External check

2014-09-22 Thread Raphael Geissert
CVE-2014-3640: RESERVED CVE-2014-3655: RESERVED -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was run. -- To UNSUBSCRIBE, email to

Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-22 Thread Raphael Hertzog
Hello, I'm in the process of reviewing open CVE in oldstable and deciding whether it must be added to dla-needed.txt or not. I have multiple questions: 1/ is there a page on the security tracker that lists packages with open vulnerabilities in stable/oldstable which are neither unimportant, nor

Re: Guidance on no-dsa and adding entries to dsa/dla-needed.txt

2014-09-22 Thread Holger Levsen
Hi Raphael, thanks for your work on triaging oldstable related CVEs! On Montag, 22. September 2014, Raphael Hertzog wrote: 1/ is there a page on the security tracker that lists packages with open vulnerabilities in stable/oldstable which are neither unimportant, nor marked no-dsa and not

Bug#762069: marked as done (security-tracker does not update NVD information anymore)

2014-09-22 Thread Debian Bug Tracking System
Your message dated Mon, 22 Sep 2014 19:14:23 +0200 with message-id 20140922171423.GA26721@eldamar.local and subject line Re: Bug#762069: security-tracker does not update NVD information anymore has caused the Debian Bug report #762069, regarding security-tracker does not update NVD information

Bug#742382: Display oldstable/stable security and olstable-lts repositories in tabular view. (Closes: #742382)

2014-09-22 Thread Holger Levsen
Hi, On Montag, 22. September 2014, Christoph Biedl wrote: While the new appearence of the security tracker is a *huge* improvemnt, both in information details and design, thanks for that, thanks! As a suggestion for the above issue: + squeeze, squeeze (security) 5.04-5+squeeze5 [gray]No

Bug#642987: EOL-support patch updated, to apply against new checkboxes code

2014-09-22 Thread Holger Levsen
Hi, see mail subject and attached file. [00:53] h01ger | buxy: i have a patch to display end-of-life too, #642987 - i just dont like abusing urgency for it as i do. i'd rather have florians db remodelling.. but I might still commit this one to svn, as perfect is the enemy of good also

Processed: merge

2014-09-22 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 762288 wishlist Bug #762288 [security-tracker] security-tracker: available versions table is unnecessary Severity set to 'wishlist' from 'normal' merge 761963 762288 Bug #761963 [security-tracker] security-tracker: consolidate