Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
344b9eee by Moritz Muehlenhoff at 2026-08-27T17:35:28+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -40,6 +40,7 @@ CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - 
Reflected XSS via th
        NOT-FOR-US: Joomla
 CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia 
diagram e ...)
        - dia <unfixed>
+       [trixie] - dia <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/580
 CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. 
In vers ...)
        - seaweedfs <itp> (bug #956957)
@@ -346,6 +347,7 @@ CVE-2026-78360
        NOT-FOR-US: fedora-infra/anitya
 CVE-2026-77117
        - glibc <unfixed>
+       [trixie] - glibc <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523274
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can 
construct mali ...)
        NOT-FOR-US: ZTE
@@ -2147,7 +2149,9 @@ CVE-2026-77693 (The Order Tip for WooCommerce WordPress 
plugin before 1.6.0 does
        NOT-FOR-US: WordPress plugin
 CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range 
header p ...)
        - libsoup3 <unfixed> (bug #1145785)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
 CVE-2026-77585 (The Okta Privileged Access client does not reject a leading 
hyphen in  ...)
@@ -2412,8 +2416,10 @@ CVE-2026-41707 (Authentication Bypass by Capture-replay 
vulnerability in Spring
 CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & 
Ecosystem ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version 
source snapsh ...)
-       - sqlite3 <unfixed>
-       TODO: check upstream details
+       - sqlite3 3.53.2-1
+       [trixie] - sqlite3 <no-dsa> (Minor issue)
+       NOTE: https://github.com/20000419/CVE-2026-39113
+       NOTE: 
https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508
 (version-3.53.0)
 CVE-2026-38474 (GazellePW (GazellePosterWall) commit 
86c4bedf727691b5a97af42a4864869d1 ...)
        NOT-FOR-US: GazellePW
 CVE-2026-38473 (A Stored XSS vulnerability in the subtitle deletion flow in 
GazellePW  ...)
@@ -2580,12 +2586,15 @@ CVE-2026-79717 (A server-side request forgery (SSRF) 
vulnerability was found in
        NOT-FOR-US: Ansible Galaxy server plugin for Pulp
 CVE-2026-79676 (NLTK versions before 3.10.3 contain a path traversal 
vulnerability in  ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-p4rw-rvv2-7xwr
 CVE-2026-79675 (NLTK before 3.10.3 fails to validate JVM options passed 
through the pe ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3
 CVE-2026-79674 (NLTK versions before 3.10.3 contain a path sandbox bypass 
vulnerabilit ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49
 CVE-2026-79673 (Ech0 before 4.4.3 protects the PUT /user endpoint with the 
profile:rea ...)
        NOT-FOR-US: Ech0
@@ -3069,10 +3078,10 @@ CVE-2026-17548 (Missing authorization in Checkmk 
<2.5.0p12, <2.4.0p36, <2.3.0p50
 CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations 
in a fe ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP 
OPIE/S-KEY auth ...)
-       - wget <unfixed>
-       [trixie] - wget <no-dsa> (Minor issue)
+       - wget <unfixed> (unimportant)
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-16599/
        NOTE: Fixed by: 
https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
+       NOTE: Hang in CLI tool, no security impact
 CVE-2026-16286 (Unrestricted upload of file with dangerous type vulnerability 
in TRtek ...)
        NOT-FOR-US: TRtek Software Repository Management
 CVE-2026-16234 (There is a memory corruption vulnerability recently discovered 
in NI L ...)
@@ -3123,6 +3132,7 @@ CVE-2021-47996 (Nokogiri before 1.11.4 (CRuby 
implementation only, when the pack
        TODO: check
 CVE-2026-63676
        - libyaml-perl 1.321-1
+       [trixie] - libyaml-perl <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/ingydotnet/yaml-pm/commit/9388c6a02a66db79f9d2b3727b5588272f612cf1
 (v1.320.0)
 CVE-2026-XXXX [GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows 
configuration takeover and remote code execution]
        - sabnzbdplus 5.1.2+dfsg-1 (bug #1145563)
@@ -3579,6 +3589,7 @@ CVE-2026-78369 (RansomLook contains a missing 
authentication vulnerability in th
        NOT-FOR-US: RansomLook
 CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball 
processing. When p ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://github.com/rpm-software-management/rpm/issues/4314
 CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the 
supplier API i ...)
        NOT-FOR-US: Roskus Prospero Flow CRM


=====================================
data/dsa-needed.txt
=====================================
@@ -57,6 +57,8 @@ jupyterlab
 --
 kamailio
 --
+keystone
+--
 kitty
 --
 libapache2-mod-auth-openidc (jmm)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/344b9eee707b3fe2ee651d12e0ba46b71f6760a7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to