Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c53354a1 by Emilio Pozuelo Monfort at 2026-09-08T09:14:27+02:00
lts: mark two expat issues as postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -21805,6 +21805,7 @@ CVE-2026-66620 (Editor PHP Object Injection in
OptionTree <= 2.7.3 versions.)
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability
caused ...)
- expat 2.8.4-1 (bug #1144925)
[trixie] - expat <no-dsa> (Minor issue)
+ [bookworm] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1321
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
(R_2_8_4)
NOTE: Fixed by:
https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
(R_2_8_4)
@@ -108055,6 +108056,7 @@ CVE-2026-8194 (A security vulnerability has been
detected in osTicket up to 1.18
CVE-2026-45186 (In libexpat before 2.8.1, the computational complexity of
attribute na ...)
{DSA-6404-1}
- expat 2.8.0-2 (bug #1136164)
+ [bookworm] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1216
NOTE: https://blog.hartwork.org/posts/expat-2-8-1-released/
CVE-2026-45184 (Kdenlive before 26.04.1 allows dangerous proxy parameters when
an atta ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c53354a1251ac45f2e915ee9d738683d5fce8826
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c53354a1251ac45f2e915ee9d738683d5fce8826
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits