[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 11:09:14 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
07bde5cc by Moritz Muehlenhoff at 2026-09-24T12:09:03+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -169,9 +169,10 @@ CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 627f
CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8 ...)
NOT-FOR-US: sfturing hosp_order
CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's uncompress ...)
- - gimp <unfixed>
+ - gimp <unfixed> (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/108c72aab28fe069129ad0e545d6b97de5c0ce2f
+ NOTE: Crash in GUI tool, no security impact
CVE-2026-96545 (An out-of-bounds heap read flaw was found in GIMP's TIM image loader. ...)
- gimp <unfixed>
[trixie] - gimp <not-affected> (Vulnerable code not present)
@@ -2971,6 +2972,7 @@ CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2. A
NOT-FOR-US: x-ui
CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execu ...)
- xiphos 4.4.0+dfsg1-1
+ [trixie] - xiphos <no-dsa> (Minor issue)
NOTE: https://github.com/crosswire/xiphos/pull/1314
NOTE: https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a
NOTE: Fixed by: https://github.com/crosswire/xiphos/commit/f96ad3273277e7fb24908b40f3aa1e9efeeb4e85 (4.4.0)
@@ -35772,10 +35774,10 @@ CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or esca
CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from the mult ...)
NOT-FOR-US: DB-GPT
CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
- - gimp 3.2.6-1 (bug #1145871)
- [trixie] - gimp <no-dsa> (Minor issue)
+ - gimp 3.2.6-1 (bug #1145871; unimportant)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16583
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/e78fe7ae2a8d3341f6e862c0426265791d5975e6 (GIMP_3_2_6)
+ NOTE: Crash in GUI tool, no security impact
CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. ...)
NOT-FOR-US: TOTOLINK
CVE-2026-79911 (A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7 ...)
@@ -695168,11 +695170,11 @@ CVE-2020-11023 (In jQuery versions greater than or equal to 1.0.3 and before 3.5
[buster] - node-jquery <no-dsa> (Minor issue)
- otrs2 6.0.30-1
[stretch] - otrs2 <ignored> (Non-free not supported)
- - znc 1.10.3-1 (bug #1145369)
+ - znc 1.10.3-1 (bug #1145369; unimportant)
NOTE: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6
NOTE: https://www.drupal.org/sa-core-2020-002
NOTE: https://otrs.com/release-notes/otrs-security-advisory-2020-14/
- NOTE: https://wiki.znc.in/ChangeLog/1.10.3
+ NOTE: https://wiki.znc.in/ChangeLog/1.10.3 (but negligible security impact)
CVE-2020-11022 (In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from unt ...)
{DSA-4693-1 DLA-3551-1 DLA-2608-1}
- jquery <removed>
@@ -695184,12 +695186,12 @@ CVE-2020-11022 (In jQuery starting with 1.12.0 and before 3.5.0, passing HTML fr
[jessie] - drupal7 <not-affected> (Vulnerable code not embedded)
- otrs2 6.0.30-1
[stretch] - otrs2 <ignored> (Non-free not supported)
- - znc 1.10.3-1 (bug #1145369)
+ - znc 1.10.3-1 (bug #1145369; unimportant)
NOTE: https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2
NOTE: https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77
NOTE: https://www.drupal.org/sa-core-2020-002
NOTE: https://otrs.com/release-notes/otrs-security-advisory-2020-14/
- NOTE: https://wiki.znc.in/ChangeLog/1.10.3
+ NOTE: https://wiki.znc.in/ChangeLog/1.10.3 (but negligible security impact)
CVE-2020-11021 (Actions Http-Client (NPM @actions/http-client) before version 1.0.8 ca ...)
NOT-FOR-US: Actions Http-Client
CVE-2020-11020 (Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1. ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -123,6 +123,8 @@ pacemaker
pdfminer (carnil)
Required followup for CVE-2025-64512 as original fix was incomplete.
--
+php8.4
+--
podman
--
prometheus
@@ -179,6 +181,8 @@ tomcat10
--
tomcat11
--
+tor
+--
valkey (aron)
--
varnish
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07bde5cc8d95f9e0b924ab210bb137793d79c762
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07bde5cc8d95f9e0b924ab210bb137793d79c762
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/ae2755ee/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list