Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6d7959cb by Moritz Mühlenhoff at 2026-09-07T19:56:24+02:00
jbig2dec DSA
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -63449,7 +63449,6 @@ CVE-2026-39243 (decompress before 4.2.2 allows
arbitrary hardlink creation durin
NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function
of Arti ...)
- jbig2dec <unfixed> (bug #1142282)
- [trixie] - jbig2dec <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended
Endpoints ...)
NOT-FOR-US: Juniper
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[07 Sep 2026] DSA-6488-1 jbig2dec - security update
+ {CVE-2026-38076}
+ [trixie] - jbig2dec 0.20-1+deb13u1
[07 Sep 2026] DSA-6487-1 strongswan - security update
{CVE-2026-78123 CVE-2026-78124 CVE-2026-78126 CVE-2026-78127
CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132 CVE-2026-78133
CVE-2026-78134 CVE-2026-78135}
[trixie] - strongswan 6.0.1-6+deb13u7
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d7959cb1ca7c9e4f00087ce4f1e8d6b6dcfea5a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d7959cb1ca7c9e4f00087ce4f1e8d6b6dcfea5a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits