[Git][security-tracker-team/security-tracker][master] Track fixed version for glib-networking issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 12:55:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7cf2076b by Salvatore Bonaccorso at 2026-09-19T13:44:17+02:00
Track fixed version for glib-networking issues
Two CVEs had a typo in the year in the debian/changelog file as
uploaded, they are CVE-2025-60018 and CVE-2025-60019 and fixed as well
with the 2.90.0-1 upload.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -115473,7 +115473,7 @@ CVE-2026-2128 (The Breeze plugin for WordPress is vulnerable to Exposure of Sens
CVE-2026-10044 (Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary fil ...)
NOT-FOR-US: Usagi-org ai-goofish-monitor
CVE-2026-10028 (A flaw was found in glib-networking. A remote attacker can exploit thi ...)
- - glib-networking <unfixed> (bug #1138235)
+ - glib-networking 2.90.0-1 (bug #1138235)
[trixie] - glib-networking <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - glib-networking <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - glib-networking <postponed> (Minor issue)
@@ -174444,7 +174444,7 @@ CVE-2026-2604 (A flaw was found in evolution-data-server. Inconsistent compariso
CVE-2026-2575 (A flaw was found in Keycloak. An unauthenticated remote attacker can t ...)
- keycloak <itp> (bug #1088287)
CVE-2026-2574
- - glib-networking <unfixed> (unimportant)
+ - glib-networking 2.90.0-1 (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/228
NOTE: OpenSSL backend disabled by default upstream and in Debian
CVE-2026-2474 (Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable t ...)
@@ -229438,13 +229438,13 @@ CVE-2025-10036 (The Featured Image from URL (FIFU) plugin for WordPress is vulne
CVE-2025-60249 (vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and u ...)
NOT-FOR-US: vulnerability-lookup
CVE-2025-60019 (glib-networking's OpenSSL backend fails to properly check the return v ...)
- - glib-networking <unfixed> (bug #1116429; unimportant)
+ - glib-networking 2.90.0-1 (bug #1116429; unimportant)
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/227
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/263
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/70df675dd4f5e4a593b2f95406c1aac031aa8bc7
NOTE: OpenSSL backend disabled by default upstream and in Debian
CVE-2025-60018 (glib-networking's OpenSSL backend fails to properly check the return v ...)
- - glib-networking <unfixed> (bug #1116430; unimportant)
+ - glib-networking 2.90.0-1 (bug #1116430; unimportant)
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/226
NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/262
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/4dd540505d40babe488404f3174ec39f49a84485
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/8ffc27b8/attachment.htm>
More information about the debian-security-tracker-commits
mailing list