[Git][security-tracker-team/security-tracker][master] Though the AllowAlternateShell was introduced in v0.9.22. The
Abhijith PA (@abhijith)
abhijith at debian.org
Mon Aug 24 10:13:33 BST 2026
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ac1208da by Abhijith PA at 2026-08-24T14:23:18+05:30
Though the AllowAlternateShell was introduced in v0.9.22. The
AlternateShell function was present way before without any toggle
flag. Values supplied via Alternateshell can be executed without
any check. Marking it as ignored for bullseye and bookworm
version.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -107008,6 +107008,8 @@ CVE-2026-33436 (Stirling-PDF is a locally hosted web application that facilitate
NOT-FOR-US: Stirling-PDF
CVE-2026-33145 (xrdp is an open source RDP server. Versions through 0.10.5 allow an au ...)
- xrdp 0.10.6-1 (bug #1134339)
+ [bookworm] - xrdp <ignored> (Intrusive to backport)
+ [bullseye] - xrdp <ignored> (Intrusive to backport)
NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rmvv-7633-fg7h
NOTE: https://github.com/neutrinolabs/xrdp/commit/4174e61f38e5ebf79dade7b30634e998311e573f (v0.10.6)
CVE-2026-33093 (Anviz CX7 Firmwareis vulnerable to an unauthenticated POST to the devi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac1208daac40b7aafda565d13360dc87316945ac
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac1208daac40b7aafda565d13360dc87316945ac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260824/3cacd927/attachment.htm>
More information about the debian-security-tracker-commits
mailing list