Abhijith PA pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ac1208da by Abhijith PA at 2026-08-24T14:23:18+05:30
Though the AllowAlternateShell was introduced in v0.9.22. The
AlternateShell function was present way before without any toggle
flag. Values supplied via Alternateshell can be executed without
any check. Marking it as ignored for bullseye and bookworm
version.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -107008,6 +107008,8 @@ CVE-2026-33436 (Stirling-PDF is a locally hosted web 
application that facilitate
        NOT-FOR-US: Stirling-PDF
 CVE-2026-33145 (xrdp is an open source RDP server. Versions through 0.10.5 
allow an au ...)
        - xrdp 0.10.6-1 (bug #1134339)
+       [bookworm] - xrdp <ignored> (Intrusive to backport)
+       [bullseye] - xrdp <ignored> (Intrusive to backport)
        NOTE: 
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rmvv-7633-fg7h
        NOTE: 
https://github.com/neutrinolabs/xrdp/commit/4174e61f38e5ebf79dade7b30634e998311e573f
 (v0.10.6)
 CVE-2026-33093 (Anviz CX7 Firmwareis vulnerable to an unauthenticated POST to 
the devi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac1208daac40b7aafda565d13360dc87316945ac

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac1208daac40b7aafda565d13360dc87316945ac
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to