[Git][security-tracker-team/security-tracker][master] Add new asterisk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Feb 6 21:14:27 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1fe35f33 by Salvatore Bonaccorso at 2026-02-06T22:13:58+01:00
Add new asterisk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -139,13 +139,19 @@ CVE-2026-24050 (Zulip is an open-source team collaboration tool. From 5.0 to bef
 CVE-2026-23989 (REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bu ...)
 	NOT-FOR-US: REVA
 CVE-2026-23741 (Asterisk is an open source private branch exchange and telephony toolk ...)
-	TODO: check
+	- asterisk <unfixed>
+	NOTE: https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3
 CVE-2026-23740 (Asterisk is an open source private branch exchange and telephony toolk ...)
-	TODO: check
+	- asterisk <unfixed>
+	NOTE: https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c
 CVE-2026-23739 (Asterisk is an open source private branch exchange and telephony toolk ...)
-	TODO: check
+	- asterisk <unfixed> (unimportant)
+	NOTE: https://github.com/asterisk/asterisk/security/advisories/GHSA-85x7-54wr-vh42
+	NOTE: Asterisk does ot allow untrusted or user-supplied XML to be used but upstream
+	NOTE: fixed the issue as a future hardening measure.
 CVE-2026-23738 (Asterisk is an open source private branch exchange and telephony toolk ...)
-	TODO: check
+	- asterisk <unfixed>
+	NOTE: https://github.com/asterisk/asterisk/security/advisories/GHSA-v6hp-wh3r-cwxh
 CVE-2026-23633 (Gogs is an open source self-hosted Git service. In version 0.13.3 and  ...)
 	NOT-FOR-US: Go Git Service
 CVE-2026-23632 (Gogs is an open source self-hosted Git service. In version 0.13.3 and  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fe35f33ee8e8bc29e58c758b8f72aa416d997e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fe35f33ee8e8bc29e58c758b8f72aa416d997e9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260206/2539a597/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list