[Git][security-tracker-team/security-tracker][master] new postorius issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu May 7 22:37:37 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2a19c2c9 by Moritz Muehlenhoff at 2026-05-07T23:36:45+02:00
new postorius issues
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -66,7 +66,9 @@ CVE-2026-5786 (An Improper Access Control vulnerability in Ivanti EPMM before ve
CVE-2026-5784 (Improper neutralization of input during web page generation ('cross-si ...)
NOT-FOR-US: DivvyDrive
CVE-2026-44742 (Postorius through 1.3.13 does not escape HTML in the message subject w ...)
- TODO: check
+ - postorius <unfixed>
+ NOTE: https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b
+ NOTE: https://gitlab.com/mailman/postorius/-/merge_requests/972
CVE-2026-44407 (A remote denial-of-service vulnerability exists in the ZTE Cloud PC cl ...)
NOT-FOR-US: ZTE
CVE-2026-44406 (ZTE Cloud PC clientuSmartView contains a DLL hijacking vulnerability; ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -88,6 +88,8 @@ pdfminer (carnil)
--
php-laravel-framework/oldstable
--
+postorius (jmm)
+--
pyjwt (jmm)
Jochen Sprickerhof posted debdiffs for review
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a19c2c9b8b3a7632ef32d5da02ea7fa2c07258f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260507/cc9fcf8c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list