[Git][security-tracker-team/security-tracker][master] Add new pjproject/asterisk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 05:56:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d1b7f9c3 by Salvatore Bonaccorso at 2026-09-06T06:55:36+02:00
Add new pjproject/asterisk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -713,21 +713,45 @@ CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard
 CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57166 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-9c8q-h38q-p85j
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/4472a31d77a7506ff175dad5abef490f4e31bed1
 CVE-2026-57165 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rpq9-9fx7-95xw
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/628b71638465bacf66e767959e6acbab822eccd6
 CVE-2026-57164 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-59fr-724j-6fjv
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/8d5956afab2ede95ddb199078dc19a8ac0114f3d
 CVE-2026-57163 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-jm2j-6rg6-qvwx
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/c4a151af86fadd16d9480b2603eeb2abf4fb4f78
 CVE-2026-57162 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-m9g3-jcj8-qjfm
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9
 CVE-2026-57161 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-xc62-j9h2-mp84
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/acc03b57cef7a7d31b8e1f5b9117437d7e87c591
 CVE-2026-57160 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
 CVE-2026-57159 (PJSIP is a free and open source multimedia communication library writt ...)
-	TODO: check
+	- pjproject <removed>
+	- asterisk <unfixed>
+	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rfwg-w9gq-9mw2
+	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/673b978aab1fe3ab874247be32c871acc880cbeb
 CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
 	NOT-FOR-US: nebula-mesh
 CVE-2026-55512 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1b7f9c350aec4e8075b95ded414becd2939dcb9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1b7f9c350aec4e8075b95ded414becd2939dcb9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/45fefe31/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list