[Git][security-tracker-team/security-tracker][master] bookworm/trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 4 22:03:41 BST 2025
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
493ca5c9 by Moritz Muehlenhoff at 2025-09-04T23:03:28+02:00
bookworm/trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -697,7 +697,11 @@ CVE-2025-9919 (A vulnerability was identified in 1000projects Beauty Parlour Man
NOT-FOR-US: 1000projects Beauty Parlour Management System
CVE-2025-9901 (A flaw was found in libsoup\u2019s caching mechanism, SoupCache, where ...)
- libsoup3 <unfixed>
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <unfixed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/453
CVE-2025-9824 (ImpactThe attacker can validate if a user exists by checking the time ...)
NOT-FOR-US: Mautic
@@ -967,9 +971,10 @@ CVE-2025-9832 (A security vulnerability has been detected in SourceCodester Food
CVE-2025-9831 (A weakness has been identified in PHPGurukul Beauty Parlour Management ...)
NOT-FOR-US: PHPGurukul
CVE-2025-9817 (SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of servi ...)
- - wireshark 4.4.9-1
+ - wireshark 4.4.9-1 (unimportant)
NOTE: https://www.wireshark.org/security/wnpa-sec-2025-03.html
NOTE: https://gitlab.com/wireshark/wireshark/-/issues/20642
+ NOTE: Crash in CLI tool, no security impact
CVE-2025-9785 (PaperCut Print Deploy is an optional component that integrates with Pa ...)
NOT-FOR-US: PaperCut
CVE-2025-9378 (The Vayu Blocks \u2013 Website Builder for the Block Editor plugin for ...)
@@ -1686,6 +1691,7 @@ CVE-2025-58067 (Basecamp's Google Sign-In adds Google sign-in to Rails applicati
NOT-FOR-US: Basecamp's Google Sign-In
CVE-2025-58066 (nptd-rs is a tool for synchronizing your computer's clock, implementin ...)
- rust-ntpd 1.6.2-1 (bug #1112511)
+ [trixie] - rust-ntpd <no-dsa> (Minor issue)
NOTE: https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4
NOTE: Fixed by: https://github.com/pendulum-project/ntpd-rs/commit/da37cf167736cbd4d7804b1ed7ceb572468298e0 (v1.6.2)
CVE-2025-57822 (Next.js is a React framework for building full-stack web applications. ...)
@@ -2040,6 +2046,8 @@ CVE-2025-58061 (OpenEBS Local PV RawFile allows dynamic deployment of Stateful P
NOT-FOR-US: OpenEBS
CVE-2025-58058 (xz is a pure golang package for reading and writing xz-compressed file ...)
- golang-github-ulikunitz-xz 0.5.15-1 (bug #1112508)
+ [trixie] - golang-github-ulikunitz-xz <no-dsa> (Minor issue)
+ [bookworm] - golang-github-ulikunitz-xz <no-dsa> (Minor issue)
NOTE: https://github.com/ulikunitz/xz/security/advisories/GHSA-jc7w-c686-c4v9
NOTE: https://github.com/ulikunitz/xz/commit/88ddf1d0d98d688db65de034f48960b2760d2ae2 (v0.5.14-rc.1)
CVE-2025-54777 (Uncaught exception issue exists in Multiple products in bizhub series. ...)
@@ -13827,6 +13835,8 @@ CVE-2025-53770 (Deserialization of untrusted data in on-premises Microsoft Share
NOT-FOR-US: Microsoft
CVE-2025-XXXX [exposes .zip passwords while (un)archiving]
- krusader <unfixed> (bug #1108942)
+ [trixie] - krusader <no-dsa> (Minor issue, revisit when fixed upstream)
+ [bookworm] - krusader <no-dsa> (Minor issue, revisit when fixed upstream)
[bullseye] - krusader <postponed> (Minor issue)
CVE-2025-7853 (A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as ...)
NOT-FOR-US: Tenda
@@ -14228,10 +14238,8 @@ CVE-2025-54060 (WeGIA is an open source web manager with a focus on the Portugue
CVE-2025-54058 (WeGIA is an open source web manager with a focus on the Portuguese lan ...)
NOT-FOR-US: WeGIA
CVE-2025-53964 (GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows ...)
- - goldendict <unfixed>
- - goldendict-ng <undetermined>
- NOTE: https://github.com/tigr78/CVE-2025-53964
- TODO: check more on details of vulnerability
+ NOTE: Bogus report against GoldenDict
+ NOTE: https://github.com/xiaoyifang/goldendict-ng/issues/2442#issuecomment-3165727711
CVE-2025-53946 (WeGIA is an open source web manager with a focus on the Portuguese lan ...)
NOT-FOR-US: WeGIA
CVE-2025-53941 (Hollo is a federated single-user microblogging software designed to be ...)
@@ -33941,6 +33949,7 @@ CVE-2025-23167 (A flaw in Node.js 20's HTTP parser allows improper termination o
NOTE: Fixed by: https://github.com/nodejs/llhttp/commit/72f53095152740e176438cf7fe68742fe1cb7be8 (v9.0.1)
CVE-2025-23166 (The C++ method SignTraits::DeriveBits() may incorrectly call ThrowExce ...)
- nodejs 20.19.2+dfsg-1 (bug #1105832)
+ [bookworm] - nodejs <postponed> (Fix along with next DSA)
[bullseye] - nodejs <not-affected> (The vulnerable code was introduced later)
NOTE: https://nodejs.org/en/blog/vulnerability/may-2025-security-releases#improper-error-handling-in-async-cryptographic-operations-crashes-process-cve-2025-23166---high
NOTE: Introduced by: https://github.com/nodejs/node/commit/e60841b598ed5246c8dfc24a779c6b1b732d4f87 (v16.14.0)
@@ -41579,6 +41588,7 @@ CVE-2025-3823 (A vulnerability classified as problematic has been found in Sourc
NOT-FOR-US: SourceCodester
CVE-2025-43929 (open_actions.py in kitty before 0.41.0 does not ask for user confirmat ...)
- kitty 0.41.1-1 (bug #1103691)
+ [bookworm] - kitty <no-dsa> (Minor issue)
[bullseye] - kitty <not-affected> (vulnerable code introduced later)
NOTE: https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 (v0.41.0)
NOTE: PoC: https://github.com/0xBenCantCode/CVE-2025-43929
@@ -71501,6 +71511,7 @@ CVE-2024-57947 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/791a615b7ad2258c560f91852be54b0480837c93 (6.11-rc1)
CVE-2025-0650 (A flaw was found in the Open Virtual Network (OVN). Specially crafted ...)
- ovn 25.03.0~git20250216.7c69af7-1 (bug #1093884)
+ [bookworm] - ovn <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2025/01/22/5
NOTE: https://github.com/ovn-org/ovn/commit/249c52ad011cacb4c182dc64e88977ac7c61f668 (v24.09.2)
NOTE: https://github.com/ovn-org/ovn/commit/474bdfcad038e91aeaa036944b6b4be7c3e1ec15 (v25.03.0)
@@ -72277,6 +72288,7 @@ CVE-2025-0411 (7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability al
CVE-2025-23085 (A memory leak could occur when a remote peer abruptly closes the socke ...)
{DLA-4067-1}
- nodejs 20.18.2+dfsg-1 (bug #1094134)
+ [bookworm] - nodejs <postponed> (Fix along with next DSA)
NOTE: https://nodejs.org/en/blog/vulnerability/january-2025-security-releases#goaway-http2-frames-cause-memory-leak-outside-heap-cve-2025-23085---medium
NOTE: Fixed by: https://github.com/nodejs/node/commit/3c7686163ed4c6ae3e5901b758b7a7d4fd5bb0c0 (v23.6.1)
NOTE: Fixed by: https://github.com/nodejs/node/commit/6cc8d58e6f97c37c228f134bd9b98246c8871fb1 (v18.20.6)
=====================================
data/dsa-needed.txt
=====================================
@@ -57,8 +57,7 @@ pagure/oldstable (jmm)
--
php-laravel-framework/oldstable
--
-python-django/oldstable
- Chris is working on it
+python-django
--
ruby-rack/oldstable
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/493ca5c92354444a629a554595dec6784a17b344
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/493ca5c92354444a629a554595dec6784a17b344
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250904/98873f42/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list