Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
18c033ce by Salvatore Bonaccorso at 2026-06-25T20:46:12+02:00
Add new nsd issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1107,14 +1107,27 @@ CVE-2026-13021 (Inappropriate implementation in
DeviceBoundSessionCredentials in
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-12635 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
-CVE-2026-12490 (When a provide-xfr is given with a tls-auth-name, a secondary
requesti ...)
- TODO: check
-CVE-2026-12246 (NSD version 4.14.0 introduced a bug where a specially crafted
APL RR, ...)
- TODO: check
-CVE-2026-12245 (NSD from version 4.13.0 has a heap use-after-free bug in
logging error ...)
- TODO: check
-CVE-2026-12244 (If NSD is configured as secondary for a zone, the primary of
that zone ...)
- TODO: check
+CVE-2026-12490
+ - nsd 4.14.3-1
+ NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt
+CVE-2026-12246
+ - nsd 4.14.3-1
+ [trixie] - nsd <not-affected> (Vulnerable code introduced later)
+ [bookworm] - nsd <not-affected> (Vulnerable code introduced later)
+ [bullseye] - nsd <not-affected> (Vulnerable code introduced later)
+ NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txt
+CVE-2026-12245
+ - nsd 4.14.3-1
+ [trixie] - nsd <not-affected> (Vulnerable code introduced later)
+ [bookworm] - nsd <not-affected> (Vulnerable code introduced later)
+ [bullseye] - nsd <not-affected> (Vulnerable code introduced later)
+ NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt
+CVE-2026-12244
+ - nsd 4.14.3-1
+ [trixie] - nsd <not-affected> (Vulnerable code introduced later)
+ [bookworm] - nsd <not-affected> (Vulnerable code introduced later)
+ [bullseye] - nsd <not-affected> (Vulnerable code introduced later)
+ NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt
CVE-2026-12079 (The Dokan Pro plugin for WordPress is vulnerable to time-based
SQL Inj ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12077 (The Dokan Pro plugin for WordPress is vulnerable to time-based
SQL Inj ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18c033ce7c266f9efb9e1a8f1d61ec25ffe535b7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18c033ce7c266f9efb9e1a8f1d61ec25ffe535b7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits