Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f7bd1542 by Salvatore Bonaccorso at 2026-06-23T21:27:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2,25 +2,25 @@ CVE-2026-57062 (CMS (Cryptographic Message Syntax) parsing in
gpgsm in GnuPG thr
- gnupg2 <unfixed>
NOTE: https://blog.calif.io/p/how-to-format-a-ciphertext
CVE-2026-56815 (pwnlift before d7a9544, in a privileged deployment, contains a
symlink ...)
- TODO: check
+ NOT-FOR-US: pwnlift
CVE-2026-56784 (OpenRemote Manager before 1.24.2 contains an insecure direct
object re ...)
- TODO: check
+ NOT-FOR-US: OpenRemote Manager
CVE-2026-56762 (Hono before 4.12.12 does not validate cookie names on the
write path i ...)
- TODO: check
+ NOT-FOR-US: Hono
CVE-2026-56701 (Grav before 2.0.0-beta.2 contains an XML external entity
injection vul ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-56696 (OpenHarness /issue and /pr_comments slash commands lack
remote_invocab ...)
- TODO: check
+ NOT-FOR-US: OpenHarness
CVE-2026-56695 (OpenHarness ohmo gateway /resume and /summary slash commands
default r ...)
- TODO: check
+ NOT-FOR-US: OpenHarness
CVE-2026-56694 (NanoClaw before 2.1.0 contains a privilege escalation
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: NanoClaw
CVE-2026-56693 (NanoClaw before 2.1.17 contains a privilege escalation
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: NanoClaw
CVE-2026-56692 (NanoClaw before 2.1.17 contains a symlink following
vulnerability in f ...)
- TODO: check
+ NOT-FOR-US: NanoClaw
CVE-2026-56402 (NanoClaw before 2.1.17 contains a privilege escalation
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: NanoClaw
CVE-2026-56379 (ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command
injection ...)
TODO: check
CVE-2026-56376 (ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap
use-after-fr ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f7bd15420912d5ae2b45b9255879b1591a80f966
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f7bd15420912d5ae2b45b9255879b1591a80f966
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits