[Git][security-tracker-team/security-tracker][master] Reserve DSA number for zip update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 09:02:32 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1dba6f53 by Salvatore Bonaccorso at 2026-08-14T10:01:18+02:00
Reserve DSA number for zip update
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -8248,6 +8248,7 @@ CVE-2026-62289
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c (v1.23.1)
CVE-2026-XXXX [Command injection issue with zip]
- zip 3.0-16 (bug #1143866)
+ [trixie] - zip 3.0-15+deb13u1
CVE-2026-8325 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
NOT-FOR-US: Autodesk
CVE-2026-7406 (A maliciously crafted BMP file, when parsed through certain Autodesk p ...)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,5 @@
+[14 Aug 2026] DSA-6439-1 zip - security update
+ [trixie] - zip 3.0-15+deb13u1
[13 Aug 2026] DSA-6438-1 postgresql-17 - security update
{CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385}
[trixie] - postgresql-17 17.11-0+deb13u1
=====================================
data/dsa-needed.txt
=====================================
@@ -171,5 +171,3 @@ xorg-server
--
xrdp
--
-zip (carnil)
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1dba6f538ab428f5e823c7d29a4f20ff868f4233
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1dba6f538ab428f5e823c7d29a4f20ff868f4233
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0835cbd1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list