[Git][security-tracker-team/security-tracker][master] Update status for netcff issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 10 07:33:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f52bb31d by Salvatore Bonaccorso at 2026-07-10T08:33:42+02:00
Update status for netcff issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -110982,8 +110982,8 @@ CVE-2025-15045 (A flaw has been found in Tenda WH450 1.0.0.18. The affected elem
CVE-2025-15044 (A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an u ...)
NOT-FOR-US: Tenda
CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -110992,9 +110992,10 @@ CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1155/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by: https://github.com/Unidata/netcdf-c/commit/b491ecd8021f510427459051ebfd7bd4cfda2371 (v4.10.1)
CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111003,9 +111004,10 @@ CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow R
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1154/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by: https://github.com/Unidata/netcdf-c/commit/0b33fab5c1d7bc458bf0aead93af433e0eae5abc (v4.10.1)
CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111014,9 +111016,10 @@ CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow R
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1152/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by: https://github.com/Unidata/netcdf-c/commit/1e22866daae12203c768a38c168b8d25c65627d9 (v4.10.1)
CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Executio ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor isuse)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111025,9 +111028,10 @@ CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Ex
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1151/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by: https://github.com/Unidata/netcdf-c/commit/b06b973e040ffede8d776ff7a94d22c68074ea98 (v4.10.1)
CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code ...)
- - netcdf <unfixed> (bug #1123960)
- [trixie] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ - netcdf 1:4.10.1-1 (bug #1123960)
+ [trixie] - netcdf <no-dsa> (Minor issue)
[bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- netcdf-parallel <unfixed> (bug #1123961)
@@ -111036,6 +111040,7 @@ CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remot
[bullseye] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-1153/
NOTE: https://github.com/Unidata/netcdf-c/issues/3236
+ NOTE: Fixed by: https://github.com/Unidata/netcdf-c/commit/60578c3ac26b93b1932cba414a2870096bbcdd3b (v4.10.1)
CVE-2025-14931 (Hugging Face smolagents Remote Python Executor Deserialization of Untr ...)
NOT-FOR-US: Hugging Face smolagents
CVE-2025-14930 (Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remot ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f52bb31d8b2aa3c3d32687d62723d9c805148608
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260710/11228b2c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list