Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
82d0f356 by Moritz Muehlenhoff at 2026-10-05T11:08:09+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1117,6 +1117,7 @@ CVE-2026-104733 (User Impersonation in ProcessOnes XMMP
Server ejabberd <= 26.04
NOTE: https://github.com/processone/ejabberd/releases#release-26.07
CVE-2026-104721 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic
on Java (l ...)
- logback <unfixed> (bug #1149909)
+ [trixie] - logback <no-dsa> (Minor issue)
NOTE: https://logback.qos.ch/news.html#1.6.5
CVE-2026-104638 (A security vulnerability has been detected in onetwothreeneth
Hospital ...)
NOT-FOR-US: onetwothreeneth HospitalManagementSystem
@@ -1276,15 +1277,19 @@ CVE-2026-103956 (Missing authentication for critical
function in the authenticat
NOT-FOR-US: Amazon
CVE-2026-103885 (Asymmetric Resource Consumptionvulnerability in Apache
Directory LDAP ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/8
CVE-2026-103880 (Asymmetric Resource Consumptionvulnerability in Apache
Directory LDAP ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/7
CVE-2026-103878 (Cleartext transmission of sensitive informationvulnerability
in Apache ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/6
CVE-2026-103877 (Deserialization of Untrusted Data vulnerability in Apache
Directory LD ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/5
CVE-2026-103763 (SiYuan before v3.8.5 contains an information disclosure
vulnerability ...)
NOT-FOR-US: SiYuan
@@ -17999,6 +18004,7 @@ CVE-2026-91149 (A flaw was found in Cockpit. An
unauthenticated remote attacker
NOTE:
https://github.com/cockpit-project/cockpit/commit/e12c37897d5a8efb41c65ca95064930e256d562e
(368)
CVE-2026-91148
- cockpit 368-1
+ [trixie] - cockpit <no-dsa> (Minor issue)
NOTE:
https://github.com/cockpit-project/cockpit/commit/6e76c96272a4ebcb085c948e5cc9189eeee561af
(368)
CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a
remote, ...)
- cockpit 368-1
=====================================
data/dsa-needed.txt
=====================================
@@ -42,6 +42,8 @@ dulwich
--
emacs (jmm)
--
+ejabberd
+--
erlang
--
expat
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82d0f3561fdfc8a145a3863e5cf4c87519bcb4eb
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82d0f3561fdfc8a145a3863e5cf4c87519bcb4eb
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits