Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
264f9cbd by Salvatore Bonaccorso at 2026-08-13T06:02:04+02:00
Update status for CVE-2026-34191/apr-util
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7272,9 +7272,10 @@ CVE-2026-34501 (Heap-based Buffer Overflow vulnerability
in Apache Portable Runt
NOTE: https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv
NOTE: Fixed by:
https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2
(1.6.4-rc1-candidate)
CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- - apr-util 1.6.4-1 (bug #1143837)
+ - apr-util 1.6.4-1 (bug #1143837; unimportant)
NOTE: https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf
NOTE: Fixed by:
https://github.com/apache/apr-util/commit/6ce807e0f12b666c72ffce1a0f21b4df03fa13ec
(1.6.4-rc1-candidate)
+ NOTE: apr_dbd_oracle provider not built in Debian packages
CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0
versions.)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/264f9cbd6f3560256d65f8aee14d5d399bdc7a8e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/264f9cbd6f3560256d65f8aee14d5d399bdc7a8e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits