[Git][security-tracker-team/security-tracker][master] Add followup to CVE-2018-0499/xapian-core
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 05:18:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2c9bfcb8 by Salvatore Bonaccorso at 2026-08-14T06:18:00+02:00
Add followup to CVE-2018-0499/xapian-core
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -779535,11 +779535,17 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and includin
[stretch] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
[jessie] - curl <not-affected> (Only affects 7.54.1 to 7.60.0)
NOTE: https://curl.haxx.se/docs/adv_2018-70a2.html
+CVE-2026-XXXX [missing corner-case of CVE-2018-0499]
+ - xapian-core 1.4.32-1
+ [trixie] - xapian-core <no-dsa> (Minor issue)
+ NOTE: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
+ NOTE: https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
CVE-2018-0499 (A cross-site scripting vulnerability in queryparser/termgenerator_inte ...)
- xapian-core 1.4.6-1 (bug #902886)
[stretch] - xapian-core 1.4.3-2+deb9u1
[jessie] - xapian-core <not-affected> (vulnerable code not present)
NOTE: https://lists.xapian.org/pipermail/xapian-discuss/2018-July/009652.html
+ NOTE: https://trac.xapian.org/wiki/SecurityFixes/2018-07-02
CVE-2018-0498 (ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows loc ...)
{DSA-4296-1 DLA-1518-1}
- mbedtls 2.12.0-1 (bug #904821)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c9bfcb85bcb34a94361dcf15812f3b4667e8046
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c9bfcb85bcb34a94361dcf15812f3b4667e8046
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/d6ca0e1e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list