[Git][security-tracker-team/security-tracker][master] Track proposed update for proftpd-dfsg via trixie-pu
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 1 15:04:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
49f4d495 by Salvatore Bonaccorso at 2026-08-01T16:04:37+02:00
Track proposed update for proftpd-dfsg via trixie-pu
- - - - -
3 changed files:
- data/CVE/list
- data/dsa-needed.txt
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -12723,6 +12723,7 @@ CVE-2026-57848 (Stoat for Android exports the chat.stoat.activities.ShareTargetA
NOT-FOR-US: Stoat for Android
CVE-2026-53994 (ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an ...)
- proftpd-dfsg 1.3.9b~dfsg-1
+ [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
NOTE: https://github.com/proftpd/proftpd/issues/2115
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/8685930f5e2e448563ef31d8871553308b954785 (v1.3.9b)
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/a237fa62341bf882c7edc4e5e8cc492cec851d0b (v1.3.9b)
@@ -19670,10 +19671,12 @@ CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial
NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overf ...)
- proftpd-dfsg 1.3.9c~dfsg-1
+ [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
NOTE: https://github.com/proftpd/proftpd/issues/2190
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c)
CVE-2026-63091 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow ...)
- proftpd-dfsg 1.3.9c~dfsg-1
+ [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
NOTE: https://github.com/proftpd/proftpd/pull/2201
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6 (v1.3.9c)
CVE-2026-9824 (Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10. ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -111,9 +111,6 @@ perl (carnil)
--
podman
--
-proftpd-dfsg
- In contact with Hilmar Preusse for potential update
---
prometheus
--
py7zr
=====================================
data/next-point-update.txt
=====================================
@@ -284,3 +284,11 @@ CVE-2026-61475
[trixie] - qemu 1:10.0.12+ds-0+deb13u1
CVE-2026-63319
[trixie] - qemu 1:10.0.12+ds-0+deb13u1
+CVE-2026-44331
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-53994
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-63091
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-63090
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49f4d495824621b9467286f4d8cffedb3b14a81f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49f4d495824621b9467286f4d8cffedb3b14a81f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/c1732c7f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list