|
|
</div>
|
|
<div class="col-lg-6 col-sm-12">
|
|
|
|
<span> <span
|
|
data-testid="vuln-cvss3-nist-vector-na">NVD assessment
|
|
not yet provided.</span></span> <input type="hidden"
|
|
id="nistV3MetricHidden"
|
|
value=""/>
|
|
|
|
</div>
|
|
|
|
|
|
</div>
|
|
<!-- CNA -->
|
|
|
|
|
|
<!-- ADP -->
|
|
|
|
|
|
|
|
|
|
<!-- <div id="cvss3FootNote" class="cvssFootNote" >-->
|
|
<!-- <br/><br/>-->
|
|
<!-- <span id = "cvss3FootNoteSection" th:utext="${cvssData.cvss3FootNoteHtml}"></span>-->
|
|
<!-- </div>-->
|
|
</div>
|
|
|
|
<!-- CVSS V2.0 -->
|
|
<div class="container-fluid" id="Vuln2CvssPanel" data-testid="vuln-cvss2-panel"
|
|
style="display: none;">
|
|
<strong>CVSS 2.0 Severity and Vector Strings:</strong> <br/> <br/>
|
|
<!-- NIST -->
|
|
<div class="row no-gutters">
|
|
<div class="col-lg-3 col-sm-6">
|
|
<div class="row">
|
|
<div class="col-lg-3 col-sm-6">
|
|
<img
|
|
src="/site-media/images/NVD_NVD_Stack_Plain.svg"
|
|
class="cvssNvdIcon"
|
|
alt="National Institute of Standards and Technology">
|
|
</div>
|
|
<div class="col-lg-9 col-sm-6">
|
|
<strong>NIST:</strong> <span
|
|
data-testid="vuln-cvss2-source-nvd">NVD</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-lg-3 col-sm-6">
|
|
|
|
<span><strong>Base
|
|
Score:</strong> <span class="severityDetail"><a
|
|
id="Cvss2CalculatorAnchorNA" class="label label-default"
|
|
data-testid="vuln-cvss2-panel-score-na"
|
|
href=''>N/A</a></span></span>
|
|
|
|
</div>
|
|
<div class="col-lg-6 col-sm-12">
|
|
<span><span
|
|
data-testid="vuln-cvss2-panel-vector-na">NVD assessment
|
|
not yet provided.</span></span> <input type="hidden"
|
|
id="nistV2MetricHidden"
|
|
value=""/>
|
|
</div>
|
|
</div>
|
|
<!-- CNA -->
|
|
|
|
|
|
<!-- ADP -->
|
|
|
|
|
|
<!-- <div id = "cvss2FootNote" class="cvssFootNote" >-->
|
|
<!-- <br/><br/>-->
|
|
<!-- <span id = "cvss2FootNoteSection" th:utext="${cvssData.cvss2FootNoteHtml}"></span>-->
|
|
<!-- </div>-->
|
|
</div>
|
|
</div>
|
|
|
|
|
|
<div class="row col-sm-12">
|
|
|
|
|
|
|
|
<div id="vulnHyperlinksPanel">
|
|
<h3>References to Advisories, Solutions, and Tools</h3>
|
|
<p>
|
|
By selecting these links, you will be leaving NIST webspace.
|
|
We have provided these links to other web sites because they
|
|
may have information that would be of interest to you. No
|
|
inferences should be drawn on account of other sites being
|
|
referenced, or not, from this page. There may be other web
|
|
sites that are more appropriate for your purpose. NIST does
|
|
not necessarily endorse the views expressed, or concur with
|
|
the facts presented on these sites. Further, NIST does not
|
|
endorse any commercial products that may be mentioned on
|
|
these sites. Please address comments about this page to <a
|
|
href="mailto:nvd@nist.gov">nvd@nist.gov</a>.
|
|
</p>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-hyperlinks-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Hyperlink</th>
|
|
<th>Resource</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
|
|
|
|
|
|
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
<div id="vulnTechnicalDetailsDiv" class="technicalDetails"
|
|
data-testid="vuln-technical-details-container">
|
|
<h3>Weakness Enumeration</h3>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-CWEs-table">
|
|
<thead>
|
|
<tr>
|
|
<th>CWE-ID</th>
|
|
<th>CWE Name</th>
|
|
<th>Source</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
|
|
|
|
|
|
</tbody>
|
|
</table>
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div id="vulnChangeHistoryDiv"
|
|
data-testid="vuln-change-history-container">
|
|
<h3 id="VulnChangeHistorySection">Change History</h3>
|
|
<small> 12 change records found <a href="#VulnChangeHistorySection"
|
|
style="text-decoration: underline" id="changeHistoryToggle">show
|
|
changes</a>
|
|
</small>
|
|
<div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-0">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-0">11/06/2023 11:11:40 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-0">
|
|
<td
|
|
data-testid="vuln-change-history-0-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-0-type">Description</td>
|
|
<td data-testid="vuln-change-history-0-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-0-new">
|
|
|
|
<pre style="word-break: break-all !important">Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-1">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-1">5/26/2023 1:15:15 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Description</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c.</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
<pre style="word-break: break-all !important">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">CWE</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">Red Hat, Inc. CWE-190</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://access.redhat.com/security/cve/CVE-2023-2004 [Third Party Advisory]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462 [Mailing List, Patch]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://bugzilla.redhat.com/show_bug.cgi?id=2186428 [Issue Tracking, Patch]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://github.com/freetype/freetype/commit/e6fda039ad638866b7a6a5d046f03278ba1b7611 [Patch]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/ [Mailing List, Release Notes]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ES2CDRHR2Y4WY6DNDIAPYZFXJU3ZBFAV/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/ [Mailing List, Release Notes]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IHHD6KNH4WLUE6JG6HRQZWNAJMHJ32X7/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDNGTGQAUZJ6YQDI2AVGYIFFPUMMZLKS/ [Mailing List, Third Party Advisory]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGWWGQULJ7QRNP4GY57HE7OO7VMRWMPN/ [Mailing List, Release Notes]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/ [Mailing List, Release Notes]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFZWDF43D73C5KWFF26GIIVZJKEFPS3K/ [Mailing List, Third Party Advisory]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLO7BL2MHZYPY6O3OAEAQL3SKYMGGO6M/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-1">
|
|
<td
|
|
data-testid="vuln-change-history-1-action">Removed</td>
|
|
<td
|
|
data-testid="vuln-change-history-1-type">Reference</td>
|
|
<td data-testid="vuln-change-history-1-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRSEIYMPWLVPGTC34N2Q3WAUHGGOWSWP/ [Mailing List, Third Party Advisory]</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-1-new">
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-2">CVE Rejected by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-2">5/26/2023 1:15:14 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-3">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-3">5/01/2023 11:15:08 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-3">
|
|
<td
|
|
data-testid="vuln-change-history-3-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-3-type">Reference</td>
|
|
<td data-testid="vuln-change-history-3-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-3-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ES2CDRHR2Y4WY6DNDIAPYZFXJU3ZBFAV/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-4">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-4">4/26/2023 10:15:09 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-4">
|
|
<td
|
|
data-testid="vuln-change-history-4-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-4-type">Reference</td>
|
|
<td data-testid="vuln-change-history-4-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-4-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLO7BL2MHZYPY6O3OAEAQL3SKYMGGO6M/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-5">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-5">4/26/2023 12:15:09 AM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-5">
|
|
<td
|
|
data-testid="vuln-change-history-5-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-5-type">Reference</td>
|
|
<td data-testid="vuln-change-history-5-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-5-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IHHD6KNH4WLUE6JG6HRQZWNAJMHJ32X7/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-6">Initial Analysis by NIST</span> <span
|
|
data-testid="vuln-change-history-date-6">4/24/2023 1:50:08 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">CVSS V3.1</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">CWE</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">NIST CWE-190</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">CPE Configuration</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">OR
|
|
*cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:* versions up to (excluding) 2.13.0</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">CPE Configuration</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">OR
|
|
*cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
|
|
*cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
|
|
*cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">CPE Configuration</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">OR
|
|
*cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
|
|
*cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://access.redhat.com/security/cve/CVE-2023-2004 No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://access.redhat.com/security/cve/CVE-2023-2004 Third Party Advisory</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462 No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462 Mailing List, Patch</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://bugzilla.redhat.com/show_bug.cgi?id=2186428 No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://bugzilla.redhat.com/show_bug.cgi?id=2186428 Issue Tracking, Patch</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://github.com/freetype/freetype/commit/e6fda039ad638866b7a6a5d046f03278ba1b7611 No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://github.com/freetype/freetype/commit/e6fda039ad638866b7a6a5d046f03278ba1b7611 Patch</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/ Mailing List, Release Notes</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/ Mailing List, Release Notes</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDNGTGQAUZJ6YQDI2AVGYIFFPUMMZLKS/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDNGTGQAUZJ6YQDI2AVGYIFFPUMMZLKS/ Mailing List, Third Party Advisory</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGWWGQULJ7QRNP4GY57HE7OO7VMRWMPN/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGWWGQULJ7QRNP4GY57HE7OO7VMRWMPN/ Mailing List, Release Notes</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/ Mailing List, Release Notes</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFZWDF43D73C5KWFF26GIIVZJKEFPS3K/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFZWDF43D73C5KWFF26GIIVZJKEFPS3K/ Mailing List, Third Party Advisory</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-6">
|
|
<td
|
|
data-testid="vuln-change-history-6-action">Changed</td>
|
|
<td
|
|
data-testid="vuln-change-history-6-type">Reference Type</td>
|
|
<td data-testid="vuln-change-history-6-old">
|
|
|
|
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRSEIYMPWLVPGTC34N2Q3WAUHGGOWSWP/ No Types Assigned</pre>
|
|
<br/>
|
|
|
|
<br/>
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-6-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRSEIYMPWLVPGTC34N2Q3WAUHGGOWSWP/ Mailing List, Third Party Advisory</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-7">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-7">4/21/2023 11:15:11 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-7">
|
|
<td
|
|
data-testid="vuln-change-history-7-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-7-type">Reference</td>
|
|
<td data-testid="vuln-change-history-7-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-7-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDNGTGQAUZJ6YQDI2AVGYIFFPUMMZLKS/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-7">
|
|
<td
|
|
data-testid="vuln-change-history-7-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-7-type">Reference</td>
|
|
<td data-testid="vuln-change-history-7-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-7-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFZWDF43D73C5KWFF26GIIVZJKEFPS3K/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
<tr data-testid="vuln-change-history-7">
|
|
<td
|
|
data-testid="vuln-change-history-7-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-7-type">Reference</td>
|
|
<td data-testid="vuln-change-history-7-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-7-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRSEIYMPWLVPGTC34N2Q3WAUHGGOWSWP/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-8">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-8">4/21/2023 12:15:43 AM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-8">
|
|
<td
|
|
data-testid="vuln-change-history-8-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-8-type">Reference</td>
|
|
<td data-testid="vuln-change-history-8-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-8-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-9">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-9">4/20/2023 11:15:07 PM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-9">
|
|
<td
|
|
data-testid="vuln-change-history-9-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-9-type">Reference</td>
|
|
<td data-testid="vuln-change-history-9-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-9-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-10">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-10">4/20/2023 3:15:07 AM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-10">
|
|
<td
|
|
data-testid="vuln-change-history-10-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-10-type">Reference</td>
|
|
<td data-testid="vuln-change-history-10-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-10-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
<div class="vuln-change-history-container"
|
|
style="display:none">
|
|
|
|
<h4>
|
|
<strong><span
|
|
data-testid="vuln-change-history-type-11">CVE Modified by Red Hat, Inc.</span> <span
|
|
data-testid="vuln-change-history-date-11">4/15/2023 12:16:08 AM</span></strong>
|
|
</h4>
|
|
|
|
|
|
<table
|
|
class="table table-striped table-condensed table-bordered detail-table"
|
|
data-testid="vuln-change-history-table">
|
|
<thead>
|
|
<tr>
|
|
<th>Action</th>
|
|
<th>Type</th>
|
|
<th>Old Value</th>
|
|
<th>New Value</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr data-testid="vuln-change-history-11">
|
|
<td
|
|
data-testid="vuln-change-history-11-action">Added</td>
|
|
<td
|
|
data-testid="vuln-change-history-11-type">Reference</td>
|
|
<td data-testid="vuln-change-history-11-old">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
<td data-testid="vuln-change-history-11-new">
|
|
|
|
<pre style="word-break: break-all !important">https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGWWGQULJ7QRNP4GY57HE7OO7VMRWMPN/ [No Types Assigned]</pre>
|
|
<br/>
|
|
|
|
<br />
|
|
|
|
|
|
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
|
|
|
|
|
|
</div>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
</div>
|
|
|
|
|
|
<div class="col-lg-3 col-md-5 col-sm-12">
|
|
|
|
<div class="bs-callout bs-callout-info">
|
|
<h4>Quick Info</h4>
|
|
<strong>CVE Dictionary Entry:</strong><br/> <a
|
|
target="_blank" rel="noopener noreferrer" data-testid="vuln-cve-dictionary-entry"
|
|
href="https://cve.org/CVERecord?id=CVE-2023-2004">CVE-2023-2004</a><br/> <strong>NVD
|
|
Published Date:</strong><br/> <span
|
|
data-testid="vuln-published-on">04/14/2023</span><br/> <strong>NVD
|
|
Last Modified:</strong><br/> <span
|
|
data-testid="vuln-last-modified-on">11/06/2023</span><br/> <strong>
|
|
Source:</strong><br/> <span
|
|
data-testid="vuln-current-description-source">Red Hat, Inc.</span><br/>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
|
|
</div>
|
|
<!-- Hidden input for padding -->
|
|
<input type="hidden" value="dody2HaA9ur6nX4QIrqMhPS2lGeFr3yMxqVBGEdT68iNIRWdp2MmBU7MoVHCZW7E6Mnlmx6j31di9DuHNgKo9Do7cjGatVzP43K80zxef0vramr7DVbipxCArmdC4hSQNfv9XWlDic9Z25sJYh2WC7wxSxAe6RtLZfr4LA5gL727N7U1teo2jXyhQnUTyBGgISgemgn9BlCDr6g5AP21baYiZYa4vdSc4GoK2ZAbGu9DYV2now1Y6e4OzcMkWQ9AcFOAfBzSBWo6463jH4kL7yuvue7c6h7xcIRh3MXXKanxkNQwOZMs81Vi5W21CftRg92OKJ3cBoxPSeYhJzMj8JXUuIaS7EXrYV8aDlJTR5uoa4mm2X96KwSZP5BsVnzeUudo1AgF421smTU4pZQ9b6ikGawoZgkA3FvuK6d9mRbWOlSGNJz9xjv9GplU5k7vho2p1LCOJddR6mxaUsqkbHT8G4dDNSGwih0EEfMvcr9hHNLWk5SoVvLPT0Nb3Ve21q7jOiDuVuxDpVpdkdIPEqjCNTngRu0ISimdZZxkUj4QTcq2XsPKBKhjSlsmqHhdxqiVNB1uZkg959a0KezVC1cJy7tkz2UCQgPwGFJVWHDtG6" id="padding" name="padding"/>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</main>
|
|
<footer id="footer" role="contentinfo">
|
|
<div class="container">
|
|
|
|
<div class="row">
|
|
<div class="col-sm-12">
|
|
<ul class="social-list pull-right">
|
|
<li class="field-item service-twitter list-horiz"><a
|
|
href="https://twitter.com/NISTCyber" target="_blank" rel="noopener noreferrer"
|
|
class="social-btn social-btn--large extlink ext"> <i
|
|
class="fa fa-twitter fa-fw"><span class="element-invisible">twitter</span></i><span
|
|
class="ext"><span class="element-invisible"> (link
|
|
is external)</span></span>
|
|
</a></li>
|
|
<li class="field-item service-facebook list-horiz"><a
|
|
href="https://www.facebook.com/NIST" target="_blank" rel="noopener noreferrer"
|
|
class="social-btn social-btn--large extlink ext"> <i
|
|
class="fa fa-facebook fa-fw"><span class="element-invisible">facebook</span></i><span
|
|
class="ext"><span class="element-invisible"> (link
|
|
is external)</span></span></a></li>
|
|
<li class="field-item service-linkedin list-horiz"><a
|
|
href="https://www.linkedin.com/company/nist" target="_blank" rel="noopener noreferrer"
|
|
class="social-btn social-btn--large extlink ext"> <i
|
|
class="fa fa-linkedin fa-fw"><span class="element-invisible">linkedin</span></i><span
|
|
class="ext"><span class="element-invisible"> (link
|
|
is external)</span></span></a></li>
|
|
<li class="field-item service-youtube list-horiz"><a
|
|
href="https://www.youtube.com/user/USNISTGOV" target="_blank" rel="noopener noreferrer"
|
|
class="social-btn social-btn--large extlink ext"> <i
|
|
class="fa fa-youtube fa-fw"><span class="element-invisible">youtube</span></i><span
|
|
class="ext"><span class="element-invisible"> (link
|
|
is external)</span></span></a></li>
|
|
<li class="field-item service-rss list-horiz"><a
|
|
href="https://www.nist.gov/news-events/nist-rss-feeds"
|
|
target="_blank" rel="noopener noreferrer" class="social-btn social-btn--large extlink">
|
|
<i class="fa fa-rss fa-fw"><span class="element-invisible">rss</span></i>
|
|
</a></li>
|
|
<li class="field-item service-govdelivery list-horiz last"><a
|
|
href="https://public.govdelivery.com/accounts/USNIST/subscriber/new?qsp=USNIST_3"
|
|
target="_blank" rel="noopener noreferrer" class="social-btn social-btn--large extlink ext">
|
|
<i class="fa fa-envelope fa-fw"><span
|
|
class="element-invisible">govdelivery</span></i><span class="ext"><span
|
|
class="element-invisible"> (link is external)</span></span>
|
|
</a></li>
|
|
</ul>
|
|
<span class="hidden-xs"> <a
|
|
title="National Institute of Standards and Technology" rel="home"
|
|
class="footer-nist-logo"> <img
|
|
src="/site-media/images/nist/nist-logo.png"
|
|
alt="National Institute of Standards and Technology logo" />
|
|
</a>
|
|
</span>
|
|
</div>
|
|
</div>
|
|
<div class="row hidden-sm hidden-md hidden-lg">
|
|
<div class="col-sm-12">
|
|
<a href="https://www.nist.gov"
|
|
title="National Institute of Standards and Technology" rel="home"
|
|
target="_blank" rel="noopener noreferrer" class="footer-nist-logo"> <img
|
|
src="/site-media/images/nist/nist-logo.png"
|
|
alt="National Institute of Standards and Technology logo" />
|
|
</a>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="row footer-contact-container">
|
|
<div class="col-sm-6">
|
|
<strong>HEADQUARTERS</strong>
|
|
<br>
|
|
100 Bureau Drive
|
|
<br>
|
|
Gaithersburg, MD 20899
|
|
<br>
|
|
<a href="tel:301-975-2000">(301) 975-2000</a>
|
|
<br>
|
|
<br>
|
|
<a href="mailto:nvd@nist.gov">Webmaster</a> | <a
|
|
href="https://www.nist.gov/about-nist/contact-us">Contact Us</a>
|
|
| <a href="https://www.nist.gov/about-nist/visit"
|
|
style="display: inline-block;">Our Other Offices</a>
|
|
</div>
|
|
<div class="col-sm-6">
|
|
<div class="pull-right"
|
|
style="text-align:right">
|
|
<strong>Incident Response Assistance and Non-NVD Related<br>Technical Cyber Security Questions:</strong>
|
|
<br>
|
|
US-CERT Security Operations Center
|
|
<br> Email: <a href="mailto:soc@us-cert.gov">soc@us-cert.gov</a>
|
|
<br> Phone: 1-888-282-0870
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="row">
|
|
<nav title="Footer Navigation" role="navigation"
|
|
class="row footer-bottom-links-container">
|
|
<!-- https://github.com/usnistgov/nist-header-footer/blob/nist-pages/boilerplate-footer.html -->
|
|
<p>
|
|
<a href="https://www.nist.gov/oism/site-privacy">Site Privacy</a>
|
|
|
|
|
<a href="https://www.nist.gov/oism/accessibility">Accessibility</a>
|
|
|
|
|
<a href="https://www.nist.gov/privacy">Privacy Program</a>
|
|
|
|
|
<a href="https://www.nist.gov/oism/copyrights">Copyrights</a>
|
|
|
|
|
<a href="https://www.commerce.gov/vulnerability-disclosure-policy">Vulnerability Disclosure</a>
|
|
|
|
|
<a href="https://www.nist.gov/no-fear-act-policy">No Fear Act Policy</a>
|
|
|
|
|
<a href="https://www.nist.gov/foia">FOIA</a>
|
|
|
|
|
<a href="https://www.nist.gov/environmental-policy-statement">Environmental Policy</a>
|
|
|
|
|
<a href="https://www.nist.gov/summary-report-scientific-integrity">Scientific Integrity</a>
|
|
|
|
|
<a href="https://www.nist.gov/nist-information-quality-standards">Information Quality Standards</a>
|
|
|
|
|
<a href="https://www.commerce.gov/">Commerce.gov</a>
|
|
|
|
|
<a href="https://www.science.gov/">Science.gov</a>
|
|
|
|
|
<a href="https://www.usa.gov/">USA.gov</a>
|
|
</p>
|
|
</nav>
|
|
</div>
|
|
</div>
|
|
</footer>
|
|
</body>
|
|
</html>
|
|
|
|
|