Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
577dad2e by Moritz Muehlenhoff at 2026-09-18T17:51:36+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -85,22 +85,22 @@ CVE-2026-93371 (A security vulnerability has been detected 
in marcopiovanello yt
 CVE-2026-93331 (A vulnerability was identified in GPAC 26.08-DEV. This 
vulnerability a ...)
        - gpac <removed>
 CVE-2026-93314 (A vulnerability was determined in Freedesktop Poppler 26.07.0. 
This af ...)
-       - poppler <unfixed>
+       - poppler <unfixed> (bug #1148266)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1761
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2315
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ed2a5538cf0a8d3ff908191eda9b73f91a5f952a
 (poppler-26.08.0)
 CVE-2026-93313 (A vulnerability was found in Freedesktop Poppler 26.07.0. The 
impacted ...)
-       - poppler <unfixed>
+       - poppler <unfixed> (bug #1148266)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1760
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2322
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/eb87cf711563894649bd0c365baa479401dc6d51
 CVE-2026-93312 (A flaw has been found in Freedesktop Poppler 26.07.0. Impacted 
is the  ...)
-       - poppler <unfixed>
+       - poppler <unfixed> (bug #1148266)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067
 (poppler-26.08.0)
 CVE-2026-93311 (A vulnerability was detected in Freedesktop Poppler 26.07.0. 
This issu ...)
-       - poppler <unfixed>
+       - poppler <unfixed> (bug #1148267)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1758
 CVE-2026-93310 (A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. 
This af ...)
        NOT-FOR-US: O-RAN-SC SMO OAM
@@ -585,10 +585,10 @@ CVE-2026-92927 (A vulnerability was found in 
SourceCodester Drug Recommendation
 CVE-2026-92926 (A vulnerability has been found in code-projects Matrimonial 
System 1.0 ...)
        NOT-FOR-US: code-projects
 CVE-2026-92925 (A flaw was found in Redis community. The cluster bus packet 
parser, re ...)
-       - redis <unfixed>
+       - redis <unfixed> (bug #1148265)
        NOTE: https://github.com/redis/redis/pull/15263
        NOTE: Fixed by: 
https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523 
(8.10-rc1)
-       TODO: check details and if redict affected
+       TODO: check if redict affected
 CVE-2026-92921 (admin3 through 3.0.0 stores account passwords using 
single-round MD5 w ...)
        NOT-FOR-US: cjbi admin3
 CVE-2026-92920 (admin3 through 3.0.0 fails to invalidate existing sessions 
when disabl ...)
@@ -3893,7 +3893,7 @@ CVE-2026-92122 (Jenkins Script Security Plugin 
1415.v9a_f9b_3a_c253d and earlier
 CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 
0.10.6. Affe ...)
        NOT-FOR-US: a2ui-project a2ui
 CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function 
validates  ...)
-       - python-jwcrypto <unfixed>
+       - python-jwcrypto <unfixed> (bug #1148270)
        NOTE: 
https://github.com/latchset/jwcrypto/security/advisories/GHSA-pwgw-f7xr-863h
        NOTE: https://github.com/latchset/jwcrypto/pull/398
        NOTE: 
https://github.com/latchset/jwcrypto/commit/21d2a2c20dbc1201ebe0b9b2621417629f37bfcd
 (v1.6.1)
@@ -3906,34 +3906,34 @@ CVE-2026-91939 (Cotonti 1.0.0 Comments plugin passes 
the ci GET parameter to uns
 CVE-2026-91843 (A stack overflow during the unauthenticated login process may 
allow an ...)
        NOT-FOR-US: Check Point
 CVE-2026-91106 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91105 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91104 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91103 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91102 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91101 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91100 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91099 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91098 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-91097 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       - hplip <unfixed>
+       - hplip <unfixed> (bug #1148269)
        NOTE: 
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
 CVE-2026-90999 (Sentry Seer is vulnerable to a multi-stage trust-boundary 
violation th ...)
        NOT-FOR-US: Sentry Seer
@@ -5960,8 +5960,8 @@ CVE-2026-19607 (A flaw was found in the 
first-broker-login flow of the keycloak-
 CVE-2026-19535 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request 
Forgery  ...)
        NOT-FOR-US: Advantech
 CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a 
remotely-triggerable denia ...)
-       - qt6-base <unfixed>
-       - qtbase-opensource-src <unfixed>
+       - qt6-base <unfixed> (bug #1148271)
+       - qtbase-opensource-src <unfixed> (bug #1148272)
        NOTE: https://qt-project.atlassian.net/browse/QTBUG-147191
        NOTE: 
https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f 
(6.10)
 CVE-2026-18595 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable 
to Stor ...)
@@ -6029,7 +6029,7 @@ CVE-2025-36591 (Dell ECS versions 3.8.1.0 through 
3.8.1.7, and Dell ObjectScale
 CVE-2025-14871 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2025-11395 (A flaw was found in Podman. If an attacker can pass a crafted 
tar arch ...)
-       - podman <unfixed>
+       - podman <unfixed> (bug #1148273)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2402034
 CVE-2024-11222 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/577dad2e843c4b65f83221b42a0f01846749a799

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/577dad2e843c4b65f83221b42a0f01846749a799
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to