Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7a916f5c by Salvatore Bonaccorso at 2026-07-25T07:58:41+02:00
Associate some older Cloudflare Quiche issues with itp'ed entry

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -29782,7 +29782,7 @@ CVE-2026-12238 (The WP Go Maps \u2013 Most Popular Map 
Plugin plugin for WordPre
 CVE-2026-12104 (OS command injection in the environment and tunnel 
configuration funct ...)
        NOT-FOR-US: SIMA GmbH Bondix
 CVE-2026-11941 (Cloudflare Quiche was affected by 2 use-after-free 
vulnerabilities in  ...)
-       NOT-FOR-US: Cloudflare Quiche
+       - quiche <itp> (bug #841848)
 CVE-2026-11576 (The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo 
refacto ...)
        NOT-FOR-US: Eclipse
 CVE-2025-71326 (AVAST Antivirus 25.11 contains an unquoted service path 
vulnerability  ...)
@@ -332785,7 +332785,7 @@ CVE-2024-21330 (Open Management Infrastructure (OMI) 
Elevation of Privilege Vuln
 CVE-2024-20671 (Microsoft Defender Security Feature Bypass Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2024-1765 (Cloudflare Quiche (through version 0.19.1/0.20.0) was affected 
by an u ...)
-       NOT-FOR-US: Cloudflare quiche
+       - quiche <itp> (bug #841848)
 CVE-2024-1618 (A search path or unquoted item vulnerability in Faronics Deep 
Freeze S ...)
        NOT-FOR-US: Faronics Deep Freeze Server Standard
 CVE-2024-1529 (Vulnerability in CMS Made Simple 2.2.14, which does not 
sufficiently e ...)
@@ -332795,7 +332795,7 @@ CVE-2024-1528 (CMS Made Simple version 2.2.14, does 
not sufficiently encode user
 CVE-2024-1527 (Unrestricted file upload vulnerability in CMS Made Simple, 
affecting v ...)
        NOT-FOR-US: CMS Made Simple
 CVE-2024-1410 (Cloudflare quiche was discovered to be vulnerable to unbounded 
storage ...)
-       NOT-FOR-US: Cloudflare quiche
+       - quiche <itp> (bug #841848)
 CVE-2024-1328 (The Newsletter2Go plugin for WordPress is vulnerable to Stored 
Cross-S ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-1304 (Cross-site scripting vulnerability in Badger Meter Monitool 
that affec ...)
@@ -352685,7 +352685,7 @@ CVE-2023-6593 (Client side permission bypass in 
Devolutions Remote Desktop Manag
 CVE-2023-6547 (Mattermost fails to validate team membership when a user 
attempts to a ...)
        - mattermost-server <itp> (bug #823556)
 CVE-2023-6193 (quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable 
to unb ...)
-       NOT-FOR-US: Cloudflare quiche
+       - quiche <itp> (bug #841848)
 CVE-2023-50495 (NCurse v6.4-20230418 was discovered to contain a segmentation 
fault vi ...)
        - ncurses 6.4+20230625-1
        [bookworm] - ncurses <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to