[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 6 19:23:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
59c79ea0 by Moritz Muehlenhoff at 2026-09-06T20:17:14+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -214,21 +214,27 @@ CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to a
NOT-FOR-US: WordPress plugin
CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF instructio ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce (libpcap-1.10.7)
CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 (libpcap-1.10.7)
CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of the filter ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 (libpcap-1.10.7)
CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF instructi ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 (libpcap-1.10.7)
CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 (libpcap-1.10.7)
CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 (libpcap-1.10.7)
CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is vulnerable to ...)
NOT-FOR-US: WordPress plugin
@@ -238,15 +244,17 @@ CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email Automati
NOT-FOR-US: WordPress plugin
CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch memory r ...)
- libpcap <unfixed> (bug #1146825)
+ [trixie] - libpcap <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 (libpcap-1.10.7)
CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress is vuln ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability in the o ...)
NOT-FOR-US: CDT
CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read vulnerability in t ...)
- - ugrep 7.6.0+dfsg-1
+ - ugrep 7.6.0+dfsg-1 (unimportant)
NOTE: https://github.com/Genivia/ugrep/issues/511
NOTE: Fixed by: https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4 (v7.6.0)
+ NOTE: Crash in CLI tool, no security impact
CVE-2024-11080 (The Post Grid and Gutenberg Blocks \u2013 ComboBlocks plugin for WordP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
@@ -302,6 +310,7 @@ CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redir
NOT-FOR-US: Camaleon CMS
CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)
- ndpi <unfixed> (bug #1146882)
+ [trixie] - ndpi <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c (6.0)
CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer dereference vulne ...)
NOT-FOR-US: PX4 Autopilot
@@ -309,7 +318,9 @@ CVE-2026-86096 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerabi
NOT-FOR-US: PX4 Autopilot
CVE-2026-86095 (Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulner ...)
- netcdf <unfixed>
+ [trixie] - netcdf <no-dsa> (Minor issue)
- netcdf-parallel <unfixed>
+ [trixie] - netcdf-parallel <no-dsa> (Minor issue)
CVE-2026-86091 (ntopng before 6.7.260717 fails to check user privileges in the pools b ...)
- ntopng <removed>
CVE-2026-86090 (ntopng before 6.7.260717 fails to perform authorization checks in the ...)
@@ -574,21 +585,27 @@ CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whethe
NOT-FOR-US: fastify/middie
CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0 does not p ...)
NOT-FOR-US: WordPress plugin
@@ -600,6 +617,7 @@ CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform
NOT-FOR-US: WordPress plugin
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
NOT-FOR-US: WordPress plugin
@@ -619,6 +637,7 @@ CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77 d
NOT-FOR-US: WordPress plugin
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
NOT-FOR-US: WordPress plugin
@@ -974,6 +993,7 @@ CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated
NOT-FOR-US: IBM
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
NOT-FOR-US: IBM
@@ -1027,6 +1047,7 @@ CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attac
NOT-FOR-US: IBM
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context ...)
NOT-FOR-US: IBM
@@ -1046,6 +1067,7 @@ CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to ma
NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
+ [trixie] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
@@ -1797,21 +1819,27 @@ CVE-2026-8862 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credent
NOT-FOR-US: IBM
CVE-2026-85509 (FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_ ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85508 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85507 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85506 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85505 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85504 (FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_ ...)
- freeipmi 1.6.19-1 (bug #1146649)
+ [trixie] - freeipmi <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/5
CVE-2026-85458 (Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 fo ...)
- xpdf <not-affected> (Debian uses poppler)
@@ -2452,6 +2480,7 @@ CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In
- ntopng <removed>
CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
- libmongocrypt 1.20.4-1
+ [trixie] - libmongocrypt <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-971
CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of ...)
- mongo-cxx-driver 4.5.2-1
@@ -2464,6 +2493,7 @@ CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers o
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
- php-mongodb <unfixed>
+ [trixie] - php-mongodb <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/PHPC-2744
NOTE: Fixed by: https://github.com/mongodb/mongo-php-driver/commit/44f68614e0a859a0d880811e3f93c2a02330c565 (2.5.1)
CVE-2026-84967 (A component of the MongoDB extension for Visual Studio Code does not n ...)
@@ -2487,6 +2517,7 @@ CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of
NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
- libmongocrypt 1.20.2-1
+ [trixie] - libmongocrypt <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-960
CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
NOT-FOR-US: RightNow-AI OpenFang
@@ -5623,9 +5654,8 @@ CVE-2026-5956 (Improper neutralization of special elements used in an SQL comman
CVE-2026-59111 (Improper neutralization of special elements used in an OS command ('OS ...)
NOT-FOR-US: Ministry of the Interior eObananka-Identifikace
CVE-2026-58301 (When Apache Shiro is used with the Jakarta EE integration module, a lo ...)
- - shiro <unfixed>
+ - shiro <not-affected> (Vulnerable code introduced later in 2.x)
NOTE: https://lists.apache.org/thread/g1g84ovof5fnonvc5o89wym2jzt77fww
- TODO: check, possibly not affecting old 1.3.y version in Debian
CVE-2026-53553 (Goploy is an open-source automation deployment system. Prior to versio ...)
NOT-FOR-US: Goploy
CVE-2026-53552 (Goploy is an open-source automation deployment system. In versions 1.1 ...)
@@ -6926,6 +6956,7 @@ CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic v
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2vh6-hw4j-32ww
CVE-2026-82249 (gitoxide before 0.38.2 fails to validate carriage return characters in ...)
- rust-gix-credentials 0.39.1-1
+ [trixie] - rust-gix-credentials <no-dsa> (Minor issue)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6wr8-3w4h-j9wj
CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of gitoxide) allows writing fil ...)
- rust-gix-worktree-state <not-affected> (Only affects gix-worktree-state on Windows)
@@ -13652,10 +13683,12 @@ CVE-2026-12554 (Potential security vulnerabilities have been identified in HP Ea
NOT-FOR-US: HP
CVE-2026-10618 (Hugo's default fenced-code-block renderer writes attribute values take ...)
- hugo <unfixed> (bug #1146720)
+ [trixie] - hugo <no-dsa> (Minor issue)
NOTE: https://github.com/gohugoio/hugo/issues/15247
NOTE: https://github.com/gohugoio/hugo/commit/e4dc48cf7f8e06fc1e7e4c290dccc7c35d881c55
CVE-2026-10582 (Hugo's security.http.urls allowlist is the only control on outbound fe ...)
- hugo <unfixed> (bug #1146720)
+ [trixie] - hugo <no-dsa> (Minor issue)
NOTE: https://github.com/gohugoio/hugo/issues/15247
NOTE: https://github.com/gohugoio/hugo/commit/d6e6f9e500eebdeae8e28de830fff2e3bfc7d534
CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient granularity ...)
@@ -57426,12 +57459,14 @@ CVE-2026-49208 (Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 unt
NOT-FOR-US: Symfony UX
CVE-2026-48487 (Zeroconf is a pure Python implementation of multicast DNS service disc ...)
- python-zeroconf 0.149.16-1
+ [trixie] - python-zeroconf <no-dsa> (Minor issue)
NOTE: https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-qc2x-6f54-m6h9
NOTE: https://github.com/python-zeroconf/python-zeroconf/issues/1752
NOTE: https://github.com/python-zeroconf/python-zeroconf/pull/1756
NOTE: Fixed by: https://github.com/python-zeroconf/python-zeroconf/commit/544449596e645fcaad3834fa0cb614a54f847a82 (0.149.13)
CVE-2026-48045 (Zeroconf is a pure Python implementation of multicast DNS service disc ...)
- python-zeroconf 0.149.16-1
+ [trixie] - python-zeroconf <no-dsa> (Minor issue)
NOTE: https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9663-mqmp-p9mm
NOTE: https://github.com/python-zeroconf/python-zeroconf/pull/1751
NOTE: Fixed by: https://github.com/python-zeroconf/python-zeroconf/commit/b22c8ff19c66c68907d220a4823c0950f4fa93f7 (0.149.12)
@@ -57449,18 +57484,21 @@ CVE-2026-48008 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.
NOT-FOR-US: Shopware
CVE-2026-47184 (Zeroconf is a pure Python implementation of multicast DNS service disc ...)
- python-zeroconf 0.149.7-1
+ [trixie] - python-zeroconf <no-dsa> (Minor issue)
NOTE: https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-rfg2-pjw2-56x2
NOTE: https://github.com/python-zeroconf/python-zeroconf/issues/1715
NOTE: https://github.com/python-zeroconf/python-zeroconf/pull/1718
NOTE: Fixed by: https://github.com/python-zeroconf/python-zeroconf/commit/0ad3f37b5b852b8f614d322283d148efb2cef6e4 (0.149.7)
CVE-2026-47183 (Zeroconf is a pure Python implementation of multicast DNS service disc ...)
- python-zeroconf 0.149.6-1
+ [trixie] - python-zeroconf <no-dsa> (Minor issue)
NOTE: https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-phvx-9mgw-67r5
NOTE: https://github.com/python-zeroconf/python-zeroconf/issues/1714
NOTE: https://github.com/python-zeroconf/python-zeroconf/pull/1717
NOTE: Fixed by: https://github.com/python-zeroconf/python-zeroconf/commit/95561e28b24922358f1991e38e3a86d70d72dcec (0.149.6)
CVE-2026-47180 (Zeroconf is a pure Python implementation of multicast DNS service disc ...)
- python-zeroconf 0.149.6-1
+ [trixie] - python-zeroconf <no-dsa> (Minor issue)
NOTE: https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9pgc-3ccv-5297
NOTE: https://github.com/python-zeroconf/python-zeroconf/pull/1719
NOTE: Fixed by: https://github.com/python-zeroconf/python-zeroconf/commit/f9e23592137f30fdf7ef710dba065da31c79b1cf (0.149.5)
@@ -167580,6 +167618,7 @@ CVE-2026-22781 (TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win3
CVE-2026-22776 (cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTT ...)
[experimental] - cpp-httplib 0.41.0+ds-1
- cpp-httplib 0.41.0+ds-3 (bug #1126754)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h934-98h4-j43q
NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/2e2e47bab1ae6a853476eecbc4bf279dd1fef792 (0.30.1)
CVE-2026-22771 (Envoy Gateway is an open source project for managing Envoy Proxy as a ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -161,6 +161,8 @@ tomcat11
unbound
Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
--
+valkey
+--
vim
some of the issues seem worth fixing
Lee Garrett is interested in contributing an update for stable
@@ -174,3 +176,5 @@ wordpress
--
xorg-server (carnil)
--
+zlib
+--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59c79ea04b013149cd3e2e596b1d6163c60f1a73
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59c79ea04b013149cd3e2e596b1d6163c60f1a73
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/7c9011ac/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list