[Git][security-tracker-team/security-tracker][master] libgit2 0.27.0 based uploaded to unstable with 0.6 revision

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c4657ba by Salvatore Bonaccorso at 2018-07-18T06:30:01+02:00 libgit2 0.27.0 based uploaded to unstable with 0.6 revision - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2018-1000613,bouncycastle: Stretch is not affected

2018-07-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: edd00c55 by Markus Koschany at 2018-07-17T22:47:54+02:00 CVE-2018-1000613,bouncycastle: Stretch is not affected The XMSS/XMSS^MT algorithms were first introduced in version 1.57. - - - - - 1

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-1434{7,6}/libextractor

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 14811ea1 by Salvatore Bonaccorso at 2018-07-17T22:39:27+02:00 Add CVE-2018-1434{7,6}/libextractor - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14345/sddm

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fc870127 by Salvatore Bonaccorso at 2018-07-17T22:37:10+02:00 Add CVE-2018-14345/sddm - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] ffmpeg, blender DSA

2018-07-17 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 534a5d81 by Moritz Muehlenhoff at 2018-07-17T22:33:47+02:00 ffmpeg, blender DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add mutt to dsa-needed list (but not urgent for DSA)

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 628875cf by Salvatore Bonaccorso at 2018-07-17T22:32:41+02:00 Add mutt to dsa-needed list (but not urgent for DSA) - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14349/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 71e2aa9d by Salvatore Bonaccorso at 2018-07-17T22:31:12+02:00 Add CVE-2018-14349/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14350/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e14f724 by Salvatore Bonaccorso at 2018-07-17T22:30:08+02:00 Add CVE-2018-14350/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14351/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5101b609 by Salvatore Bonaccorso at 2018-07-17T22:28:42+02:00 Add CVE-2018-14351/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14352/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 066ff732 by Salvatore Bonaccorso at 2018-07-17T22:27:38+02:00 Add CVE-2018-14352/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14353/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0c60409c by Salvatore Bonaccorso at 2018-07-17T22:26:46+02:00 Add CVE-2018-14353/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update status of sympa in dla-needed.txt

2018-07-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ad6eeb7b by Markus Koschany at 2018-07-17T22:25:58+02:00 Update status of sympa in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2018-1000613,bouncycastle: Jessie is not affected

2018-07-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a2d71d08 by Markus Koschany at 2018-07-17T22:23:40+02:00 CVE-2018-1000613,bouncycastle: Jessie is not affected The XMSS/XMSS^MT algorithms were first introduced in BC = 1.57. - - - - - 14cabe44 by

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14354/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e9cb130 by Salvatore Bonaccorso at 2018-07-17T22:24:17+02:00 Add CVE-2018-14354/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14355/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fdff5ff8 by Salvatore Bonaccorso at 2018-07-17T22:23:06+02:00 Add CVE-2018-14355/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14356/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e92b5c3c by Salvatore Bonaccorso at 2018-07-17T22:21:54+02:00 Add CVE-2018-14356/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Drop unneeded reference (no substantial information)

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e281464 by Salvatore Bonaccorso at 2018-07-17T22:20:54+02:00 Drop unneeded reference (no substantial information) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14357/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 92c3c13a by Salvatore Bonaccorso at 2018-07-17T22:20:07+02:00 Add CVE-2018-14357/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14358/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 476df21f by Salvatore Bonaccorso at 2018-07-17T22:18:51+02:00 Add CVE-2018-14358/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14359/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 032f472e by Salvatore Bonaccorso at 2018-07-17T22:17:38+02:00 Add CVE-2018-14359/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14360/neomutt

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c7333915 by Salvatore Bonaccorso at 2018-07-17T22:16:17+02:00 Add CVE-2018-14360/neomutt - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14361/neomutt

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c756778b by Salvatore Bonaccorso at 2018-07-17T22:15:13+02:00 Add CVE-2018-14361/neomutt - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14362/{neomutt,mutt}

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 792ed86c by Salvatore Bonaccorso at 2018-07-17T22:14:17+02:00 Add CVE-2018-14362/{neomutt,mutt} - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14363/neomutt

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dd89d20d by Salvatore Bonaccorso at 2018-07-17T22:12:58+02:00 Add CVE-2018-14363/neomutt - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dc2fc7b0 by security tracker role at 2018-07-17T20:10:21+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-14337

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 39bbeec7 by Salvatore Bonaccorso at 2018-07-17T21:25:53+02:00 Add bug reference for CVE-2018-14337 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Remove reference to commit

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5aeaae0f by Salvatore Bonaccorso at 2018-07-17T20:43:33+02:00 Remove reference to commit This commit was not for CVE-2018-1000544. It was to fix another issue, upstream issue #315, but not the

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-100211/ruby-doorkeeper

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: afa76a8c by Salvatore Bonaccorso at 2018-07-17T20:39:32+02:00 Add bug reference for CVE-2018-100211/ruby-doorkeeper - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Wrap paragraph

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d61d1ef by Salvatore Bonaccorso at 2018-07-17T20:24:35+02:00 Wrap paragraph - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove superflous dot in CVE/list.

2018-07-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b501684 by Markus Koschany at 2018-07-17T20:15:01+02:00 Remove superflous dot in CVE/list. - - - - - 1 changed file: - data/CVE/list Changes: =

Processing e62bd1e928dca706e4a2d2b0cd317865a6282306 failed

2018-07-17 Thread security tracker role
The error message was: data/CVE/list:28200: expected package entry, got: '[jessie] - ruby-sanitize (Only occurs with libxml2 >= 2.9.2, jessie has 2.9.1).' Makefile:34: recipe for target 'all' failed make: *** [all] Error 1 ___

[Git][security-tracker-team/security-tracker][master] Add twitter-bootstrap and twitter-bootstrap3 to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: e62bd1e9 by Mike Gabriel at 2018-07-17T19:52:51+02:00 Add twitter-bootstrap and twitter-bootstrap3 to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes:

Processing 9401f1235a2261c82f9d0684e2ce1969042b2af3 failed

2018-07-17 Thread security tracker role
The error message was: data/CVE/list:28200: expected package entry, got: '[jessie] - ruby-sanitize (Only occurs with libxml2 >= 2.9.2, jessie has 2.9.1).' Makefile:34: recipe for target 'all' failed make: *** [all] Error 1 ___

[Git][security-tracker-team/security-tracker][master] 2 commits: data/CVE/list: Add commit that fixes CVE-2018-1000544 (ruby-zip).

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 8ccf2d71 by Mike Gabriel at 2018-07-17T19:33:46+02:00 data/CVE/list: Add commit that fixes CVE-2018-1000544 (ruby-zip). - - - - - 9401f123 by Mike Gabriel at 2018-07-17T19:34:20+02:00 Add ruby-zip to

Processing ebc66f79026e623c894cbce02ac99725e3b66733 failed

2018-07-17 Thread security tracker role
The error message was: data/CVE/list:28199: expected package entry, got: '[jessie] - ruby-sanitize (Only occurs with libxml2 >= 2.9.2, jessie has 2.9.1).' Makefile:34: recipe for target 'all' failed make: *** [all] Error 1 ___

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Ignore CVE-2018-3740 (ruby-sanitize) for jessie. Issue only…

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: ebc66f79 by Mike Gabriel at 2018-07-17T19:28:33+02:00 data/CVE/list: Ignore CVE-2018-3740 (ruby-sanitize) for jessie. Issue only occurs with libxml2 = 2.9.2. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Add vim-syntastic to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 52063535 by Mike Gabriel at 2018-07-17T19:16:10+02:00 Add vim-syntastic to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add twig to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 617d954c by Mike Gabriel at 2018-07-17T19:09:16+02:00 Add twig to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Tag CVE-2018-14329 as for htslib in [jessie]. Upstream…

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 465d0599 by Mike Gabriel at 2018-07-17T19:06:23+02:00 data/CVE/list: Tag CVE-2018-14329 as no-dsa for htslib in [jessie]. Upstream chose to ignore the issue and encounter it with user education. See

[Git][security-tracker-team/security-tracker][master] libpgobject-util-dbadmin-perl no-dsa

2018-07-17 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 6cc4d595 by Moritz Muehlenhoff at 2018-07-17T19:02:06+02:00 libpgobject-util-dbadmin-perl no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add yum-utils to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: e3b67335 by Mike Gabriel at 2018-07-17T18:58:54+02:00 Add yum-utils to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add giflib to dla-needed.txt (with comment).

2018-07-17 Thread Mike Gabriel
, rustc, cargo) which need some work. -- +giflib + NOTE: 20180717: As of today, no possible fix could be found for CVE-2018-11489 and + NOTE: 20180717: CVE-2018-11490 while triaging these issues. +-- git-annex NOTE: See #903037 for more information and a fix for Stretch. -- View it on GitLab

[Git][security-tracker-team/security-tracker][master] Add ruby2.1 to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c182f57 by Mike Gabriel at 2018-07-17T18:33:57+02:00 Add ruby2.1 to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add libtomcrypt to dla-needed.txt.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: b3759ab5 by Mike Gabriel at 2018-07-17T17:19:54+02:00 Add libtomcrypt to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Tag CVE-2017-17689 as for [jessie]. Wait for upstream…

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: e1f5c4c1 by Mike Gabriel at 2018-07-17T17:14:45+02:00 data/CVE/list: Tag CVE-2017-17689 as postponed for [jessie]. Wait for upstream release containing the fix. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Tag CVE-2018-14073 and CVE-2018-14072 as (both: libsixel). Minor issues.

2018-07-17 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 35f09210 by Mike Gabriel at 2018-07-17T17:08:39+02:00 data/CVE/list: Tag CVE-2018-14073 and CVE-2018-14072 as postponed (both: libsixel). Minor issues. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] claim libgit2

2018-07-17 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: df93055d by Thorsten Alteholz at 2018-07-17T13:35:05+02:00 claim libgit2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Process NFUs

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 60fcedf7 by Salvatore Bonaccorso at 2018-07-17T10:18:08+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c6b66da by Salvatore Bonaccorso at 2018-07-17T10:13:34+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14337/mruby

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 39dec6a7 by Salvatore Bonaccorso at 2018-07-17T10:12:40+02:00 Add CVE-2018-14337/mruby - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-14329/htslib

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c975d4b by Salvatore Bonaccorso at 2018-07-17T10:13:05+02:00 Add CVE-2018-14329/htslib - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2018-07-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 39fa51e1 by security tracker role at 2018-07-17T08:10:11+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Claim gpac

2018-07-17 Thread Brian May
Brian May pushed to branch master at Debian Security Tracker / security-tracker Commits: d8d2f6fd by Brian May at 2018-07-17T17:23:40+10:00 Claim gpac - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] stable triage

2018-07-17 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 617038f2 by Moritz Muehlenhoff at 2018-07-17T08:01:53+02:00 stable triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =