[Git][security-tracker-team/security-tracker][master] Add new assigned libheif issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 07:51:42 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a99e2bac by Salvatore Bonaccorso at 2026-09-19T08:49:48+02:00
Add new assigned libheif issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -322,21 +322,33 @@ CVE-2026-84975 (PJSIP is a free and open source multimedia communication library
NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-382p-87mh-r3q8
NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/43d3bd77bb6833eab4c493503b8d564a754ddfdd
CVE-2026-84449 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
- TODO: check
+ - libheif 1.19.7-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-2c3g-p585-8rpq
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e29953da30eb11aa1762df0bff3b36be4b22fbe3 (v1.19.6)
CVE-2026-84448 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
- TODO: check
+ - libheif 1.23.2-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p58j-h3vm-3fp5
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/646d85fbf5bd18fc3cdc516e915e59072de2d510 (v1.23.2)
CVE-2026-84447 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 ...)
- TODO: check
+ - libheif 1.23.2-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-x8xm-cm2c-cfc8
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/30b52a4e829efe0ee6d7208e8500b99f664af5e9 (v1.23.2)
CVE-2026-84446 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
- TODO: check
+ - libheif 1.23.2-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-xw34-mjcp-jqh8
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/3a7a69ae325f652e48c026b8241ab25bedf44d9b (v1.23.2)
CVE-2026-84444 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
- TODO: check
+ - libheif 1.23.2-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e65071f59a1ac08aa1eb0d07a831deaf6bb4d03b (v1.23.2)
CVE-2026-84400 (CareCam CM2507 IP cameras contain an insufficiently protected network ...)
TODO: check
CVE-2026-84398 (CM2507 IP cameras accept an empty password for a privileged account ex ...)
TODO: check
CVE-2026-84384 (libheif is a HEIF and AVIF file format decoder and encoder. From 1.19. ...)
- TODO: check
+ - libheif 1.23.2-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w
+ NOTE: Fixed by: https://github.com/strukturag/libheif/commit/21893e8f66c8b79363ca2809391b07d35e1a95ec (v1.23.2)
CVE-2026-83561 (The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-81946 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a99e2bac9062fcee205f67154969d1eab48edb82
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a99e2bac9062fcee205f67154969d1eab48edb82
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/77479f40/attachment.htm>
More information about the debian-security-tracker-commits
mailing list