Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c51e463d by Moritz Muehlenhoff at 2026-09-11T22:23:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -355,6 +355,7 @@ CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 
through 12.1.5 is vuln
        NOT-FOR-US: IBM
 CVE-2026-87908 (multiparty is a Node.js library for parsing 
multipart/form-data reques ...)
        - node-multiparty <unfixed> (bug #1147414)
+       [trixie] - node-multiparty <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
 CVE-2026-86815 (The BackWPup  WordPress plugin before 5.7.5 does not properly 
restrict ...)
        NOT-FOR-US: WordPress plugin
@@ -522,6 +523,7 @@ CVE-2026-54054 (Transmute is a free, open-source, 
self-hosted file conversion an
        NOT-FOR-US: Transmute
 CVE-2026-49836 (psd-tools is a Python package for working with Adobe Photoshop 
PSD fil ...)
        - psd-tools 1.17.4+dfsg.1-1
+       [trixie] - psd-tools <no-dsa> (Minor issue)
        NOTE: 
https://github.com/psd-tools/psd-tools/security/advisories/GHSA-2rmg-vrx8-9j2f
        NOTE: https://github.com/psd-tools/psd-tools/pull/657 (v1.17.1)
 CVE-2026-3096 (The product's web portals allow external links to be opened in 
a new b ...)
@@ -588,6 +590,7 @@ CVE-2025-15695 (The Translate WordPress with GTranslate 
WordPress plugin before
        NOT-FOR-US: WordPress plugin
 CVE-2026-88914 (A flaw was found in GStreamer's gst-plugins-good isomp4 
plugin. When p ...)
        - gst-plugins-good1.0 1.28.7-1
+       [trixie] - gst-plugins-good1.0 <no-dsa> (Minor issue)
        NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0079.html
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5235
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12433
@@ -598,6 +601,7 @@ CVE-2026-89011 (isomorphic-git before 1.42.0 contains a 
prototype pollution vuln
        NOT-FOR-US: isomorphic-git
 CVE-2026-89092 (The nscd service in the GNU C Library 2.3.4 onwards may crash 
due to a ...)
        - glibc <unfixed> (bug #1147395)
+       [trixie] - glibc <no-dsa> (Minor issue)
        NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34624
        NOTE: 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016
 CVE-2026-9338 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
a denia ...)
@@ -867,6 +871,7 @@ CVE-2026-88044 (rclone is a command-line program to sync 
files and directories t
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153
 (v1.75.1)
 CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP 
cookies, use ...)
        - node-cookies <unfixed> (bug #1147405)
+       [trixie] - node-cookies <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
        NOTE: Fixed by: 
https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c
 (v0.9.2)
 CVE-2026-88036 (Improper neutralization of special elements in data query 
logic in the ...)
@@ -3988,6 +3993,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python 
bindings enabled. A remo
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12
 (v2.15.3)
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts 
user-supplied ZIP a ...)
        - gnome-tweaks <unfixed>
+       [trixie] - gnome-tweaks <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability 
in the s ...)
        NOT-FOR-US: XenForo
@@ -6033,6 +6039,7 @@ CVE-2026-86478 (In JetBrains YouTrack before 
2025.3.161254,  2026.1.14042 improp
        NOT-FOR-US: JetBrains
 CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with 
G_FILE_C ...)
        - glib2.0 <unfixed> (bug #1147411)
+       [trixie] - glib2.0 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2473839
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/4044
 CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly 
constrained ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c51e463d5b3349cca44d35cb2efbf9d2ce6d97d8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c51e463d5b3349cca44d35cb2efbf9d2ce6d97d8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to