Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cbddeb20 by Utkarsh Gupta at 2026-07-11T02:26:07+05:30
lts: anki not-affected in bullseye (CVE-2026-59153)
- - - - -
dc444071 by Utkarsh Gupta at 2026-07-11T02:26:08+05:30
lts: anki not-affected in bullseye (CVE-2026-58266)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1949,6 +1949,7 @@ CVE-2026-59704 (Cap's GET /api/video/ai endpoint fails to
validate user ownershi
NOT-FOR-US: CapSoftware Cap
CVE-2026-59153 (Anki is a program for creating and reviewing flashcards. Prior
to 25.0 ...)
- anki <removed>
+ [bullseye] - anki <not-affected> (Vulnerable local-server API absent in
2.1.15; no HTTP API/origin handling in aqt/mediasrv.py)
NOTE:
https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g
NOTE: Fixed by:
https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219
(25.09.3)
CVE-2026-58583 (FluxInk (formerly Sunia SPB Peripheral) Color Management
Driver (TcnPe ...)
@@ -1979,6 +1980,7 @@ CVE-2026-58384 (A flaw was found in GIMP's PSD parser. An
integer overflow in re
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e21779a851fcd95d2af29294bee4071a67a7
(GIMP_3_2_4)
CVE-2026-58266 (Anki is a program for creating and reviewing flashcards. Prior
to 25.0 ...)
- anki <removed>
+ [bullseye] - anki <not-affected> (2.1.15 lacks the internal localhost
API/getImageForOcclusion and CSP handling in aqt/mediasrv.py)
NOTE:
https://github.com/ankitects/anki/security/advisories/GHSA-cw6h-ffmh-x6vh
NOTE: Fixed by:
https://github.com/ankitects/anki/commit/b2b68d829e853da51b5de8aad6c13b53e90bc20d
(25.09.4)
CVE-2026-57895 (Incorrect default permissions issue exists in Pupsman versions
prior t ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e3ea1ed7ac440fa36900ec299836538dfa05948f...dc444071a5834b04ca0581a720a23179c9b4882c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e3ea1ed7ac440fa36900ec299836538dfa05948f...dc444071a5834b04ca0581a720a23179c9b4882c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits