Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b264a3e6 by Salvatore Bonaccorso at 2026-08-08T07:30:50+02:00
Track fixed verison for mina2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -53132,7 +53132,7 @@ CVE-2026-47325 (ProjectsAndPrograms
school-management-systemuses predictable cre
CVE-2026-47324 (ProjectsAndPrograms school-management-system is vulnerable to
Stored C ...)
NOT-FOR-US: ProjectsAndPrograms school-management-system
CVE-2026-47321
- - mina2 <unfixed> (bug #1139162)
+ - mina2 2.2.9-1 (bug #1139162)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue)
@@ -53141,7 +53141,7 @@ CVE-2026-47321
[bullseye] - mina <postponed> (Minor issue)
NOTE: https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
CVE-2026-47065 (ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers
Filter By ...)
- - mina2 <unfixed> (bug #1139162)
+ - mina2 2.2.9-1 (bug #1139162)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue)
@@ -78984,7 +78984,7 @@ CVE-2026-42410 (Improper Neutralization of Input During
Web Page Generation ('Cr
CVE-2026-42379 (Insertion of Sensitive Information Into Sent Data
vulnerability in WPD ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-41635 (Apache MINA's AbstractIoBuffer.resolveClass() contains two
branches, o ...)
- - mina2 <unfixed> (bug #1135167)
+ - mina2 2.2.9-1 (bug #1135167)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <ignored> (Minor issue)
[bullseye] - mina2 <ignored> (Minor issue)
@@ -79005,7 +79005,7 @@ CVE-2026-41463 (ProjeQtor versions 7.0 through 12.4.3
contain a ZipSlip path tra
CVE-2026-41462 (ProjeQtor versions 7.0 through 12.4.3 contain an
unauthenticated SQL i ...)
NOT-FOR-US: ProjeQtor
CVE-2026-41409 (The fix for CVE-2024-52046 in Apache MINA
AbstractIoBuffer.getObject() ...)
- - mina2 <unfixed> (bug #1135347)
+ - mina2 2.2.9-1 (bug #1135347)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046
not applied)
[bullseye] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046
not applied)
@@ -261611,7 +261611,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in
Apache MINA uses Java\u2019s n
- mina <removed>
[bookworm] - mina <no-dsa> (Minor issue)
[bullseye] - mina <postponed> (Minor issue; need specific conditions)
- - mina2 2.2.1-4 (bug #1091530)
+ - mina2 2.2.9-1 (bug #1091530)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits