Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
493ca5c9 by Moritz Muehlenhoff at 2025-09-04T23:03:28+02:00
bookworm/trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -697,7 +697,11 @@ CVE-2025-9919 (A vulnerability was identified in 
1000projects Beauty Parlour Man
        NOT-FOR-US: 1000projects Beauty Parlour Management System
 CVE-2025-9901 (A flaw was found in libsoup\u2019s caching mechanism, 
SoupCache, where ...)
        - libsoup3 <unfixed>
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
+       [bookworm] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <unfixed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
+       [bookworm] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/453
 CVE-2025-9824 (ImpactThe attacker can validate if a user exists by checking 
the time  ...)
        NOT-FOR-US: Mautic
@@ -967,9 +971,10 @@ CVE-2025-9832 (A security vulnerability has been detected 
in SourceCodester Food
 CVE-2025-9831 (A weakness has been identified in PHPGurukul Beauty Parlour 
Management ...)
        NOT-FOR-US: PHPGurukul
 CVE-2025-9817 (SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial 
of servi ...)
-       - wireshark 4.4.9-1
+       - wireshark 4.4.9-1 (unimportant)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2025-03.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/issues/20642
+       NOTE: Crash in CLI tool, no security impact
 CVE-2025-9785 (PaperCut Print Deploy is an optional component that integrates 
with Pa ...)
        NOT-FOR-US: PaperCut
 CVE-2025-9378 (The Vayu Blocks \u2013 Website Builder for the Block Editor 
plugin for ...)
@@ -1686,6 +1691,7 @@ CVE-2025-58067 (Basecamp's Google Sign-In adds Google 
sign-in to Rails applicati
        NOT-FOR-US: Basecamp's Google Sign-In
 CVE-2025-58066 (nptd-rs is a tool for synchronizing your computer's clock, 
implementin ...)
        - rust-ntpd 1.6.2-1 (bug #1112511)
+       [trixie] - rust-ntpd <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4
        NOTE: Fixed by: 
https://github.com/pendulum-project/ntpd-rs/commit/da37cf167736cbd4d7804b1ed7ceb572468298e0
 (v1.6.2)
 CVE-2025-57822 (Next.js is a React framework for building full-stack web 
applications. ...)
@@ -2040,6 +2046,8 @@ CVE-2025-58061 (OpenEBS Local PV RawFile allows dynamic 
deployment of Stateful P
        NOT-FOR-US: OpenEBS
 CVE-2025-58058 (xz is a pure golang package for reading and writing 
xz-compressed file ...)
        - golang-github-ulikunitz-xz 0.5.15-1 (bug #1112508)
+       [trixie] - golang-github-ulikunitz-xz <no-dsa> (Minor issue)
+       [bookworm] - golang-github-ulikunitz-xz <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ulikunitz/xz/security/advisories/GHSA-jc7w-c686-c4v9
        NOTE: 
https://github.com/ulikunitz/xz/commit/88ddf1d0d98d688db65de034f48960b2760d2ae2 
(v0.5.14-rc.1)
 CVE-2025-54777 (Uncaught exception issue exists in Multiple products in bizhub 
series. ...)
@@ -13827,6 +13835,8 @@ CVE-2025-53770 (Deserialization of untrusted data in 
on-premises Microsoft Share
        NOT-FOR-US: Microsoft
 CVE-2025-XXXX [exposes .zip passwords while (un)archiving]
        - krusader <unfixed> (bug #1108942)
+       [trixie] - krusader <no-dsa> (Minor issue, revisit when fixed upstream)
+       [bookworm] - krusader <no-dsa> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - krusader <postponed> (Minor issue)
 CVE-2025-7853 (A vulnerability was found in Tenda FH451 1.0.0.9. It has been 
rated as ...)
        NOT-FOR-US: Tenda
@@ -14228,10 +14238,8 @@ CVE-2025-54060 (WeGIA is an open source web manager 
with a focus on the Portugue
 CVE-2025-54058 (WeGIA is an open source web manager with a focus on the 
Portuguese lan ...)
        NOT-FOR-US: WeGIA
 CVE-2025-53964 (GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method 
that allows ...)
-       - goldendict <unfixed>
-       - goldendict-ng <undetermined>
-       NOTE: https://github.com/tigr78/CVE-2025-53964
-       TODO: check more on details of vulnerability
+       NOTE: Bogus report against GoldenDict
+       NOTE: 
https://github.com/xiaoyifang/goldendict-ng/issues/2442#issuecomment-3165727711
 CVE-2025-53946 (WeGIA is an open source web manager with a focus on the 
Portuguese lan ...)
        NOT-FOR-US: WeGIA
 CVE-2025-53941 (Hollo is a federated single-user microblogging software 
designed to be ...)
@@ -33941,6 +33949,7 @@ CVE-2025-23167 (A flaw in Node.js 20's HTTP parser 
allows improper termination o
        NOTE: Fixed by: 
https://github.com/nodejs/llhttp/commit/72f53095152740e176438cf7fe68742fe1cb7be8
 (v9.0.1)
 CVE-2025-23166 (The C++ method SignTraits::DeriveBits() may incorrectly call 
ThrowExce ...)
        - nodejs 20.19.2+dfsg-1 (bug #1105832)
+       [bookworm] - nodejs <postponed> (Fix along with next DSA)
        [bullseye] - nodejs <not-affected> (The vulnerable code was introduced 
later)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/may-2025-security-releases#improper-error-handling-in-async-cryptographic-operations-crashes-process-cve-2025-23166---high
        NOTE: Introduced by: 
https://github.com/nodejs/node/commit/e60841b598ed5246c8dfc24a779c6b1b732d4f87 
(v16.14.0)
@@ -41579,6 +41588,7 @@ CVE-2025-3823 (A vulnerability classified as 
problematic has been found in Sourc
        NOT-FOR-US: SourceCodester
 CVE-2025-43929 (open_actions.py in kitty before 0.41.0 does not ask for user 
confirmat ...)
        - kitty 0.41.1-1 (bug #1103691)
+       [bookworm] - kitty <no-dsa> (Minor issue)
        [bullseye] - kitty <not-affected> (vulnerable code introduced later)
        NOTE: 
https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35
 (v0.41.0)
        NOTE: PoC: https://github.com/0xBenCantCode/CVE-2025-43929
@@ -71501,6 +71511,7 @@ CVE-2024-57947 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/791a615b7ad2258c560f91852be54b0480837c93 (6.11-rc1)
 CVE-2025-0650 (A flaw was found in the Open Virtual Network (OVN). Specially 
crafted  ...)
        - ovn 25.03.0~git20250216.7c69af7-1 (bug #1093884)
+       [bookworm] - ovn <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2025/01/22/5
        NOTE: 
https://github.com/ovn-org/ovn/commit/249c52ad011cacb4c182dc64e88977ac7c61f668 
(v24.09.2)
        NOTE: 
https://github.com/ovn-org/ovn/commit/474bdfcad038e91aeaa036944b6b4be7c3e1ec15 
(v25.03.0)
@@ -72277,6 +72288,7 @@ CVE-2025-0411 (7-Zip Mark-of-the-Web Bypass 
Vulnerability. This vulnerability al
 CVE-2025-23085 (A memory leak could occur when a remote peer abruptly closes 
the socke ...)
        {DLA-4067-1}
        - nodejs 20.18.2+dfsg-1 (bug #1094134)
+       [bookworm] - nodejs <postponed> (Fix along with next DSA)
        NOTE: 
https://nodejs.org/en/blog/vulnerability/january-2025-security-releases#goaway-http2-frames-cause-memory-leak-outside-heap-cve-2025-23085---medium
        NOTE: Fixed by: 
https://github.com/nodejs/node/commit/3c7686163ed4c6ae3e5901b758b7a7d4fd5bb0c0 
(v23.6.1)
        NOTE: Fixed by: 
https://github.com/nodejs/node/commit/6cc8d58e6f97c37c228f134bd9b98246c8871fb1 
(v18.20.6)


=====================================
data/dsa-needed.txt
=====================================
@@ -57,8 +57,7 @@ pagure/oldstable (jmm)
 --
 php-laravel-framework/oldstable
 --
-python-django/oldstable
-  Chris is working on it
+python-django
 --
 ruby-rack/oldstable
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/493ca5c92354444a629a554595dec6784a17b344

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/493ca5c92354444a629a554595dec6784a17b344
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to