[Git][security-tracker-team/security-tracker][master] CVE-2026-45793/composer: fix fixed version
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Jul 18 07:57:17 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e525ffcd by Sylvain Beucler at 2026-07-18T08:56:56+02:00
CVE-2026-45793/composer: fix fixed version
0.9.1+dfsg-1 is not an existing composer version.
This is below all composer versions and masks the issue for <bookworm
in the tracker.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -45204,7 +45204,7 @@ CVE-2026-6637 (Stack buffer overflow in PostgreSQL module "refint" allows an unp
- postgresql-13 <removed>
NOTE: https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
CVE-2026-45793 (Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...)
- - composer 0.9.1+dfsg-1
+ - composer 2.10.0-1
[trixie] - composer 2.8.8-1+deb13u3
[bookworm] - composer 2.5.5-1+deb12u5
NOTE: https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e525ffcdbf606011355667877c370920c2ad114a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e525ffcdbf606011355667877c370920c2ad114a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/b5dceb07/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list