[Git][security-tracker-team/security-tracker][master] Associate some older Cloudflare Quiche issues with itp'ed entry

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 06:59:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7a916f5c by Salvatore Bonaccorso at 2026-07-25T07:58:41+02:00
Associate some older Cloudflare Quiche issues with itp'ed entry

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -29782,7 +29782,7 @@ CVE-2026-12238 (The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPre
 CVE-2026-12104 (OS command injection in the environment and tunnel configuration funct ...)
 	NOT-FOR-US: SIMA GmbH Bondix
 CVE-2026-11941 (Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in  ...)
-	NOT-FOR-US: Cloudflare Quiche
+	- quiche <itp> (bug #841848)
 CVE-2026-11576 (The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refacto ...)
 	NOT-FOR-US: Eclipse
 CVE-2025-71326 (AVAST Antivirus 25.11 contains an unquoted service path vulnerability  ...)
@@ -332785,7 +332785,7 @@ CVE-2024-21330 (Open Management Infrastructure (OMI) Elevation of Privilege Vuln
 CVE-2024-20671 (Microsoft Defender Security Feature Bypass Vulnerability)
 	NOT-FOR-US: Microsoft
 CVE-2024-1765 (Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an u ...)
-	NOT-FOR-US: Cloudflare quiche
+	- quiche <itp> (bug #841848)
 CVE-2024-1618 (A search path or unquoted item vulnerability in Faronics Deep Freeze S ...)
 	NOT-FOR-US: Faronics Deep Freeze Server Standard
 CVE-2024-1529 (Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently e ...)
@@ -332795,7 +332795,7 @@ CVE-2024-1528 (CMS Made Simple version 2.2.14, does not sufficiently encode user
 CVE-2024-1527 (Unrestricted file upload vulnerability in CMS Made Simple, affecting v ...)
 	NOT-FOR-US: CMS Made Simple
 CVE-2024-1410 (Cloudflare quiche was discovered to be vulnerable to unbounded storage ...)
-	NOT-FOR-US: Cloudflare quiche
+	- quiche <itp> (bug #841848)
 CVE-2024-1328 (The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-1304 (Cross-site scripting vulnerability in Badger Meter Monitool that affec ...)
@@ -352685,7 +352685,7 @@ CVE-2023-6593 (Client side permission bypass in Devolutions Remote Desktop Manag
 CVE-2023-6547 (Mattermost fails to validate team membership when a user attempts to a ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2023-6193 (quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unb ...)
-	NOT-FOR-US: Cloudflare quiche
+	- quiche <itp> (bug #841848)
 CVE-2023-50495 (NCurse v6.4-20230418 was discovered to contain a segmentation fault vi ...)
 	- ncurses 6.4+20230625-1
 	[bookworm] - ncurses <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/2318515d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list