Thorsten Alteholz pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d8b6f407 by Thorsten Alteholz at 2026-02-08T00:44:05+01:00
mark CVE-2026-1642 as postponed for Bullseye
- - - - -
18c911bf by Thorsten Alteholz at 2026-02-08T01:02:06+01:00
mark CVE-2026-2100 as not-affected for Bullseye, vulnerable code introduced in
v0.25.6
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -240,6 +240,8 @@ CVE-2020-37079 (Wing FTP Server versions prior to 6.2.7
contain a cross-site req
NOT-FOR-US: Wing FTP Server
CVE-2026-2100 [NULL dereference via C_DeriveKey with specific NULL parameters]
- p11-kit <unfixed>
+ [bullseye] - p11-kit <not-affected> (vulnerable code introduced in
v0.25.6)
+ NOTE: Introduced by:
https://github.com/p11-glue/p11-kit/commit/d7523b1031938fdd9740757f90e903aa09f5397d
(0.25.6)
NOTE: Fixed by:
https://github.com/p11-glue/p11-kit/commit/39f3b5ed3deccc2772e21ffb7d269329e3ecb600
(0.26.2)
CVE-2026-2103 (Infor SyteLine ERP uses hard-coded static cryptographic keys to
encryp ...)
NOT-FOR-US: Infor SyteLine ERP
@@ -1042,6 +1044,7 @@ CVE-2026-20056 (A vulnerability in the Dynamic Vectoring
and Streaming (DVS) Eng
NOT-FOR-US: Cisco
CVE-2026-1642 (A vulnerability exists in NGINX OSS and NGINX Plus when
configured to ...)
- nginx <unfixed> (bug #1127053)
+ [bullseye] - nginx <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/02/05/1
NOTE: https://my.f5.com/manage/s/article/K000159824
NOTE: Fixed by:
https://github.com/nginx/nginx/commit/784fa05025cb8cd0c770f99bc79d2794b9f85b6e
(release-1.28.2)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51755976b19f274ea9dff64da3237d1c83479b67...18c911bf77b5b1166da3193b48976b3de472f5df
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51755976b19f274ea9dff64da3237d1c83479b67...18c911bf77b5b1166da3193b48976b3de472f5df
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits