[Git][security-tracker-team/security-tracker][master] CVE-2026-77806/spip assigned
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 20:36:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4368a567 by Salvatore Bonaccorso at 2026-08-21T21:35:20+02:00
CVE-2026-77806/spip assigned
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12,8 +12,6 @@ CVE-2026-77814 (is_path_trusted in scripts/iib/api.py compares the requested pat
TODO: check
CVE-2026-77812 (DJI drones transmit DUML (DJI Universal Markup Language) protocol mess ...)
NOT-FOR-US: DJI
-CVE-2026-77806 (SPIP before 4.4.21 allows unauthenticated remote attackers to execute ...)
- TODO: check
CVE-2026-77795 (A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. ...)
TODO: check
CVE-2026-77780 (Authorization Bypass Through User-Controlled Key in the transaction sa ...)
@@ -17868,9 +17866,8 @@ CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
NOT-FOR-US: Joomla
-CVE-2026-XXXX [RCE fixed in 4.4.21]
+CVE-2026-77806 [RCE fixed in 4.4.21]
- spip 4.4.21+dfsg-1
- [trixie] - spip 4.4.21+dfsg-0+deb13u1
NOTE: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
CVE-2026-77647 (SPIP before 4.4.20 allows unauthenticated remote attackers to execute ...)
{DSA-6448-1}
=====================================
data/DSA/list
=====================================
@@ -1,4 +1,5 @@
[21 Aug 2026] DSA-6456-1 spip - security update
+ {CVE-2026-77806}
[trixie] - spip 4.4.21+dfsg-0+deb13u1
[20 Aug 2026] DSA-6455-1 chromium - security update
{CVE-2026-76033 CVE-2026-76034 CVE-2026-76035 CVE-2026-76036 CVE-2026-76037 CVE-2026-76038 CVE-2026-76039 CVE-2026-76040 CVE-2026-76041 CVE-2026-76042 CVE-2026-76043 CVE-2026-76044 CVE-2026-76045 CVE-2026-76046 CVE-2026-76047}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4368a567858cf4b54e9a255f362d2549518504b1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4368a567858cf4b54e9a255f362d2549518504b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/985a2778/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list