Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2631ad2a by Salvatore Bonaccorso at 2026-09-07T07:07:02+02:00
Track fixed version for thrift issues now fixed in unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -46089,13 +46089,13 @@ CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) 
in the email module in Rosk
        NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-58662 (Improper Validation of Specified Quantity in Input, 
Out-of-bounds Read ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed> (unimportant)
+       - thrift 0.24.0-2 (unimportant)
        NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
        NOTE: rust bindings not built in Debian package
 CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when 
reconstruct ...)
@@ -46109,7 +46109,7 @@ CVE-2026-58227 (The Erlang/OTP ssl application does not 
detect cycles when recon
        NOTE: Fixed by: 
https://github.com/erlang/otp/commit/7db64720177961e04545681480d691c4be81c54d 
(OTP-29.0.4)
 CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib 
bindings.  Th ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
@@ -46123,25 +46123,25 @@ CVE-2026-56537 (HCL Connections is vulnerable to 
information disclosure which co
        NOT-FOR-US: HCL
 CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ 
bindings ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed> (bug #1145700)
+       - thrift 0.24.0-2 (bug #1145700)
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
 CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.  
This is ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7
 CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift 
C++, c_g ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
 CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources 
Without Li ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed> (unimportant)
+       - thrift 0.24.0-2 (unimportant)
        NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
        NOTE: nodejs bindings not built in Debian package
 CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does 
not veri ...)
@@ -46204,24 +46204,24 @@ CVE-2026-51235
        REJECTED
 CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data 
Amplification) vulne ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed> (unimportant)
+       - thrift 0.24.0-2 (unimportant)
        NOTE: https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7
        NOTE: ruby bindings not built in Debian package
 CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data 
Amplification) vulne ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
 CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch 
vulnerability in ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h
 CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch 
vulnerability in ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
@@ -46250,13 +46250,13 @@ CVE-2026-45623 (PostCSS takes a CSS file and provides 
an API to analyze and modi
        NOTE: 
https://github.com/postcss/postcss/commit/85c4d7dab830be366f8a96047f9e5b7944e101d8
 (8.5.12)
 CVE-2026-45112 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc
 CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') 
vulnerability i ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        [bookworm] - thrift <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
@@ -46269,7 +46269,7 @@ CVE-2026-42792 (Improper Handling of Exceptional 
Conditions vulnerability in Erl
        NOTE: Fixed by: 
https://github.com/erlang/otp/commit/865d203e4a6a8f44179eced9e1428f9259e4a3bb 
(OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data 
Amplification) vulne ...)
        [experimental] - thrift 0.24.0-1
-       - thrift <unfixed>
+       - thrift 0.24.0-2
        [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
 CVE-2026-40000 (The Activity 
zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2631ad2a72267e35c18f1ac0d0cd137cf6372062

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2631ad2a72267e35c18f1ac0d0cd137cf6372062
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to