Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d2d1bc2e by Moritz Muehlenhoff at 2026-08-20T23:01:43+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1643,12 +1643,14 @@ CVE-2026-64850 (Grav is a file-based Web platform.
Prior to 2.0.7, Grav Blueprin
NOT-FOR-US: Grav CMS
CVE-2026-63652 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
- freerdp3 3.28.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9g22-w2gr-vcmp
NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
NOTE: Fixed by:
https://github.com/FreeRDP/FreeRDP/commit/caf653c0ba1c75ec8f298d1baa59770102a5d14c
(3.28.0)
CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
- freerdp3 3.28.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq
NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
@@ -1659,6 +1661,7 @@ CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav
CMS that provides full
NOT-FOR-US: Grav plugin
CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
- freerdp3 3.28.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v64m-xxfw-hrv6
NOTE: https://github.com/FreeRDP/FreeRDP/pull/12980
@@ -2013,9 +2016,9 @@ CVE-2026-76048 (A flaw has been found in SourceCodester
Simple Online Food Order
CVE-2026-76032 (Pydio Cells 5.0.0 through 5.0.2 returns share-link details to
any auth ...)
NOT-FOR-US: Pydio Cells
CVE-2026-76014 (A vulnerability has been found in BusyBox up to 1.30.1. This
vulnerabi ...)
- - busybox <unfixed>
+ - busybox <unfixed> (unimportant)
NOTE: https://github.com/mirror/busybox/issues/124
- TODO: check details, reported as issue on github mirror
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-76008 (A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects
the fun ...)
NOT-FOR-US: Comfast
CVE-2026-76004 (A security vulnerability has been detected in UTT HiPER 1250GW
up to 3 ...)
@@ -4135,6 +4138,7 @@ CVE-2026-15571 (A flaw was found in the legacy
client-initiated account-linking
- keycloak <itp> (bug #1088287)
CVE-2026-75900 (An out-of-bounds read vulnerability was found in swtpm's
SWTPM_NVRAM_C ...)
- swtpm <unfixed> (bug #1144810)
+ [trixie] - swtpm <no-dsa> (Minor issue)
NOTE: https://github.com/stefanberger/swtpm/pull/1155
NOTE: Fixed by:
https://github.com/stefanberger/swtpm/commit/dc5f5ee3d8261a4d9814ad5da69164a118822401
(master)
NOTE: Fixed by:
https://github.com/stefanberger/swtpm/commit/afc9e512a0459b12776e8fa509cfa039908c6be6
(v0.10.2)
@@ -4718,6 +4722,7 @@ CVE-2026-73692
REJECTED
CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From
0.2.0 unt ...)
- golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64
(v0.144.0)
CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for
everyday w ...)
@@ -5237,6 +5242,7 @@ CVE-2026-23938 (An authenticated administrator is able to
crash Zabbix server or
NOTE: https://support.zabbix.com/browse/ZBX-28075
CVE-2026-23937 (The Zabbix API host.get action can be exploited by
authenticated users ...)
- zabbix <unfixed> (bug #1144945)
+ [trixie] - zabbix <no-dsa> (Minor issue)
NOTE: https://support.zabbix.com/browse/ZBX-28074
CVE-2026-23935 (A Zabbix administrator is able to read out of bounds memory by
utilizi ...)
- zabbix <unfixed> (bug #1144946)
@@ -5983,6 +5989,7 @@ CVE-2026-19998 (A weakness has been identified in
code-projects Online Shopping
NOT-FOR-US: code-projects
CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent
directory ...)
- node-extract-zip <unfixed> (bug #1144934)
+ [trixie] - node-extract-zip <no-dsa> (Minor issue)
NOTE: https://github.com/max-mapper/extract-zip/pull/160
CVE-2026-18674 (On a Kong Mesh global control plane, resources received over
the zone- ...)
TODO: check
=====================================
data/dsa-needed.txt
=====================================
@@ -36,12 +36,16 @@ cups
--
dulwich
--
+emacs (jmm)
+--
erlang (aron)
--
firebird3.0
--
firebird4.0
--
+freecad
+--
gimp
--
gst-plugins-bad1.0 (jmm)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2d1bc2e641d526996d0d1246c1f4399f000cf5b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2d1bc2e641d526996d0d1246c1f4399f000cf5b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits