[Git][security-tracker-team/security-tracker][master] Reserve DLA-4734-1 for lemonldap-ng
Yadd (@yadd)
yadd at debian.org
Wed Aug 12 14:52:22 BST 2026
Yadd pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a198561c by Yadd at 2026-08-12T15:52:05+02:00
Reserve DLA-4734-1 for lemonldap-ng
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -47151,8 +47151,6 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
- lemonldap-ng 2.23.1+ds-1
[trixie] - lemonldap-ng <no-dsa> (Minor issue)
- [bookworm] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
- [bullseye] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
NOTE: Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/478bed8e58f0457235e0916e3f73a85a2f19471f (v2.23.1)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[12 Aug 2026] DLA-4734-1 lemonldap-ng - security update
+ {CVE-2026-12804 CVE-2026-19349}
+ [bullseye] - lemonldap-ng 2.0.11+ds-4+deb11u9
+ [bookworm] - lemonldap-ng 2.16.1+ds-deb12u9
[11 Aug 2026] DLA-4733-1 php7.4 - security update
{CVE-2026-7260 CVE-2026-17543}
[bullseye] - php7.4 7.4.33-1+deb11u12
=====================================
data/dla-needed.txt
=====================================
@@ -295,10 +295,6 @@ ldap-account-manager
NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
--
-lemonldap-ng (yadd)
- NOTE: 20260811: CVE-2026-19349 (major)
- NOTE: 20260811: CVE-2026-12804 (minor)
---
libarchive
NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a198561c4d2c7a37a4dca2a4f5c3d1f3bcde054a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a198561c4d2c7a37a4dca2a4f5c3d1f3bcde054a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/368b292d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list