Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0eb0c0cb by Moritz Muehlenhoff at 2026-08-10T11:02:57+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -609,6 +609,7 @@ CVE-2026-71558 (Heap type confusion vulnerability in Apache
Fory C++ deserializa
CVE-2026-71557 (go-git is an extensible git implementation library written in
pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
- golang-github-go-git-go-git <unfixed> (bug #1143903)
+ [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
NOTE: https://github.com/go-git/go-git/pull/2247
NOTE: Fixed by (merge):
https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36
(v6.0.0-alpha.5)
@@ -617,6 +618,7 @@ CVE-2026-71557 (go-git is an extensible git implementation
library written in pu
CVE-2026-71556 (go-git is an extensible git implementation library written in
pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha.5-1 (bug #1143904)
- golang-github-go-git-go-git <unfixed> (bug #1143903)
+ [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
NOTE:
https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
NOTE: Fixed by:
https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac
(v6.0.0-alpha.5)
NOTE: Fixed by:
https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab
(v5.19.2)
@@ -3726,12 +3728,14 @@ CVE-2026-69247 (cryptography is a package designed to
expose cryptographic primi
CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and
8.0.1, Gu ...)
[experimental] - guzzle 8.0.1-1
- guzzle 7.15.2-1 (bug #1143595)
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33
NOTE: Fixed by:
https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4
(8.0.1)
NOTE: Fixed by:
https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf
(7.15.2)
CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and
8.0.1, Se ...)
[experimental] - guzzle 8.0.1-1
- guzzle 7.15.2-1 (bug #1143595)
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r
NOTE: Fixed by:
https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4
(8.0.1)
NOTE: Fixed by:
https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf
(7.15.2)
@@ -4144,6 +4148,7 @@ CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains
a code injection vulner
NOT-FOR-US: WebsiteBaker CMS
CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
- apache-jena <unfixed> (bug #1143599)
+ [trixie] - apache-jena <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84
CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to
properly a ...)
NOT-FOR-US: Sharp and Toshiba Tec MFPs
@@ -4686,12 +4691,15 @@ CVE-2026-6453 (The CubeWP Framework plugin for
WordPress is vulnerable to SQL In
NOT-FOR-US: WordPress plugin
CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve
host-only co ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577
CVE-2026-67354 (guzzlehttp/guzzle versions before 7.15.1 contain an
information disclo ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8
CVE-2026-67353 (guzzlehttp/guzzle versions before 7.15.1 contain a denial of
service v ...)
- guzzle 7.15.1-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79
CVE-2026-67352 (luci-app-https-dns-proxy contains a stored cross-site
scripting vulner ...)
NOT-FOR-US: luci-app-https-dns-proxy
@@ -4707,6 +4715,7 @@ CVE-2026-67340 (ArcadeDB before 26.7.2 (arcadedb-engine)
allows trigger scripts
NOT-FOR-US: ArcadeDB
CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly
isolate Prox ...)
- guzzle 7.14.2-1
+ [trixie] - guzzle <no-dsa> (Minor issue)
NOTE:
https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting
vulnera ...)
- jupyterlab <unfixed>
@@ -12698,6 +12707,7 @@ CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14
and prior have a plaintext
NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a
vulnerability ...)
- knot 3.5.4-1
+ [trixie] - knot <no-dsa> (Minor issue)
[bookworm] - knot <postponed> (Minor issue)
[bullseye] - knot <postponed> (Minor issue)
NOTE: https://www.knot-dns.cz/2026-04-01-version-3410.html
@@ -17760,13 +17770,16 @@ CVE-2026-64620 (FreeRDP before 3.28.0 (affected
<=3.27.1) contains a heap-based
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG
image rea ...)
- libcupsfilters <unfixed> (bug #1142687)
+ [trixie] - libcupsfilters <no-dsa> (Minor issue)
[bookworm] - libcupsfilters <postponed> (Minor issue)
[bullseye] - libcupsfilters <postponed> (Minor issue)
- cups-filters <unfixed>
+ [trixie] - cups-filters <no-dsa> (Minor issue)
[bookworm] - cups-filters <postponed> (Minor issue)
[bullseye] - cups-filters <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502801
- NOTE:
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
(not public)
+ NOTE:
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
+ NOTE:
https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of
Service via de ...)
- libnet-dns-perl 1.56-1 (bug #1142503)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eb0c0cb4f7aed9d850e5ea9347b8434fc65526a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits