Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: aff21e54 by Salvatore Bonaccorso at 2026-07-13T22:20:32+02:00 Add two new proftpd-dfsg issues (pending CVE assignments) - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,11 @@ +CVE-2026-XXXX [Authenticated SFTP sessions can overflow the SFTP packet buffer] + - proftpd-dfsg 1.3.9c~dfsg-1 + NOTE: https://github.com/proftpd/proftpd/issues/2190 + NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c) +CVE-2026-XXXX [SCP signed-size integer overflow; heap over-read] + - proftpd-dfsg 1.3.9c~dfsg-1 + NOTE: https://github.com/proftpd/proftpd/pull/2201 + NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6 (v1.3.9c) CVE-2026-9824 (Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10. ...) - mattermost-server <itp> (bug #823556) CVE-2026-9820 (Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sani ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aff21e54d444493a4510984f251d622d15b29d07 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aff21e54d444493a4510984f251d622d15b29d07 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
