[Git][security-tracker-team/security-tracker][master] Two CVEs assigned for propftd-dfsg issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 15:55:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
70b55e03 by Salvatore Bonaccorso at 2026-07-20T16:55:10+02:00
Two CVEs assigned for propftd-dfsg issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6822,11 +6822,11 @@ CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial
 	- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
 	NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
-CVE-2026-XXXX [Authenticated SFTP sessions can overflow the SFTP packet buffer]
+CVE-2026-63090 [Authenticated SFTP sessions can overflow the SFTP packet buffer]
 	- proftpd-dfsg 1.3.9c~dfsg-1
 	NOTE: https://github.com/proftpd/proftpd/issues/2190
 	NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c)
-CVE-2026-XXXX [SCP signed-size integer overflow; heap over-read]
+CVE-2026-63091 [SCP signed-size integer overflow; heap over-read]
 	- proftpd-dfsg 1.3.9c~dfsg-1
 	NOTE: https://github.com/proftpd/proftpd/pull/2201
 	NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6 (v1.3.9c)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70b55e03b89e91ec93b62befdd658a104709c77b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70b55e03b89e91ec93b62befdd658a104709c77b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/35e3feb7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list