Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
704b8364 by Salvatore Bonaccorso at 2026-08-30T13:50:05+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -152,7 +152,7 @@ CVE-2026-14835 (The SOGO Add Script to Individual Pages
Header Footer WordPress
CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not
sanitise o ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory
traversal.)
- - ocaml-cohttp <unfixed>
+ - ocaml-cohttp <unfixed> (bug #1146137)
NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an
SSRF iss ...)
NOT-FOR-US: MITRE SAF Heimdall
@@ -161,7 +161,7 @@ CVE-2026-82476 (Memos through 0.30.0 omits the
100.64.0.0/10 carrier-grade NAT a
CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains an authorization
bypass vu ...)
NOT-FOR-US: iFlytek astron-agent
CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks
to the ex ...)
- - sudo <unfixed>
+ - sudo <unfixed> (bug #1146136)
NOTE:
https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status
reports on ...)
NOT-FOR-US: KubeEdge CloudCore
@@ -230,7 +230,7 @@ CVE-2026-75807 (The SAML Single Sign On \u2013 SSO Login
plugin for WordPress is
CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to
Remote Code ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When
processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146135)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
CVE-2026-82333 (multer is a middleware for handling multipart/form-data in
Node.js. A ...)
@@ -717,14 +717,14 @@ CVE-2026-9548 (An improper neutralization of input during
web page generation ('
CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in
Synolo ...)
NOT-FOR-US: Synology
CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When
processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146134)
[trixie] - gimp <not-affected> (Vulnerable code not present)
[bookworm] - gimp <not-affected> (Vulnerable code not present)
[bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16586
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a
CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When
processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146133)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library
used by R ...)
@@ -732,7 +732,7 @@ CVE-2026-82327 (A flaw was found in libsolv, a
dependency-resolution library use
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
TODO: check upstream status, no references from Red Hat
CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP.
When proce ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146132)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with
experime ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/704b836463722a9dd0165164e377b9ec41703cf3
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/704b836463722a9dd0165164e377b9ec41703cf3
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits