[Git][security-tracker-team/security-tracker][master] Reserve DSA number for zip update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 09:02:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1dba6f53 by Salvatore Bonaccorso at 2026-08-14T10:01:18+02:00
Reserve DSA number for zip update

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -8248,6 +8248,7 @@ CVE-2026-62289
 	NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c (v1.23.1)
 CVE-2026-XXXX [Command injection issue with zip]
 	- zip 3.0-16 (bug #1143866)
+	[trixie] - zip 3.0-15+deb13u1
 CVE-2026-8325 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-7406 (A maliciously crafted BMP file, when parsed through certain Autodesk p ...)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,5 @@
+[14 Aug 2026] DSA-6439-1 zip - security update
+	[trixie] - zip 3.0-15+deb13u1
 [13 Aug 2026] DSA-6438-1 postgresql-17 - security update
 	{CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385}
 	[trixie] - postgresql-17 17.11-0+deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -171,5 +171,3 @@ xorg-server
 --
 xrdp
 --
-zip (carnil)
---



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1dba6f538ab428f5e823c7d29a4f20ff868f4233

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1dba6f538ab428f5e823c7d29a4f20ff868f4233
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0835cbd1/attachment.htm>


More information about the debian-security-tracker-commits mailing list