Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
84b2201d by Moritz Muehlenhoff at 2026-08-22T23:23:35+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -46,12 +46,15 @@ CVE-2026-75866 (Punk::OAuth2::Server versions through 0.03 
for Perl issue access
        NOT-FOR-US: Punk::OAuth2::Server Perl module
 CVE-2026-71514 (NLTK 3.9.4 through 3.10.2 contains a path traversal 
vulnerability in C ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab 
(v3.10.3-rc1)
 CVE-2026-71513 (NLTK before 3.10.3 contains a remote code execution 
vulnerability in A ...)
        - nltk <unfixed>
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea 
(v3.10.3-rc1)
 CVE-2026-70626 (NLTK versions before 3.9.4 contain a symlink escape 
vulnerability in C ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
 CVE-2026-6258
        REJECTED
@@ -77,31 +80,40 @@ CVE-2026-66916 (Joomla Extension - joomgalleryfriends.net - 
Password-Protected C
        NOT-FOR-US: Joomla
 CVE-2026-66393 (NLTK versions before 3.9.4 contain an unbounded recursion 
vulnerabilit ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw
 CVE-2026-65915 (NLTK versions before 3.10.0 contain a logic bug in 
FileSystemPathPoint ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9
 CVE-2026-63312 (NLTK before 3.10.0 contains an arbitrary local file read 
vulnerability ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
 CVE-2026-63311 (NLTK before 3.10.0 (affected versions <= 3.9.4) contains a 
server-side ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839
 CVE-2026-63310 (NLTK before 3.9.3 fails to verify file integrity after 
downloading pac ...)
        - nltk 3.9.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q
 CVE-2026-62388 (NLTK versions before 3.10.0 default to ENFORCE=False in 
pathsec.py, ca ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
 CVE-2026-62385 (NLTK versions before 3.10.0 contain a path traversal 
vulnerability in  ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
 CVE-2026-62384 (NLTK versions before 3.10.2 contain a symlink-based sandbox 
bypass in  ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv
        NOTE: CVE exists because it is possible to bypass the fix for 
CVE-2026-12074
 CVE-2026-62383 (nltk versions before 3.10.2 contain a symlink-based arbitrary 
file rea ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
 CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an 
improper au ...)
        NOT-FOR-US: PasswordPusher
@@ -780,6 +792,7 @@ CVE-2026-77413 (JSONata is a JSON query and transformation 
language. Prior to 1.
        NOT-FOR-US: jsonata-js
 CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 
0.124.0 u ...)
        - golang-github-getkin-kin-openapi <unfixed>
+       [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
        [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-xhj3-7xw9-vr34
@@ -800,6 +813,7 @@ CVE-2026-77000 (The WP Social Media Login WordPress plugin 
through 1.0.6 does no
        NOT-FOR-US: WordPress plugin
 CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 
0.10.0 un ...)
        - golang-github-getkin-kin-openapi <unfixed>
+       [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
        [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-mmfr-pmjx-hw9w
@@ -1345,6 +1359,7 @@ CVE-2026-56875
        REJECTED
 CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
        - capstone <unfixed>
+       [trixie] - capstone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
        NOTE: https://github.com/capstone-engine/capstone/pull/2968
        NOTE: Fixed by: 
https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
 (6.0.0-Alpha10)
@@ -1352,6 +1367,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In 
6.0.0-Alpha9 and earlier
        NOTE: Fixed by: 
https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed
 (v5 branch)
 CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
        - capstone <unfixed>
+       [trixie] - capstone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
        NOTE: https://github.com/capstone-engine/capstone/pull/2968
        NOTE: Fixed by: 
https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e
 (6.0.0-Alpha10)
@@ -1424,6 +1440,7 @@ CVE-2026-49217 (Mailu is a mail server as a set of Docker 
images. Prior to versi
        NOT-FOR-US: Mailu
 CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function 
builds the ex ...)
        - onnx <unfixed>
+       [trixie] - onnx <no-dsa> (Minor issue)
        NOTE: 
https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
 CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder 
(XmlBuilder module ...)
        NOT-FOR-US: joshnuss xml_builder
@@ -2228,6 +2245,7 @@ CVE-2026-19586 (A pre-authentication OS command injection 
vulnerability has been
        NOT-FOR-US: TPLink
 CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could 
exploit  ...)
        - libvirt <unfixed> (bug #1145069)
+       [trixie] - libvirt <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/903
        NOTE: Introduced with: 
https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b
 (v1.2.6-rc1)
        NOTE: Fixed by: 
https://gitlab.com/libvirt/libvirt/-/commit/5a62cbf2907d4590283597b46da9c0f41e7b4d4f
@@ -2364,6 +2382,7 @@ CVE-2026-16922 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 
4.1 could allow a loca
        NOT-FOR-US: IBM
 CVE-2026-15743 (Catalyst::Plugin::Static::Simple versions through 0.38 for 
Perl mark r ...)
        - libcatalyst-plugin-static-simple-perl 0.38-1
+       [trixie] - libcatalyst-plugin-static-simple-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42860527/
        NOTE: 
https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple/pull/3
        NOTE: 
https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch
@@ -3496,15 +3515,19 @@ CVE-2026-66596 (Unauthenticated Cross Site Scripting 
(XSS) in Newsletter <= 9.3.
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can 
place a f ...)
        - nnn <unfixed>
+       [trixie] - nnn <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can 
createa direc ...)
        - nnn <unfixed>
+       [trixie] - nnn <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only 
represent value ...)
        - nnn <unfixed>
+       [trixie] - nnn <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to 
lack of v ...)
        - nnn <unfixed>
+       [trixie] - nnn <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
 CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
        NOT-FOR-US: Grav plugin
@@ -6246,6 +6269,7 @@ CVE-2026-75107 (Grav Form Plugin before 9.1.19 fails to 
escape field-definition
        NOT-FOR-US: Grav plugin
 CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet 
length fi ...)
        - bluez 5.87-2 (bug #1144961)
+       [trixie] - bluez <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
        NOTE: Followup: 
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
@@ -7006,6 +7030,7 @@ CVE-2026-50167 (Kurrier is a modern, self-hosted 
workspace for email, calendar,
        NOT-FOR-US: Kurrier
 CVE-2026-50161 (libre is a generic library for real-time communications with 
asynchron ...)
        - libre <unfixed>
+       [trixie] - libre <no-dsa> (Minor issue)
        NOTE: 
https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h
        NOTE: https://github.com/baresip/re/pull/1584
        NOTE: Fixed by: 
https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8 
(v4.8.1)
@@ -13363,6 +13388,7 @@ CVE-2025-7639 (The vulnerability, if exploited, could 
allow an authenticated mis
        NOT-FOR-US: AVEVA
 CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect 
vulnerability in t ...)
        - golang-github-go-chi-chi 5.2.3-1
+       [trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
        [bookworm] - golang-github-go-chi-chi <ignored> (Minor issue; out of 
LTS support)
        [bullseye] - golang-github-go-chi-chi <ignored> (Minor issue; out of 
LTS support)
        NOTE: 
https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93
@@ -16004,6 +16030,7 @@ CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for 
Perl allow memory exhaus
        NOTE: Fixed by: 
https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27db676fd1ca671fbb31208a22c1b1ba9724
 (0.23)
 CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting 
vulnerab ...)
        - python-tablib 3.10.0-1
+       [trixie] - python-tablib <no-dsa> (Minor issue)
        NOTE: https://github.com/jazzband/tablib/pull/668
        NOTE: Fixed by: 
https://github.com/jazzband/tablib/commit/b0ff39fb9b2f457e5332249b4cc2ec11eabf46ee
 (v3.10.0)
 CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -65,6 +65,8 @@ jupyterlab
 --
 kamailio
 --
+libapache2-mod-auth-openidc (jmm)
+--
 libdbi-perl (carnil)
 --
 libde265



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84b2201d14f42b9fce769d24b11d4f4cf19ebbed

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84b2201d14f42b9fce769d24b11d4f4cf19ebbed
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to