Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8185b132 by Sylvain Beucler at 2026-07-15T20:58:08+02:00
CVE-2026-59203/pillow: bookworm,bullseye not-affected + introductory commit

- - - - -
96ff55ff by Sylvain Beucler at 2026-07-15T21:01:20+02:00
CVE-2026-49981/php-twig: replicate bookworm triage from CVE-2026-46636

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -155,9 +155,12 @@ CVE-2026-59204 (Pillow is a Python imaging library. From 
8.2.0 through 12.2.0, s
 CVE-2026-59203 (Pillow is a Python imaging library. From 12.0.0 through 
12.2.0, Pillow ...)
        - pillow <unfixed>
        [trixie] - pillow <not-affected> (Vulnerable code not present)
+       [bookworm] - pillow <not-affected> (BeginBinary support introduced in 
v12.0.0)
+       [bullseye] - pillow <not-affected> (BeginBinary support introduced in 
v12.0.0)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798
        NOTE: https://github.com/python-pillow/Pillow/pull/9708
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
 (12.3.0)
+       NOTE: Introduced by: 
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
 (12.0.0)
 CVE-2026-59200 (Pillow is a Python imaging library. From 5.1.0 until 12.3.0, 
PdfParser ...)
        - pillow <unfixed>
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
@@ -1236,6 +1239,7 @@ CVE-2026-4017 (Buffer Overflow in the entry handler of 
the TraceEvent() system c
 CVE-2026-49981 (Twig is a template language for PHP. Prior to 3.27.0, the 
per-template ...)
        - php-twig 3.27.0-1
        [trixie] - php-twig 3.27.0-0+deb13u1
+       [bookworm] - php-twig <ignored> (Minor issue, too intrusive to backport)
        NOTE: 
https://github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hq
        NOTE: 
https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4 
(v3.27.0)
        NOTE: Duplicate of CVE-2026-46636



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37b8b4c376bc5858cccca75b0ddb9cd55a780f7d...96ff55ff9cca090e536d65595331ea2e02f5f1cf

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37b8b4c376bc5858cccca75b0ddb9cd55a780f7d...96ff55ff9cca090e536d65595331ea2e02f5f1cf
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to