[Git][security-tracker-team/security-tracker][master] Reference commit from 1.6.x branch for CVE-2026-34191
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 7 19:49:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
34003fcc by Salvatore Bonaccorso at 2026-08-07T20:48:50+02:00
Reference commit from 1.6.x branch for CVE-2026-34191
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -885,10 +885,7 @@ CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runt
CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
- apr-util 1.6.4-1 (bug #1143837)
NOTE: https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf
- NOTE: Fixed by: [1/4] https://github.com/apache/apr-util/commit/1aed1e343014fced408559f743ccabeafa2ed45e
- NOTE: Fixed by: [2/4] https://github.com/apache/apr-util/commit/159d938a086bb7e4cd8d4a9e740742548ffebc85
- NOTE: Fixed by: [3/4] https://github.com/apache/apr-util/commit/4f5600610f81d37e76f1b4f8c63ed8703482ab79
- NOTE: Fixed by: [4/4] https://github.com/apache/apr-util/commit/4877d02526af7206001811ed28fe051790c5d0b5
+ NOTE: Fixed by: https://github.com/apache/apr-util/commit/6ce807e0f12b666c72ffce1a0f21b4df03fa13ec (1.6.4-rc1-candidate)
CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34003fcc27f3058866fde5aab9dab8be46aee3f5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34003fcc27f3058866fde5aab9dab8be46aee3f5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/5007a66a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list