Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0eb0c0cb by Moritz Muehlenhoff at 2026-08-10T11:02:57+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -609,6 +609,7 @@ CVE-2026-71558 (Heap type confusion vulnerability in Apache 
Fory C++ deserializa
 CVE-2026-71557 (go-git is an extensible git implementation library written in 
pure Go. ...)
        - golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
        - golang-github-go-git-go-git <unfixed> (bug #1143903)
+       [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
        NOTE: https://github.com/go-git/go-git/pull/2247
        NOTE: Fixed by (merge): 
https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36
 (v6.0.0-alpha.5)
@@ -617,6 +618,7 @@ CVE-2026-71557 (go-git is an extensible git implementation 
library written in pu
 CVE-2026-71556 (go-git is an extensible git implementation library written in 
pure Go. ...)
        - golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
        - golang-github-go-git-go-git <unfixed> (bug #1143903)
+       [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
        NOTE: Fixed by: 
https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac
 (v6.0.0-alpha.5)
        NOTE: Fixed by: 
https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab
 (v5.19.2)
@@ -3726,12 +3728,14 @@ CVE-2026-69247 (cryptography is a package designed to 
expose cryptographic primi
 CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 
8.0.1, Gu ...)
        [experimental] - guzzle 8.0.1-1
        - guzzle 7.15.2-1 (bug #1143595)
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33
        NOTE: Fixed by: 
https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4
 (8.0.1)
        NOTE: Fixed by: 
https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf
 (7.15.2)
 CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 
8.0.1, Se ...)
        [experimental] - guzzle 8.0.1-1
        - guzzle 7.15.2-1 (bug #1143595)
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r
        NOTE: Fixed by: 
https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4
 (8.0.1)
        NOTE: Fixed by: 
https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf
 (7.15.2)
@@ -4144,6 +4148,7 @@ CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains 
a code injection vulner
        NOT-FOR-US: WebsiteBaker CMS
 CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
        - apache-jena <unfixed> (bug #1143599)
+       [trixie] - apache-jena <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84
 CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to 
properly a ...)
        NOT-FOR-US: Sharp and Toshiba Tec MFPs
@@ -4686,12 +4691,15 @@ CVE-2026-6453 (The CubeWP Framework plugin for 
WordPress is vulnerable to SQL In
        NOT-FOR-US: WordPress plugin
 CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve 
host-only co ...)
        - guzzle 7.15.1-1
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577
 CVE-2026-67354 (guzzlehttp/guzzle versions before 7.15.1 contain an 
information disclo ...)
        - guzzle 7.15.1-1
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8
 CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of 
service v ...)
        - guzzle 7.15.1-1
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
 CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site 
scripting vulner ...)
        NOT-FOR-US: luci-app-https-dns-proxy
@@ -4707,6 +4715,7 @@ CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine) 
allows trigger scripts
        NOT-FOR-US: ArcadeDB
 CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly 
isolate Prox ...)
        - guzzle 7.14.2-1
+       [trixie] - guzzle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting 
vulnera ...)
        - jupyterlab <unfixed>
@@ -12698,6 +12707,7 @@ CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 
and prior have a plaintext
        NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a 
vulnerability ...)
        - knot 3.5.4-1
+       [trixie] - knot <no-dsa> (Minor issue)
        [bookworm] - knot <postponed> (Minor issue)
        [bullseye] - knot <postponed> (Minor issue)
        NOTE: https://www.knot-dns.cz/2026-04-01-version-3410.html
@@ -17760,13 +17770,16 @@ CVE-2026-64620 (FreeRDP before 3.28.0 (affected 
<=3.27.1) contains a heap-based
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
 CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG 
image rea ...)
        - libcupsfilters <unfixed> (bug #1142687)
+       [trixie] - libcupsfilters <no-dsa> (Minor issue)
        [bookworm] - libcupsfilters <postponed> (Minor issue)
        [bullseye] - libcupsfilters <postponed> (Minor issue)
        - cups-filters <unfixed>
+       [trixie] - cups-filters <no-dsa> (Minor issue)
        [bookworm] - cups-filters <postponed> (Minor issue)
        [bullseye] - cups-filters <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502801
-       NOTE: 
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
 (not public)
+       NOTE: 
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
+       NOTE: 
https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
 CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of 
Service via de ...)
        - libnet-dns-perl 1.56-1 (bug #1142503)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to