[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 21:25:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
70c882d3 by Salvatore Bonaccorso at 2026-07-27T22:24:52+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -276,9 +276,9 @@ CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when recon
 CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.  Th ...)
 	TODO: check
 CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
-	TODO: check
+	NOT-FOR-US: proCertum SmartSign
 CVE-2026-57916 (proCertum SmartSign opens Certificate Practice Statement (CPS) URI wit ...)
-	TODO: check
+	NOT-FOR-US: proCertum SmartSign
 CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information disclosure ...)
 	NOT-FOR-US: HCL
 CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which could al ...)
@@ -296,13 +296,13 @@ CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does no
 CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ...)
 	TODO: check
 CVE-2026-55579 (Pheditor is a single-file editor and file manager written in PHP. From ...)
-	TODO: check
+	NOT-FOR-US: Pheditor
 CVE-2026-55578 (Pheditor is a single-file editor and file manager written in PHP. From ...)
-	TODO: check
+	NOT-FOR-US: Pheditor
 CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ...)
 	TODO: check
 CVE-2026-54540 (Pheditor is a single-file editor and file manager written in PHP. Prio ...)
-	TODO: check
+	NOT-FOR-US: Pheditor
 CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
 	TODO: check
 CVE-2026-51304 (sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY c ...)
@@ -320,7 +320,7 @@ CVE-2026-51297 (sqlite 3.41 has a use-after-free vulnerability in the JSON parsi
 CVE-2026-51296 (SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQ ...)
 	TODO: check
 CVE-2026-51244 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: schreibfaul1 ESP32-audioI2S
 CVE-2026-51235 (LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function ...)
 	TODO: check
 CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
@@ -332,11 +332,11 @@ CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerabil
 CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
 	TODO: check
 CVE-2026-48052 (Papra is a minimalistic document management and archiving platform. Pr ...)
-	TODO: check
+	NOT-FOR-US: Papra
 CVE-2026-48051 (Papra is a minimalistic document management and archiving platform. Pr ...)
-	TODO: check
+	NOT-FOR-US: Papra
 CVE-2026-48030 (Pheditor is a single-file editor and file manager written in PHP. From ...)
-	TODO: check
+	NOT-FOR-US: Pheditor
 CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ...)
 	TODO: check
 CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70c882d39fb11be90bc6bf5957a09b1be610874f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/70c882d39fb11be90bc6bf5957a09b1be610874f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/e19426ab/attachment.htm>


More information about the debian-security-tracker-commits mailing list