Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4011c474 by Salvatore Bonaccorso at 2026-07-27T21:10:55+02:00
Adjust upstream tag in CVE-2026-55202 commit
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32380,7 +32380,7 @@ CVE-2026-55202 (Tinyproxy through 1.11.3, fixed in
commit 09312a1, fails to prop
[bullseye] - tinyproxy <not-affected> (Host header based stathost
matching introduced in 1.11.0; 1.10.0 only matches the port-stripped host from
the request URL)
NOTE: https://github.com/tinyproxy/tinyproxy/pull/606
NOTE: Fixed by:
https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce
- NOTE: Introduced by
https://github.com/tinyproxy/tinyproxy/commit/734ba1d9702cd7d420c624c3574bec1470ebf590
(1.11.0)
+ NOTE: Introduced with:
https://github.com/tinyproxy/tinyproxy/commit/734ba1d9702cd7d420c624c3574bec1470ebf590
(1.11.0-rc1)
CVE-2026-55201 (Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a
path trave ...)
NOT-FOR-US: Evil-WinRM
CVE-2026-55200 (libssh2 through 1.11.1, fixed in commit 7acf3df contains an
out-of-bou ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4011c474b68170f85385491c4383658627d4aa34
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4011c474b68170f85385491c4383658627d4aa34
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits