Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cdfc55dd by Moritz Muehlenhoff at 2026-08-09T23:29:40+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -417,12 +417,14 @@ CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision 
Labs Arena SDK 1.0.80.
        NOT-FOR-US: LUCID Vision Labs Arena SDK
 CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.15 ...)
        - pypdf <unfixed> (bug #1143902)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
        NOTE: https://github.com/py-pdf/pypdf/pull/3944
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa 
(6.15.0)
 CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.15 ...)
        - pypdf <unfixed> (bug #1143902)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
        NOTE: https://github.com/py-pdf/pypdf/pull/3946
@@ -4879,6 +4881,7 @@ CVE-2026-55825 (Contao is an Open Source CMS. In versions 
5.7.0 through 5.7.6, a
 CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, 
XORMappedAdd ...)
        - golang-github-pion-stun-v3 <unfixed>
        - golang-github-pion-stun <unfixed>
+       [trixie] - golang-github-pion-stun <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
        NOTE: https://github.com/pion/stun/pull/278
        NOTE: Fixed by: 
https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 
(v3.1.3)
@@ -8646,10 +8649,12 @@ CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a 
reachable assertion vulne
        NOTE: 
https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection 
vulnerabili ...)
        - rust-tiny-http <unfixed> (bug #1142989)
+       [trixie] - rust-tiny-http <no-dsa> (Minor issue)
        NOTE: 
https://github.com/theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master
        NOTE: https://github.com/tiny-http/tiny-http/issues/288
 CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling 
vulnerabil ...)
        - rust-tiny-http <unfixed> (bug #1142989)
+       [trixie] - rust-tiny-http <no-dsa> (Minor issue)
        NOTE: 
https://github.com/theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master
        NOTE: https://github.com/tiny-http/tiny-http/issues/287
 CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper 
authorization vuln ...)
@@ -10164,6 +10169,7 @@ CVE-2026-64531 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/28/8
 CVE-2026-49478
        - golang-github-sigstore-fulcio 1.8.7-1
+       [trixie] - golang-github-sigstore-fulcio <no-dsa> (Minor issue)
        NOTE: https://github.com/sigstore/fulcio/pull/2354
        NOTE: Fixed by: 
https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1
 (v1.8.6)
 CVE-2026-48702
@@ -13289,8 +13295,10 @@ CVE-2026-15348 (The Premium Packages \u2013 Sell 
Digital Products Securely plugi
        NOT-FOR-US: WordPress plugin
 CVE-2026-15037 (Improper output neutralization (XML injection) in QDom 
comment, CDATA, ...)
        - qt6-base <unfixed>
+       [trixie] - qt6-base <no-dsa> (Minor issue)
        [bookworm] - qt6-base <postponed> (Minor issue)
        - qtbase-opensource-src <unfixed>
+       [trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
        [bookworm] - qtbase-opensource-src <postponed> (Minor issue)
        [bullseye] - qtbase-opensource-src <postponed> (Minor issue)
        NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/748323
@@ -20726,6 +20734,7 @@ CVE-2026-57980 (Authentication bypass using an 
alternate path or channel in Micr
        NOT-FOR-US: Microsoft
 CVE-2026-56741 (JLine is a Java library for handling console input. Prior to 
3.30.14,  ...)
        - jline3 <unfixed> (bug #1143458)
+       [trixie] - jline3 <no-dsa> (Minor issue)
        - jline2 <undetermined>
        - jline <undetermined>
        NOTE: 
https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933
@@ -20733,6 +20742,7 @@ CVE-2026-56741 (JLine is a Java library for handling 
console input. Prior to 3.3
        NOTE: Fixed by: 
https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708 
(jline-3.30.14)
 CVE-2026-56740 (JLine is a Java library for handling console input. Prior to 
3.30.14,  ...)
        - jline3 <unfixed> (bug #1143458)
+       [trixie] - jline3 <no-dsa> (Minor issue)
        - jline2 <undetermined>
        - jline <undetermined>
        NOTE: 
https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f
@@ -20861,6 +20871,7 @@ CVE-2026-49852 (joserfc is a Python library that 
provides an implementation of s
        NOTE: Fixed by: 
https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1
 (1.6.8)
 CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and 
verification. Pri ...)
        - sigstore-go 1.2.1-1
+       [trixie] - sigstore-go <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6
        NOTE: https://github.com/sigstore/sigstore-go/pull/633
        NOTE: Fixed by: 
https://github.com/sigstore/sigstore-go/commit/dbb07e62623edd5b175fb9dd5a41dcb85a159207
 (v1.2.0)
@@ -20897,6 +20908,7 @@ CVE-2026-45785 (OpenMcdf is a fully .NET / C# library 
to manipulate Compound Fil
        NOT-FOR-US: OpenMcdf
 CVE-2026-45784 (rust-openssl provides OpenSSL bindings for the Rust 
programming langua ...)
        - rust-openssl <unfixed> (bug #1142474)
+       [trixie] - rust-openssl <no-dsa> (Minor issue)
        [bookworm] - rust-openssl <not-affected> (Vulnerable 
CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the 
Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are 
absent too)
        [bullseye] - rust-openssl <not-affected> (Vulnerable 
CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the 
Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are 
absent too)
        NOTE: 
https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
@@ -24248,6 +24260,7 @@ CVE-2026-48252 (Adobe Experience Manager is affected by 
a Missing Authentication
        NOT-FOR-US: Adobe
 CVE-2026-48125 (UAParser.js is a JavaScript library to detect browsers, 
operating syst ...)
        - node-ua-parser-js <unfixed>
+       [trixie] - node-ua-parser-js <no-dsa> (Minor issue)
        [bookworm] - node-ua-parser-js <postponed> (minor issue)
        [bullseye] - node-ua-parser-js <postponed> (minor issue)
        NOTE: 
https://github.com/faisalman/ua-parser-js/security/advisories/GHSA-9h5v-pfqq-x599



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cdfc55dd2f3feed37233008320317d0c3fbe811c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cdfc55dd2f3feed37233008320317d0c3fbe811c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to