{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2025/cve-2025-67746-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-14T15:39:44Z",
      "generator": {
        "date": "2026-09-14T15:39:44Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-67746-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2025-12-30T16:15:00Z",
      "revision_history": [
        {
          "date": "2025-12-30T16:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-14T15:39:44Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-67746"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "composer-0:2.0.9-2+deb11u4.all",
                "product": {
                  "name": "composer-0:2.0.9-2+deb11u4.all",
                  "product_id": "composer-0:2.0.9-2+deb11u4.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/composer@2.0.9-2%2Bdeb11u4?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
                "product": {
                  "name": "composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
                  "product_id": "composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/composer@2.0.9-2%2Bdeb11u4%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "composer-0:2.0.9-2+deb11u4+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:composer-0:2.0.9-2+deb11u4+tuxcare.els1.all"
        },
        "product_reference": "composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "composer-0:2.0.9-2+deb11u4.all as a component of Debian 11",
          "product_id": "Debian-11:composer-0:2.0.9-2+deb11u4.all"
        },
        "product_reference": "composer-0:2.0.9-2+deb11u4.all",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-67746",
      "cwe": {
        "id": "CWE-74",
        "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to confusion or DoS of the terminal application. There is no proven exploit and this has thus a low severity but we still publish a CVE as it has potential for abuse, and we want to be on the safe side informing users that they should upgrade. Versions 2.2.26 and 2.9.3 contain a patch for the issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
          "Debian-11:composer-0:2.0.9-2+deb11u4.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-67746"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917",
          "url": "https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/commit/5db1876a76fdef76d3c4f8a27995c434c7a43e71",
          "url": "https://github.com/composer/composer/commit/5db1876a76fdef76d3c4f8a27995c434c7a43e71"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/releases/tag/2.2.26",
          "url": "https://github.com/composer/composer/releases/tag/2.2.26"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/releases/tag/2.9.3",
          "url": "https://github.com/composer/composer/releases/tag/2.9.3"
        },
        {
          "category": "external",
          "summary": "https://github.com/composer/composer/security/advisories/GHSA-59pp-r3rg-353g",
          "url": "https://github.com/composer/composer/security/advisories/GHSA-59pp-r3rg-353g"
        }
      ],
      "release_date": "2025-12-30T16:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-07T14:46:08.788637Z",
          "details": "This vulnerability only enables ANSI control-sequence injection into Composer’s terminal output, producing garbled text or a transient terminal hang without any confidentiality or integrity impact and no code execution. Exploitation also requires that an attacker already control a remote package source contacted by Composer, a non-trivial prerequisite outside the target host. Given this narrow, non-persistent, DoS-only effect and dependence on a compromised upstream, it can be safely deprioritized in enterprise VM/server environments.",
          "product_ids": [
            "Debian-11:composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
            "Debian-11:composer-0:2.0.9-2+deb11u4.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Debian-11:composer-0:2.0.9-2+deb11u4+tuxcare.els1.all",
            "Debian-11:composer-0:2.0.9-2+deb11u4.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}