{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2025/cve-2025-67746-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-18T16:44:38Z",
      "generator": {
        "date": "2026-08-18T16:44:38Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-67746-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2025-12-30T16:15:00Z",
      "revision_history": [
        {
          "date": "2025-12-30T16:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-18T16:44:38Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-67746"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "composer-0:1.8.4-1+deb10u4.all",
                "product": {
                  "name": "composer-0:1.8.4-1+deb10u4.all",
                  "product_id": "composer-0:1.8.4-1+deb10u4.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/composer@1.8.4-1%2Bdeb10u4?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
                "product": {
                  "name": "composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
                  "product_id": "composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/composer@1.8.4-1%2Bdeb10u4%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "composer-0:1.8.4-1+deb10u4+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:composer-0:1.8.4-1+deb10u4+tuxcare.els1.all"
        },
        "product_reference": "composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "composer-0:1.8.4-1+deb10u4.all as a component of Debian 10",
          "product_id": "Debian-10:composer-0:1.8.4-1+deb10u4.all"
        },
        "product_reference": "composer-0:1.8.4-1+deb10u4.all",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-67746",
      "cwe": {
        "id": "CWE-74",
        "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to confusion or DoS of the terminal application. There is no proven exploit and this has thus a low severity but we still publish a CVE as it has potential for abuse, and we want to be on the safe side informing users that they should upgrade. Versions 2.2.26 and 2.9.3 contain a patch for the issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
          "Debian-10:composer-0:1.8.4-1+deb10u4.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-67746"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917",
          "url": "https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/commit/5db1876a76fdef76d3c4f8a27995c434c7a43e71",
          "url": "https://github.com/composer/composer/commit/5db1876a76fdef76d3c4f8a27995c434c7a43e71"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/releases/tag/2.2.26",
          "url": "https://github.com/composer/composer/releases/tag/2.2.26"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/releases/tag/2.9.3",
          "url": "https://github.com/composer/composer/releases/tag/2.9.3"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/security/advisories/GHSA-59pp-r3rg-353g",
          "url": "https://github.com/composer/composer/security/advisories/GHSA-59pp-r3rg-353g"
        }
      ],
      "release_date": "2025-12-30T16:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-31T18:44:47.611125Z",
          "details": "CVE-2025-67746 only allows ANSI control sequences from an attacker-controlled package source to mangle the terminal output of Composer commands, with no effect on dependency integrity, no code execution, and no confidentiality impact. Because exploitation requires the environment to be explicitly configured to fetch from a repository or VCS URL the attacker controls and the outcome is limited to transient terminal confusion/DoS, it is a low-priority risk for centrally managed Linux servers and VMs.",
          "product_ids": [
            "Debian-10:composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
            "Debian-10:composer-0:1.8.4-1+deb10u4.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Debian-10:composer-0:1.8.4-1+deb10u4+tuxcare.els1.all",
            "Debian-10:composer-0:1.8.4-1+deb10u4.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}