Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e1759c31 by Salvatore Bonaccorso at 2026-09-08T06:55:35+02:00
Add new batch of 389-ds-base issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -320,7 +320,8 @@ CVE-2026-76578 (A flaw was found in FreeIPA. The
self-managed OTP token ACI does
NOTE: FreeIPA in Debian only builds the client packages, not the server
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519522
CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI
bind-rule eva ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519521
CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
NOT-FOR-US: WordPress plugin
CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
@@ -336,17 +337,21 @@ CVE-2026-4945 (The Otter Blocks \u2013 Gutenberg Blocks,
Page Builder for Gutenb
CVE-2026-2390 (The Powerkit plugin for WordPress is vulnerable to Stored
Cross-Site S ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19843 (A flaw was found in 389-ds-base. The Cockpit 389 Console's
LDAP editor ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2515965
CVE-2026-19204 (A client may send a WebSocket frame with an unknown opcode and
a very ...)
TODO: check
CVE-2026-18922 (A flaw was found in 389 Directory Server. During SASL PLAIN
authentica ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511388
CVE-2026-18796 (Any application that uses external QSPI flash for
encrypted XIP o ...)
NOT-FOR-US: Nordic Semiconductor ASA
CVE-2026-18453 (A flaw was found in 389 Directory Server. A missing NULL
pointer check ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509696
CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of
389 Dir ...)
- TODO: check
+ - 389-ds-base <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509186
CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory
exhaustion ...)
- libprotocol-http2-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43351225/
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1759c317dfd1d10501bfe2e3c673f9f5118cbda
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1759c317dfd1d10501bfe2e3c673f9f5118cbda
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits