[Git][security-tracker-team/security-tracker][master] 5 commits: CVE-2018-19963/xen assigned for XSA-276

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c46e9882 by Salvatore Bonaccorso at 2018-12-08T07:42:43Z CVE-2018-19963/xen assigned for XSA-276 - - - - - 23168825 by Salvatore Bonaccorso at 2018-12-08T07:43:22Z CVE-2018-19964/xen assigned

[Git][security-tracker-team/security-tracker][master] CVE-2018-1996{1,2}/zen assigned for XSA-275

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ac99d3dd by Salvatore Bonaccorso at 2018-12-08T07:41:57Z CVE-2018-1996{1,2}/zen assigned for XSA-275 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2018-19788/policykit-1

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8214dcf5 by Salvatore Bonaccorso at 2018-12-08T07:37:40Z Add fixed version for CVE-2018-19788/policykit-1 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix source package name for jessie tagged entry in CVE-2018-19960

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2408eb1e by Salvatore Bonaccorso at 2018-12-08T07:29:54Z Fix source package name for jessie tagged entry in CVE-2018-19960 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] chromium dsa

2018-12-07 Thread Michael Gilbert
Michael Gilbert pushed to branch master at Debian Security Tracker / security-tracker Commits: ee251f58 by Michael Gilbert at 2018-12-08T01:40:49Z chromium dsa - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage lxml for jessie.

2018-12-07 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: ccfea9c1 by Chris Lamb at 2018-12-07T22:47:54Z data/dla-needed.txt: Triage lxml for jessie. - - - - - 94087d91 by Chris Lamb at 2018-12-07T22:47:58Z data/dla-needed.txt: Claim lxml. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Triage CVE-2018-19960 in onionshare for jessie LTS.

2018-12-07 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: cfcd67eb by Chris Lamb at 2018-12-07T22:46:24Z Triage CVE-2018-19960 in onionshare for jessie LTS. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 4 commits: Triage CVE-2018-4700 in cups for jessie LTS.

2018-12-07 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 26c4cf48 by Chris Lamb at 2018-12-07T22:38:11Z Triage CVE-2018-4700 in cups for jessie LTS. - - - - - 722eb247 by Chris Lamb at 2018-12-07T22:42:24Z data/dla-needed.txt: Triage qtsvg-opensource-src for

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-4700/cups

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: be4bdc92 by Salvatore Bonaccorso at 2018-12-07T20:46:41Z Add bug reference for CVE-2018-4700/cups - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update references for CVE-2018-4700/cups

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 08ba193c by Salvatore Bonaccorso at 2018-12-07T20:40:22Z Update references for CVE-2018-4700/cups - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2018-4700/cups as no-dsa

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5b40600e by Salvatore Bonaccorso at 2018-12-07T20:35:44Z Mark CVE-2018-4700/cups as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-4700/cups

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6ad775f9 by Salvatore Bonaccorso at 2018-12-07T20:29:49Z Add CVE-2018-4700/cups - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] stretch triage

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 023a7b50 by Moritz Muehlenhoff at 2018-12-07T20:09:18Z stretch triage mark sqlite3 as untermined for now, this could be entirely limited to Chromiums use of sqlite recheck once details are

[Git][security-tracker-team/security-tracker][master] fix one no-dsa entry

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ba9868ec by Moritz Muehlenhoff at 2018-12-07T18:36:47Z fix one no-dsa entry - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] stretch triage

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c7983a12 by Moritz Muehlenhoff at 2018-12-07T18:33:56Z stretch triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19935/php

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 84ead2e3 by Salvatore Bonaccorso at 2018-12-07T16:15:39Z Add CVE-2018-19935/php - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19960/onionshare

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a1a0f1fc by Salvatore Bonaccorso at 2018-12-07T15:52:33Z Add CVE-2018-19960/onionshare - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-16867/qemu

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 338be424 by Salvatore Bonaccorso at 2018-12-07T15:33:52Z Add bug reference for CVE-2018-16867/qemu - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Reference commit for CVE-2018-19489/qemu

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c47172b5 by Salvatore Bonaccorso at 2018-12-07T15:27:43Z Reference commit for CVE-2018-19489/qemu - - - - - 66d64421 by Salvatore Bonaccorso at 2018-12-07T15:27:44Z Reference fix for

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libphp-phpmailer update

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fc7e8288 by Salvatore Bonaccorso at 2018-12-07T14:38:47Z Reserve DSA number for libphp-phpmailer update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] okular fixed

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 004511d2 by Moritz Muehlenhoff at 2018-12-07T12:38:16Z okular fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] php7.3 fixed

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 923705d3 by Moritz Muehlenhoff at 2018-12-07T12:10:39Z php7.3 fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] mbedtls fixed

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e289ea82 by Moritz Muehlenhoff at 2018-12-07T12:09:00Z mbedtls fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] ufraw fixed

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 6348829a by Moritz Muehlenhoff at 2018-12-07T12:08:13Z ufraw fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla-needed update

2018-12-07 Thread Hugo Lefeuvre
(such as CVE-2017-8361) - NOTE: might be worth an upload in our case, especially because those have all been fixed in more - NOTE: recent versions, patches are not too complicated and we have more time + NOTE: 20181207: working on the next upload addressing older cves. + NOTE: also: most new cves

[Git][security-tracker-team/security-tracker][master] data/cve: CVE-2018-19432 dupe of CVE-2018-13139

2018-12-07 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ad71acb by Hugo Lefeuvre at 2018-12-07T11:24:39Z data/cve: CVE-2018-19432 dupe of CVE-2018-13139 see upstream bug report for more details - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2018-12-07 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ea69d420 by Moritz Muehlenhoff at 2018-12-07T10:41:03Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add ghostscript with note on regression

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b6cbc13 by Salvatore Bonaccorso at 2018-12-07T09:09:31Z Add ghostscript with note on regression We do not necessarly need to release a regression update here, but the fix should for sure be

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19869/qtsvg-opensource-src

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ba59311 by Salvatore Bonaccorso at 2018-12-07T08:56:30Z Add CVE-2018-19869/qtsvg-opensource-src - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19871/qtimageformats-opensource-src

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 990a22e3 by Salvatore Bonaccorso at 2018-12-07T08:52:27Z Add CVE-2018-19871/qtimageformats-opensource-src - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19870/qtbase-opensource-src

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d62cee68 by Salvatore Bonaccorso at 2018-12-07T08:48:55Z Add CVE-2018-19870/qtbase-opensource-src - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Add todo for CVE-2018-19865

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 62483968 by Salvatore Bonaccorso at 2018-12-07T08:43:57Z Add todo for CVE-2018-19865 - - - - - 9ca4558f by Salvatore Bonaccorso at 2018-12-07T08:47:08Z Add CVE-2018-19873/qtbase-opensource-src

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19865/qtvirtualkeyboard-opensource-src

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8afae19d by Salvatore Bonaccorso at 2018-12-07T08:37:52Z Add CVE-2018-19865/qtvirtualkeyboard-opensource-src - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 78806a41 by Salvatore Bonaccorso at 2018-12-07T08:23:54Z Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2018-1002105/kubernetes

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a11411f1 by Salvatore Bonaccorso at 2018-12-07T08:15:51Z Add Debian bug reference for CVE-2018-1002105/kubernetes - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-1993{1,2}/binutils

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e47d360 by Salvatore Bonaccorso at 2018-12-07T08:15:00Z Add CVE-2018-1993{1,2}/binutils - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 10bd0eaf by security tracker role at 2018-12-07T08:10:23Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update CVE-2018-19664/libjpeg-turbo as not-affected

2018-12-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a14b697 by Salvatore Bonaccorso at 2018-12-07T08:00:43Z Update CVE-2018-19664/libjpeg-turbo as not-affected - - - - - 1 changed file: - data/CVE/list Changes: