[Git][security-tracker-team/security-tracker][master] Update status for unrealircd CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 13 09:08:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
15aa501a by Salvatore Bonaccorso at 2026-09-13T10:06:10+02:00
Update status for unrealircd CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4,7 +4,7 @@ CVE-2026-90678 (An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.
 	- haproxy <not-affected> (Vulnerable code introduced later)
 	NOTE: Fixed by: http://git.haproxy.org/?p=haproxy.git;a=commit;h=86a4ebc761a278838e8cb06f3a292282ba704c65 (v3.5-dev6)
 CVE-2026-90668 (The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not  ...)
-	TODO: check
+	- unrealircd <itp> (bug #1039021)
 CVE-2026-90651 (Socket Firewall (socketdev/socket-registry-firewall) in registry mode  ...)
 	TODO: check
 CVE-2026-90648 (wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in som ...)
@@ -409912,7 +409912,7 @@ CVE-2023-6885 (A vulnerability was found in Tongda OA 2017 up to 11.10. It has b
 CVE-2023-50965 (In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStati ...)
 	NOT-FOR-US: MicroHttpServer
 CVE-2023-50784 (A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 befo ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 CVE-2023-6890 (Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpm ...)
 	NOT-FOR-US: phpmyfaq
 CVE-2023-6889 (Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpm ...)
@@ -829778,7 +829778,7 @@ CVE-2017-1002150 (python-fedora 0.8.0 and lower is vulnerable to an open redirec
 	[jessie] - python-fedora <no-dsa> (Minor issue)
 	NOTE: https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929.patch
 CVE-2017-13649 (UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privil ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 CVE-2017-13648 (In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the ...)
 	- graphicsmagick 1.3.27-1 (unimportant)
 	NOTE: https://sourceforge.net/p/graphicsmagick/bugs/433/
@@ -877380,7 +877380,7 @@ CVE-2016-7141 (curl and libcurl before 7.50.2, when built with NSS and the libns
 CVE-2016-7145 (The m_authenticate function in ircd/m_authenticate.c in nefarious2 all ...)
 	NOT-FOR-US: Nefarious 2
 CVE-2016-7144 (The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3 ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 	NOTE: https://www.openwall.com/lists/oss-security/2016/09/04/3
 	NOTE: unrealircd reportedly vulnerable, and ircd-seven reportedly not vulnerable
 CVE-2016-7143 (The m_authenticate function in modules/m_sasl.c in Charybdis before 3. ...)
@@ -941025,7 +941025,7 @@ CVE-2013-7386 (Format string vulnerability in the PROJECT::write_account_file fu
 CVE-2013-7385 (LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator pa ...)
 	NOT-FOR-US: LiveZilla
 CVE-2013-7384 (UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a d ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 CVE-2014-3840 (Multiple cross-site scripting (XSS) vulnerabilities in apps/common/tem ...)
 	- mayan <itp> (bug #718580)
 CVE-2014-3801 (OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, ...)
@@ -953736,7 +953736,7 @@ CVE-2013-6414 (actionpack/lib/action_view/lookup_context.rb in Action View in Ru
 	- rails <not-affected> (vulnerable code not present)
 	NOTE: Starting with 2.3.14.1 rails is a transition package
 CVE-2013-6413 (Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allo ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 	NOTE: http://forums.unrealircd.com/viewtopic.php?f=2&t=8221
 CVE-2013-6412 (The transform_save function in transform.c in Augeas 1.0.0 through 1.1 ...)
 	{DLA-28-1}
@@ -1009226,7 +1009226,7 @@ CVE-2009-4895 (Race condition in the tty_fasync function in drivers/char/tty_io.
 CVE-2009-4894 (Multiple cross-site scripting (XSS) vulnerabilities in profile.php in  ...)
 	NOT-FOR-US: PunBB
 CVE-2009-4893 (Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::opt ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 CVE-2010-2265 (Cross-site scripting (XSS) vulnerability in the GetServerName function ...)
 	NOT-FOR-US: Microsoft Windows
 CVE-2010-2264 (The Cascading Style Sheets (CSS) implementation in WebKit in Apple Saf ...)
@@ -1009743,7 +1009743,7 @@ CVE-2010-2077
 CVE-2010-2076 (Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before  ...)
 	NOT-FOR-US: Apache CXF
 CVE-2010-2075 (UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from Novemb ...)
-	- unrealircd <itp> (bug #515130)
+	- unrealircd <itp> (bug #1039021)
 CVE-2010-2074 (istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_se ...)
 	- w3m 0.5.2-5 (low; bug #587445)
 	[lenny] - w3m 0.5.2-2+lenny1
@@ -1076802,7 +1076802,7 @@ CVE-2006-1216 (Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms
 CVE-2006-1215 (Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burnin ...)
 	NOT-FOR-US: Woltlab BB
 CVE-2006-1214 (UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denia ...)
-	NOT-FOR-US: UnrealIRCd
+	- unrealircd <itp> (bug #1039021)
 CVE-2006-1213 (JiRo's Banner System Experience and Professional 1.0 and earlier allow ...)
 	NOT-FOR-US: JiRo's Banner System Experience and Professional
 CVE-2006-1212 (Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows r ...)
@@ -1097349,7 +1097349,7 @@ CVE-2004-0681 (Multiple cross-site scripting (XSS) vulnerabilities in (1) comers
 CVE-2004-0680 (Zoom X3 ADSL modem has a terminal running on port 254 that can be acce ...)
 	NOT-FOR-US: Zoom DSL modem
 CVE-2004-0679 (The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly othe ...)
-	NOT-FOR-US: UnrealIRCd
+	- unrealircd <itp> (bug #1039021)
 CVE-2004-0678 (Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Plan ...)
 	NOT-FOR-US: 12Planet Chat Server
 CVE-2004-0677 (Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attac ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/15aa501ab03d800147803de25156a6834f8fb09f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/15aa501ab03d800147803de25156a6834f8fb09f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/4b1d44d5/attachment.htm>


More information about the debian-security-tracker-commits mailing list