[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 19:56:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
44be29dc by Salvatore Bonaccorso at 2026-09-06T20:54:05+02:00
Add Debian bug references for some issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -869,42 +869,42 @@ CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL Comma
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57166 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-9c8q-h38q-p85j
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/4472a31d77a7506ff175dad5abef490f4e31bed1
 CVE-2026-57165 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rpq9-9fx7-95xw
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/628b71638465bacf66e767959e6acbab822eccd6
 CVE-2026-57164 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-59fr-724j-6fjv
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/8d5956afab2ede95ddb199078dc19a8ac0114f3d
 CVE-2026-57163 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-jm2j-6rg6-qvwx
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/c4a151af86fadd16d9480b2603eeb2abf4fb4f78
 CVE-2026-57162 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-m9g3-jcj8-qjfm
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9
 CVE-2026-57161 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-xc62-j9h2-mp84
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/acc03b57cef7a7d31b8e1f5b9117437d7e87c591
 CVE-2026-57160 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
 CVE-2026-57159 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1146891)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-rfwg-w9gq-9mw2
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/673b978aab1fe3ab874247be32c871acc880cbeb
 CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
@@ -2696,19 +2696,19 @@ CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via `filter_ta
 CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal callback fo ...)
 	NOT-FOR-US: Joomla
 CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the notification  ...)
-	- ocsinventory-server <unfixed>
+	- ocsinventory-server <unfixed> (bug #1146890)
 	NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
 CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?f ...)
-	- ocsinventory-server <unfixed>
+	- ocsinventory-server <unfixed> (bug #1146890)
 	NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
 CVE-2026-76176 (SQL injection vulnerability in the endpoint /ocsreports/index.php?func ...)
-	- ocsinventory-server <unfixed>
+	- ocsinventory-server <unfixed> (bug #1146890)
 	NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
 CVE-2026-76175 (SQL injection vulnerability in the del_check parameter of the /ocsrepo ...)
-	- ocsinventory-server <unfixed>
+	- ocsinventory-server <unfixed> (bug #1146890)
 	NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
 CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload function ...)
-	- ocsinventory-server <unfixed>
+	- ocsinventory-server <unfixed> (bug #1146890)
 	NOTE: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng
 CVE-2026-75602 (OpenList a file list program that supports multiple storage. Prior to  ...)
 	NOT-FOR-US: OpenList



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44be29dc9901648dbf32039ef5cac73626fd599a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44be29dc9901648dbf32039ef5cac73626fd599a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/49039456/attachment.htm>


More information about the debian-security-tracker-commits mailing list