Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: a0a774a0 by Salvatore Bonaccorso at 2026-07-21T13:23:47+02:00 Add new batch of libssh issues - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,36 @@ +CVE-2026-15370 [Stack buffer overflow in SFTP server longname construction] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59842 [Information disclosure via short GSSAPI Curve25519 public key] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59843 [Denial of service via zero advertised channel packet size] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59844 [Denial of service via oversized SFTP read length] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59845 [Denial of service via unchecked ProxyCommand fork() failure] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59846 [Information disclosure via ProxyCommand %r username expansion] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59847 [Integrity downgrade via OpenSSL AES-GCM tag verification] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59848 [Denial of service via SFTP responses with unknown request IDs] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59849 [Denial of service via automatic certificate authentication loop] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59850 [Use-after-free via data callbacks on closed channels] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ +CVE-2026-59851 [Authentication bypass via missing GSSAPI principal check] + - libssh <unfixed> + NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ CVE-2026-8082 (The bpost-shipping-platform WordPress plugin before 3.2.3 does not pro ...) NOT-FOR-US: WordPress plugin CVE-2026-6952 (A post-authentication command injection vulnerability in the "LogServe ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0a774a0bb9f8711d082da6e888f172988ec0ab0 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0a774a0bb9f8711d082da6e888f172988ec0ab0 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
