[Git][security-tracker-team/security-tracker][master] Imagemagick triagging
Bastien Roucariès (@rouca)
rouca at debian.org
Sun Jul 12 09:37:36 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eccf755a by Bastien Roucariès at 2026-07-12T10:37:09+02:00
Imagemagick triagging
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18140,6 +18140,8 @@ CVE-2026-36849 [Denial of Service via large SamplesPerPixel tag]
CVE-2026-XXXX [default policy.xml HTTP/HTTPS/URL delegate rules are no-ops]
- imagemagick 8:7.1.2.25+dfsg1-2 (bug #1140176)
[trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u10
+ [bookworm] - imagemagick 8:6.9.11.60+dfsg-1.6+deb12u11
+ [bullseye] - imagemagick 8:6.9.11.60+dfsg-1.3+deb11u14
CVE-2026-9507 (A session fixation vulnerability has been identified in osTicket v1.18 ...)
- osticket <itp> (bug #998157)
CVE-2026-9307 (A sensitive information disclosure security issue exists within the af ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eccf755a16026d6f5159634997bf427bea6d6ee7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eccf755a16026d6f5159634997bf427bea6d6ee7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/b53db57c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list