[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 07:48:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
30613d23 by Moritz Muehlenhoff at 2026-09-24T08:48:14+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -698,6 +698,7 @@ CVE-2026-62985 (request-filtering-agent is an http(s).Agent implementation that
NOT-FOR-US: Node request-filtering-agent
CVE-2026-62364 (wlc is a Weblate command-line client using Weblate's REST API. Prior t ...)
- wlc <unfixed>
+ [trixie] - wlc <no-dsa> (Minor issue)
NOTE: https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc
NOTE: https://github.com/WeblateOrg/wlc/pull/1500
NOTE: https://github.com/WeblateOrg/wlc/commit/055fd2d43d0f72418b459286245330f08176db62 (2.0.1)
@@ -2494,6 +2495,7 @@ CVE-2026-94107 (NivoCart through 2.4.0 contains a predictable password reset tok
NOT-FOR-US: NivoCart
CVE-2026-94106 (getID3 before 1.9.26 contains an OS command injection vulnerability in ...)
- php-getid3 1.9.26+dfsg-1 (bug #1148666)
+ [trixie] - php-getid3 <no-dsa> (Minor issue)
NOTE: https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
NOTE: https://github.com/JamesHeinrich/getID3/issues/503
NOTE: https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6 (v1.9.26)
=====================================
data/dsa-needed.txt
=====================================
@@ -23,6 +23,8 @@ amd64-microcode (carnil)
bouncycastle
possibly move to 1.85 for trixie
--
+buildstream
+--
cacti
probably best to move to 1.2.31
--
@@ -80,7 +82,7 @@ kitty
libheif (aron)
Wait until new upstream release lands in sid
--
-libreoffice
+libreoffice (jmm)
--
linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
@@ -105,6 +107,8 @@ network-manager-sstp
network-manager-vpnc
no upstream fix yet, if totally dead removal is an option
--
+ntfs-3g
+--
nodejs (jmm)
Bastien Roucaries posted debdiff for review
--
@@ -179,8 +183,7 @@ valkey (aron)
--
varnish
--
-vlc
- wait for 3.0.24
+vlc (jmm)
--
vim
some of the issues seem worth fixing
@@ -199,3 +202,5 @@ xz-utils
--
zlib (carnil)
--
+zookeeper
+--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30613d2342336dd617c120db87cb07bcd46e33d0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30613d2342336dd617c120db87cb07bcd46e33d0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/c3054fbb/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list