[Git][security-tracker-team/security-tracker][master] 2 commits: lts: pymdown-extensions postponed in bookworm (CVE-2023-32309)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Tue Jul 21 17:11:41 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8a24c600 by Utkarsh Gupta at 2026-07-21T21:32:59+05:30
lts: pymdown-extensions postponed in bookworm (CVE-2023-32309)
- - - - -
c2736976 by Utkarsh Gupta at 2026-07-21T21:32:59+05:30
dla-needed: add chromium
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -377815,6 +377815,7 @@ CVE-2023-32955 (Improper neutralization of special elements used in an OS comman
NOT-FOR-US: Synology
CVE-2023-32309 (PyMdown Extensions is a set of extensions for the `Python-Markdown` ma ...)
- pymdown-extensions 10.8.1-1
+ [bookworm] - pymdown-extensions <postponed> (pymdownx.snippets path traversal reachable only when Snippets is enabled on untrusted Markdown, discouraged upstream)
NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-jh85-wwv9-24hv
NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/b7bb4878d6017c03c8dc97c42d8d3bb6ee81db9d (10.0)
CVE-2023-32308 (anuko timetracker is an open source time tracking system. Boolean-base ...)
=====================================
data/dla-needed.txt
=====================================
@@ -114,6 +114,10 @@ calibre/bullseye
NOTE: 20260429: partial update (abhijith)
NOTE: 20260430: Revisit when rest of the CVEs are fixed upstream (abhijith)
--
+chromium/bookworm
+ NOTE: 20260721: Added by Front-Desk (utkarsh)
+ NOTE: 20260721: CVE-2026-15899 to CVE-2026-15905 fixed in 150.0.7871.128; bookworm at .124 (DLA-4687-1). Rebase.
+--
ckeditor/bullseye
NOTE: 20241002: Added by Front-Desk (Beuc)
NOTE: 20241002: Multiple CVEs have been piling up (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5c8bc28d40b4bcbb1031364a6d56a4fd80bdc089...c27369762b4a154700c27452a3c29a6982cd87b4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5c8bc28d40b4bcbb1031364a6d56a4fd80bdc089...c27369762b4a154700c27452a3c29a6982cd87b4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/ad3c8d1c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list