Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f52bb31d by Salvatore Bonaccorso at 2026-07-10T08:33:42+02:00
Update status for netcff issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -110982,8 +110982,8 @@ CVE-2025-15045 (A flaw has been found in Tenda WH450 
1.0.0.18. The affected elem
 CVE-2025-15044 (A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted 
is an u ...)
        NOT-FOR-US: Tenda
 CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer 
Overflow Remote ...)
-       - netcdf <unfixed> (bug #1123960)
-       [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+       - netcdf 1:4.10.1-1 (bug #1123960)
+       [trixie] - netcdf <no-dsa> (Minor issue)
        [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        - netcdf-parallel <unfixed> (bug #1123961)
@@ -110992,9 +110992,10 @@ CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name 
Stack-based Buffer Overflow
        [bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when 
fixed upstream)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1155/
        NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+       NOTE: Fixed by: 
https://github.com/Unidata/netcdf-c/commit/b491ecd8021f510427459051ebfd7bd4cfda2371
 (v4.10.1)
 CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow 
Remote  ...)
-       - netcdf <unfixed> (bug #1123960)
-       [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+       - netcdf 1:4.10.1-1 (bug #1123960)
+       [trixie] - netcdf <no-dsa> (Minor issue)
        [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        - netcdf-parallel <unfixed> (bug #1123961)
@@ -111003,9 +111004,10 @@ CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name 
Heap-based Buffer Overflow R
        [bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when 
fixed upstream)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1154/
        NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+       NOTE: Fixed by: 
https://github.com/Unidata/netcdf-c/commit/0b33fab5c1d7bc458bf0aead93af433e0eae5abc
 (v4.10.1)
 CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow 
Remote  ...)
-       - netcdf <unfixed> (bug #1123960)
-       [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+       - netcdf 1:4.10.1-1 (bug #1123960)
+       [trixie] - netcdf <no-dsa> (Minor issue)
        [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        - netcdf-parallel <unfixed> (bug #1123961)
@@ -111014,9 +111016,10 @@ CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name 
Stack-based Buffer Overflow R
        [bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when 
fixed upstream)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1152/
        NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+       NOTE: Fixed by: 
https://github.com/Unidata/netcdf-c/commit/1e22866daae12203c768a38c168b8d25c65627d9
 (v4.10.1)
 CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code 
Executio ...)
-       - netcdf <unfixed> (bug #1123960)
-       [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+       - netcdf 1:4.10.1-1 (bug #1123960)
+       [trixie] - netcdf <no-dsa> (Minor isuse)
        [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        - netcdf-parallel <unfixed> (bug #1123961)
@@ -111025,9 +111028,10 @@ CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable 
Integer Overflow Remote Code Ex
        [bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when 
fixed upstream)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1151/
        NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+       NOTE: Fixed by: 
https://github.com/Unidata/netcdf-c/commit/b06b973e040ffede8d776ff7a94d22c68074ea98
 (v4.10.1)
 CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow 
Remote Code ...)
-       - netcdf <unfixed> (bug #1123960)
-       [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+       - netcdf 1:4.10.1-1 (bug #1123960)
+       [trixie] - netcdf <no-dsa> (Minor issue)
        [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed 
upstream)
        - netcdf-parallel <unfixed> (bug #1123961)
@@ -111036,6 +111040,7 @@ CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit 
Stack-based Buffer Overflow Remot
        [bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when 
fixed upstream)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1153/
        NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+       NOTE: Fixed by: 
https://github.com/Unidata/netcdf-c/commit/60578c3ac26b93b1932cba414a2870096bbcdd3b
 (v4.10.1)
 CVE-2025-14931 (Hugging Face smolagents Remote Python Executor Deserialization 
of Untr ...)
        NOT-FOR-US: Hugging Face smolagents
 CVE-2025-14930 (Hugging Face Transformers GLM4 Deserialization of Untrusted 
Data Remot ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to