Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f52bb31d by Salvatore Bonaccorso at 2026-07-10T08:33:42+02:00
Update status for netcff issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -110982,8 +110982,8 @@ CVE-2025-15045 (A flaw has been found in Tenda WH450
1.0.0.18. The affected elem
CVE-2025-15044 (A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted
is an u ...)
NOT-FOR-US: Tenda
CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer
Overflow Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -110992,9 +110992,10 @@ CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name
Stack-based Buffer Overflow
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when
fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1155/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by:
https://github.com/Unidata/netcdf-c/commit/b491ecd8021f510427459051ebfd7bd4cfda2371
(v4.10.1)
CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow
Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111003,9 +111004,10 @@ CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name
Heap-based Buffer Overflow R
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when
fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1154/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by:
https://github.com/Unidata/netcdf-c/commit/0b33fab5c1d7bc458bf0aead93af433e0eae5abc
(v4.10.1)
CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow
Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111014,9 +111016,10 @@ CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name
Stack-based Buffer Overflow R
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when
fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1152/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by:
https://github.com/Unidata/netcdf-c/commit/1e22866daae12203c768a38c168b8d25c65627d9
(v4.10.1)
CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code
Executio ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor isuse)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111025,9 +111028,10 @@ CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable
Integer Overflow Remote Code Ex
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when
fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1151/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by:
https://github.com/Unidata/netcdf-c/commit/b06b973e040ffede8d776ff7a94d22c68074ea98
(v4.10.1)
CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow
Remote Code ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed
upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111036,6 +111040,7 @@ CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit
Stack-based Buffer Overflow Remot
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when
fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1153/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by:
https://github.com/Unidata/netcdf-c/commit/60578c3ac26b93b1932cba414a2870096bbcdd3b
(v4.10.1)
CVE-2025-14931 (Hugging Face smolagents Remote Python Executor Deserialization
of Untr ...)
NOT-FOR-US: Hugging Face smolagents
CVE-2025-14930 (Hugging Face Transformers GLM4 Deserialization of Untrusted
Data Remot ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits