Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
82d0f356 by Moritz Muehlenhoff at 2026-10-05T11:08:09+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1117,6 +1117,7 @@ CVE-2026-104733 (User Impersonation in ProcessOnes XMMP 
Server ejabberd <= 26.04
        NOTE: https://github.com/processone/ejabberd/releases#release-26.07
 CVE-2026-104721 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic 
on Java (l ...)
        - logback <unfixed> (bug #1149909)
+       [trixie] - logback <no-dsa> (Minor issue)
        NOTE: https://logback.qos.ch/news.html#1.6.5
 CVE-2026-104638 (A security vulnerability has been detected in onetwothreeneth 
Hospital ...)
        NOT-FOR-US: onetwothreeneth HospitalManagementSystem
@@ -1276,15 +1277,19 @@ CVE-2026-103956 (Missing authentication for critical 
function in the authenticat
        NOT-FOR-US: Amazon
 CVE-2026-103885 (Asymmetric Resource Consumptionvulnerability in Apache 
Directory LDAP  ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/8
 CVE-2026-103880 (Asymmetric Resource Consumptionvulnerability in Apache 
Directory LDAP  ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/7
 CVE-2026-103878 (Cleartext transmission of sensitive informationvulnerability 
in Apache ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/6
 CVE-2026-103877 (Deserialization of Untrusted Data vulnerability in Apache 
Directory LD ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/5
 CVE-2026-103763 (SiYuan before v3.8.5 contains an information disclosure 
vulnerability  ...)
        NOT-FOR-US: SiYuan
@@ -17999,6 +18004,7 @@ CVE-2026-91149 (A flaw was found in Cockpit. An 
unauthenticated remote attacker
        NOTE: 
https://github.com/cockpit-project/cockpit/commit/e12c37897d5a8efb41c65ca95064930e256d562e
 (368)
 CVE-2026-91148
        - cockpit 368-1
+       [trixie] - cockpit <no-dsa> (Minor issue)
        NOTE: 
https://github.com/cockpit-project/cockpit/commit/6e76c96272a4ebcb085c948e5cc9189eeee561af
 (368)
 CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a 
remote,  ...)
        - cockpit 368-1


=====================================
data/dsa-needed.txt
=====================================
@@ -42,6 +42,8 @@ dulwich
 --
 emacs (jmm)
 --
+ejabberd
+--
 erlang
 --
 expat



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82d0f3561fdfc8a145a3863e5cf4c87519bcb4eb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82d0f3561fdfc8a145a3863e5cf4c87519bcb4eb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to