[Git][security-tracker-team/security-tracker][master] Update status for CVE-2025-6001{8,9}
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 27 10:58:19 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0dad26d1 by Salvatore Bonaccorso at 2025-09-27T11:57:05+02:00
Update status for CVE-2025-6001{8,9}
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -542,15 +542,17 @@ CVE-2025-10036 (The Featured Image from URL (FIFU) plugin for WordPress is vulne
CVE-2025-60249 (vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and u ...)
NOT-FOR-US: vulnerability-lookup
CVE-2025-60019 (glib-networking's OpenSSL backend fails to properly check the return v ...)
- - glib-networking <unfixed> (bug #1116429)
+ - glib-networking <unfixed> (bug #1116429; unimportant)
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/227
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/263
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/70df675dd4f5e4a593b2f95406c1aac031aa8bc7
+ NOTE: OpenSSL backend disabled by default upstream and in Debian
CVE-2025-60018 (glib-networking's OpenSSL backend fails to properly check the return v ...)
- - glib-networking <unfixed> (bug #1116430)
+ - glib-networking <unfixed> (bug #1116430; unimportant)
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/226
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/262
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/4dd540505d40babe488404f3174ec39f49a84485
+ NOTE: OpenSSL backend disabled by default upstream and in Debian
CVE-2025-5494 (ZohoCorp ManageEngine Endpoint Central was impacted by an improper pri ...)
NOT-FOR-US: Zoho
CVE-2025-59841 (Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0dad26d1044aa8059e9fa9e2a8b51e2daa36122f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0dad26d1044aa8059e9fa9e2a8b51e2daa36122f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250927/3a76abbe/attachment.htm>
More information about the debian-security-tracker-commits
mailing list