[Git][security-tracker-team/security-tracker][master] 3 commits: add ghostscript
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Thu Sep 24 18:21:41 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5872b3a0 by Thorsten Alteholz at 2026-09-24T19:21:27+02:00
add ghostscript
- - - - -
e8cab92b by Thorsten Alteholz at 2026-09-24T19:21:28+02:00
add network-manager-sstp and network-manager-vpnc
- - - - -
1f7d6838 by Thorsten Alteholz at 2026-09-24T19:21:29+02:00
mark CVE-2026-36849 as postponed for Bookworm
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -108040,6 +108040,7 @@ CVE-2026-53612 [Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c c
CVE-2026-36849 [Denial of Service via large SamplesPerPixel tag]
- tiff 4.7.1-3 (bug #1140300)
[trixie] - tiff <ignored> (Minor issue)
+ [bookworm] - tiff <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/17/1
NOTE: https://gitlab.com/libtiff/libtiff/-/work_items/781
NOTE: Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/eedba405d3695b52faae65994c5904f228eca0bf
=====================================
data/dla-needed.txt
=====================================
@@ -219,6 +219,9 @@ gh
NOTE: 20241230: Added by Security Team (carnil)
NOTE: 20260611: bookworm LTS handover.
--
+ghostscript
+ NOTE: 20260922: Added by Front-Desk (ta)
+--
gimp
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted image); TIM-loader
@@ -446,6 +449,12 @@ network-manager-l2tp
NOTE: 20260915: Added by Front-Desk (Beuc)
NOTE: 20260915: Follow DSA-6498-1 (3 CVEs) (Beuc/front-desk)
--
+network-manager-sstp
+ NOTE: 20260922: Added by Front-Desk (ta)
+--
+network-manager-vpnc
+ NOTE: 20260922: Added by Front-Desk (ta)
+--
node-dompurify
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8c3823a0ce4b2a26dce139df16bf9064cfb5a319...1f7d6838896a460c563a630871792a7e938b56b1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8c3823a0ce4b2a26dce139df16bf9064cfb5a319...1f7d6838896a460c563a630871792a7e938b56b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/10e3d35a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list