Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1879c6d3 by Salvatore Bonaccorso at 2026-07-20T22:40:40+02:00
Add new set of vips issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -227,9 +227,15 @@ CVE-2026-39878 (Chamilo LMS versions 1.11.38 and earlier 
contain a stored cross-
 CVE-2026-39385 (Frappe LMS is an open source learning management system. In 
version 2. ...)
        NOT-FOR-US: Frappe LMS
 CVE-2026-35591 (libvips is a fast image processing library with low memory 
needs. The  ...)
-       TODO: check
+       - vips 8.18.2-1
+       NOTE: 
https://github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76
+       NOTE: https://github.com/libvips/libvips/pull/4973
+       NOTE: Fixed by: 
https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe
 (v8.18.2)
 CVE-2026-35590 (libvips is a fast image processing library with low memory 
needs. The  ...)
-       TODO: check
+       - vips 8.18.2-1
+       NOTE: 
https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm
+       NOTE: https://github.com/libvips/libvips/pull/4972
+       NOTE: Fixed by: 
https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f
 (v8.18.2)
 CVE-2026-35217 (NanoMQ contains a protocol-semantics flaw in its MQTT v5 
`SUBSCRIBE` h ...)
        TODO: check
 CVE-2026-35198 (HeyForm is an open-source form builder. Prior to version 
3.0.0-rc.7, a ...)
@@ -239,9 +245,15 @@ CVE-2026-35048 (The Piwigo installer in versions 16.3.0 
and earlier accepts POST
 CVE-2026-34239 (Chamilo version 1.11.40 and earlier are vulnerable to 
authenticated re ...)
        TODO: check
 CVE-2026-33328 (libvips is a fast image processing library with low memory 
needs. On 3 ...)
-       TODO: check
+       - vips 8.18.1-1
+       NOTE: 
https://github.com/libvips/libvips/security/advisories/GHSA-r98w-4fp7-m9c7
+       NOTE: https://github.com/libvips/libvips/pull/4935
+       NOTE: Fixed by: 
https://github.com/libvips/libvips/commit/9b633e45abfcf1fc4c84847007c81805193c0969
 (v8.18.1)
 CVE-2026-33327 (libvips is a fast image processing library with low memory 
needs. The  ...)
-       TODO: check
+       - vips 8.18.1-1
+       NOTE: 
https://github.com/libvips/libvips/security/advisories/GHSA-2fcj-gj27-279x
+       NOTE: https://github.com/libvips/libvips/pull/4934
+       NOTE: Fixed by; 
https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9
 (v8.18.1)
 CVE-2026-32825 (dataCycle is a data management system for centrally storing, 
managing, ...)
        TODO: check
 CVE-2026-32824 (dataCycle is a data management system for centrally storing, 
managing, ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1879c6d3874741a5b5836ba67d1f6735a8d0afce

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1879c6d3874741a5b5836ba67d1f6735a8d0afce
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to