[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 30 12:50:17 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
704b8364 by Salvatore Bonaccorso at 2026-08-30T13:50:05+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -152,7 +152,7 @@ CVE-2026-14835 (The SOGO Add Script to Individual Pages Header Footer WordPress
CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise o ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
- - ocaml-cohttp <unfixed>
+ - ocaml-cohttp <unfixed> (bug #1146137)
NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF iss ...)
NOT-FOR-US: MITRE SAF Heimdall
@@ -161,7 +161,7 @@ CVE-2026-82476 (Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT a
CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains an authorization bypass vu ...)
NOT-FOR-US: iFlytek astron-agent
CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks to the ex ...)
- - sudo <unfixed>
+ - sudo <unfixed> (bug #1146136)
NOTE: https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status reports on ...)
NOT-FOR-US: KubeEdge CloudCore
@@ -230,7 +230,7 @@ CVE-2026-75807 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress is
CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146135)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
CVE-2026-82333 (multer is a middleware for handling multipart/form-data in Node.js. A ...)
@@ -717,14 +717,14 @@ CVE-2026-9548 (An improper neutralization of input during web page generation ('
CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in Synolo ...)
NOT-FOR-US: Synology
CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146134)
[trixie] - gimp <not-affected> (Vulnerable code not present)
[bookworm] - gimp <not-affected> (Vulnerable code not present)
[bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16586
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a
CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146133)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
@@ -732,7 +732,7 @@ CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library use
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
TODO: check upstream status, no references from Red Hat
CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1146132)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/704b836463722a9dd0165164e377b9ec41703cf3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/704b836463722a9dd0165164e377b9ec41703cf3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/3094d4f1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list