Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2a19c2c9 by Moritz Muehlenhoff at 2026-05-07T23:36:45+02:00
new postorius issues
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -66,7 +66,9 @@ CVE-2026-5786 (An Improper Access Control vulnerability in
Ivanti EPMM before ve
CVE-2026-5784 (Improper neutralization of input during web page generation
('cross-si ...)
NOT-FOR-US: DivvyDrive
CVE-2026-44742 (Postorius through 1.3.13 does not escape HTML in the message
subject w ...)
- TODO: check
+ - postorius <unfixed>
+ NOTE:
https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b
+ NOTE: https://gitlab.com/mailman/postorius/-/merge_requests/972
CVE-2026-44407 (A remote denial-of-service vulnerability exists in the ZTE
Cloud PC cl ...)
NOT-FOR-US: ZTE
CVE-2026-44406 (ZTE Cloud PC clientuSmartView contains a DLL hijacking
vulnerability; ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -88,6 +88,8 @@ pdfminer (carnil)
--
php-laravel-framework/oldstable
--
+postorius (jmm)
+--
pyjwt (jmm)
Jochen Sprickerhof posted debdiffs for review
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits