[Git][security-tracker-team/security-tracker][master] 2 commits: lts: anki not-affected in bullseye (CVE-2026-59153)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Fri Jul 10 21:56:50 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cbddeb20 by Utkarsh Gupta at 2026-07-11T02:26:07+05:30
lts: anki not-affected in bullseye (CVE-2026-59153)
- - - - -
dc444071 by Utkarsh Gupta at 2026-07-11T02:26:08+05:30
lts: anki not-affected in bullseye (CVE-2026-58266)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1949,6 +1949,7 @@ CVE-2026-59704 (Cap's GET /api/video/ai endpoint fails to validate user ownershi
NOT-FOR-US: CapSoftware Cap
CVE-2026-59153 (Anki is a program for creating and reviewing flashcards. Prior to 25.0 ...)
- anki <removed>
+ [bullseye] - anki <not-affected> (Vulnerable local-server API absent in 2.1.15; no HTTP API/origin handling in aqt/mediasrv.py)
NOTE: https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g
NOTE: Fixed by: https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219 (25.09.3)
CVE-2026-58583 (FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPe ...)
@@ -1979,6 +1980,7 @@ CVE-2026-58384 (A flaw was found in GIMP's PSD parser. An integer overflow in re
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e21779a851fcd95d2af29294bee4071a67a7 (GIMP_3_2_4)
CVE-2026-58266 (Anki is a program for creating and reviewing flashcards. Prior to 25.0 ...)
- anki <removed>
+ [bullseye] - anki <not-affected> (2.1.15 lacks the internal localhost API/getImageForOcclusion and CSP handling in aqt/mediasrv.py)
NOTE: https://github.com/ankitects/anki/security/advisories/GHSA-cw6h-ffmh-x6vh
NOTE: Fixed by: https://github.com/ankitects/anki/commit/b2b68d829e853da51b5de8aad6c13b53e90bc20d (25.09.4)
CVE-2026-57895 (Incorrect default permissions issue exists in Pupsman versions prior t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e3ea1ed7ac440fa36900ec299836538dfa05948f...dc444071a5834b04ca0581a720a23179c9b4882c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e3ea1ed7ac440fa36900ec299836538dfa05948f...dc444071a5834b04ca0581a720a23179c9b4882c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260710/70c35a2f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list