During the month of July 2026 and on behalf of Freexian, I worked on the following:
roundcube --------- Uploaded 1.4.15+dfsg.1-1+deb11u10 and 1.6.5+dfsg-1+deb12u10, and issued DLA-4693-1. https://lists.debian.org/msgid-search/[email protected] * CVE-2026-54432: Stored XSS via unescaped attachment MIME type on the attachment-validation warning page * CVE-2026-54433: Zero-click stored XSS in plain-text rendering * CVE-2026-62641: DoS via crafted compressed-RTF size in the TNEF file * CVE-2026-62642: Infinite loop in TNEF decoder * CVE-2026-62643: SSRF bypass via malicious embedded stylesheet * CVE-2026-62644: Username spoofing via session data [password plugin] For bookworm, 1.6.5+dfsg-1+deb12u10 also restores compatibility with PHP<8 which the previous update broke. libraw ------ Uploaded 0.20.2-1+deb11u3 and 0.20.2-2.1+deb12u2, and issued DLA-4704-1. https://lists.debian.org/msgid-search/[email protected] * CVE-2026-5342: Out-of-bounds read in the decoder routine for RAW image files from Nikon digital cameras * CVE-2026-20884: Integer overflow in the decoder routine for deflate-compressed floating-point DNG RAW files * CVE-2026-20889: Heap-based buffer overflow in the thumbnail extraction routine for RAW image files from Sigma/Foveon X3F digital cameras * CVE-2026-21413: Heap-based buffer overflow vulnerability in the lossless JPEG decoder used for processing compressed RAW data from various camera formats * CVE-2026-24660: Heap-based buffer overflow vulnerability in the Huffman decompression routine for RAW image files from Sigma/Foveon X3F digital cameras Also, file trixie-pu bug #1142984 fixing the above vulnerabilities plus * CVE-2026-24450: Integer overflow in the decoder routine for uncompressed floating-point DNG files poppler ------- Uploaded 20.09.0-3.1+deb11u3 and 22.12.0-2+deb12u3, and issued DLA-4709-1. https://lists.debian.org/msgid-search/[email protected] * CVE-2024-6239: pdfinfo(1) crash when using the -dests parameter * CVE-2025-43718: SIGSEGV via crafted PDF containing deeply nested structures within the metadata * CVE-2025-43903: Signatures with non-empty encapsulated content were trivially forgeable * CVE-2025-50420: Infinite recursion in pdfseparate(1) * CVE-2025-52885: Use-after-free * CVE-2025-52886: Integer overflow * CVE-2026-10118: Integer overflow in the Splash backend For ELTS suites, the work isn't finalized yet but an ELA will be issued shortly. Thanks to the sponsors for financing the above, and to Freexian for coordinating! -- Guilhem.
signature.asc
Description: PGP signature
