Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4e14c981 by Salvatore Bonaccorso at 2026-03-10T17:00:19+01:00
Add more imagemagick issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -105,7 +105,9 @@ CVE-2026-30887 (OneUptime is a solution for monitoring and 
managing online servi
 CVE-2026-30885 (WWBN AVideo is an open source video platform. Prior to 25.0, 
the /obje ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-30883 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qmw5-2p58-xvrc
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/5897fb65d173a57729026321d5067c9ddca5c56f
 (7.1.2-16)
 CVE-2026-30870 (PowerSync Service is the server-side component of the 
PowerSync sync e ...)
        NOT-FOR-US: PowerSync Service
 CVE-2026-30869 (SiYuan is a personal knowledge management system. Prior to 
3.5.10, a p ...)
@@ -119,19 +121,37 @@ CVE-2026-2364 (If a legitimate user confirms a 
self-update prompt or initiate an
 CVE-2026-29773 (Kubewarden is a policy engine for Kubernetes. Kubewarden 
cluster opera ...)
        NOT-FOR-US: Kubewarden
 CVE-2026-28693 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76
 CVE-2026-28692 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mrmj-x24c-wwcv
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/cb6cc0611baa4dac59add6439fa1d8af33fc5927
 (7.1.2-16)
 CVE-2026-28691 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/87f619bcd066a3c8e8fae4addb99f15d496ae881
 (7.1.2-16)
 CVE-2026-28690 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7h7q-j33q-hvpf
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/e6e874875e48dd9838acca3bd22c14a4d2f1b3ca
 (7.1.2-16)
 CVE-2026-28689 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-493f-jh8w-qhx3
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/3eb11260cfe84fddbdcb8d2ed47f92703d1b2987
 (7.1.2-14)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/753ffb699934331b31028d4e271f2f6d6db85074
 (7.1.2-16)
 CVE-2026-28688 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xxw5-m53x-j38c
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/40cfaa7b38729eb6a2808c9b94d6baa2fae6219b
 (7.1.2-14)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/e2d5b4ff0fb6abf2370af4b3dc483934b4dd63ff
 (7.1.2-14)
+       TODO: check if fixes in 7.1.2-14 are yet incomplte because claimed to 
be fixed in 7.1.2-16
 CVE-2026-28687 (ImageMagick is free and open-source software used for editing 
and mani ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q
+       NOTE: Fixed by; 
https://github.com/ImageMagick/ImageMagick/commit/3392b4bba6ce076f4d88f5653a42d97b7e4f6970
 (7.1.2-14)
+       NOTE: Fixed by; 
https://github.com/ImageMagick/ImageMagick6/commit/0e328007d2eeefb9ae24bc3f4442b1a2469d772e
 (6.9.13-39)
+       TODO: check, possibly missing followup, as claimed to be fixed in 
7.1.2-16 and 6.9.13-41
 CVE-2026-28686 (ImageMagick is free and open-source software used for editing 
and mani ...)
        TODO: check
 CVE-2026-28513 (Pocket ID is an OIDC provider that allows users to 
authenticate with t ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e14c981e414a45c33f438a76e4557a998277da8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e14c981e414a45c33f438a76e4557a998277da8
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to