[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 6 19:56:02 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
44be29dc by Salvatore Bonaccorso at 2026-09-06T20:54:05+02:00
Add Debian bug references for some issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -869,42 +869,42 @@ CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL Comma
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57166 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-9c8q-h38q-p85j
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/4472a31d77a7506ff175dad5abef490f4e31bed1
CVE-2026-57165 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rpq9-9fx7-95xw
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/628b71638465bacf66e767959e6acbab822eccd6
CVE-2026-57164 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-59fr-724j-6fjv
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/8d5956afab2ede95ddb199078dc19a8ac0114f3d
CVE-2026-57163 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-jm2j-6rg6-qvwx
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/c4a151af86fadd16d9480b2603eeb2abf4fb4f78
CVE-2026-57162 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-m9g3-jcj8-qjfm
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9
CVE-2026-57161 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-xc62-j9h2-mp84
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/acc03b57cef7a7d31b8e1f5b9117437d7e87c591
CVE-2026-57160 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
CVE-2026-57159 (PJSIP is a free and open source multimedia communication library writt ...)
- pjproject <removed>
- - asterisk <unfixed>
+ - asterisk <unfixed> (bug #1146891)
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rfwg-w9gq-9mw2
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/673b978aab1fe3ab874247be32c871acc880cbeb
CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. ...)
@@ -2696,19 +2696,19 @@ CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via `filter_ta
CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal callback fo ...)
NOT-FOR-US: Joomla
CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the notification ...)
- - ocsinventory-server <unfixed>
+ - ocsinventory-server <unfixed> (bug #1146890)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?f ...)
- - ocsinventory-server <unfixed>
+ - ocsinventory-server <unfixed> (bug #1146890)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
CVE-2026-76176 (SQL injection vulnerability in the endpoint /ocsreports/index.php?func ...)
- - ocsinventory-server <unfixed>
+ - ocsinventory-server <unfixed> (bug #1146890)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
CVE-2026-76175 (SQL injection vulnerability in the del_check parameter of the /ocsrepo ...)
- - ocsinventory-server <unfixed>
+ - ocsinventory-server <unfixed> (bug #1146890)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload function ...)
- - ocsinventory-server <unfixed>
+ - ocsinventory-server <unfixed> (bug #1146890)
NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
CVE-2026-75602 (OpenList a file list program that supports multiple storage. Prior to ...)
NOT-FOR-US: OpenList
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44be29dc9901648dbf32039ef5cac73626fd599a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44be29dc9901648dbf32039ef5cac73626fd599a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/49039456/attachment.htm>
More information about the debian-security-tracker-commits
mailing list