Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e525ffcd by Sylvain Beucler at 2026-07-18T08:56:56+02:00
CVE-2026-45793/composer: fix fixed version

0.9.1+dfsg-1 is not an existing composer version.

This is below all composer versions and masks the issue for <bookworm
in the tracker.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45204,7 +45204,7 @@ CVE-2026-6637 (Stack buffer overflow in PostgreSQL 
module "refint" allows an unp
        - postgresql-13 <removed>
        NOTE: 
https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
 CVE-2026-45793 (Composer is a dependency Manager for the PHP language. Prior 
to 1.10.2 ...)
-       - composer 0.9.1+dfsg-1
+       - composer 2.10.0-1
        [trixie] - composer 2.8.8-1+deb13u3
        [bookworm] - composer 2.5.5-1+deb12u5
        NOTE: 
https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e525ffcdbf606011355667877c370920c2ad114a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e525ffcdbf606011355667877c370920c2ad114a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to