[Git][security-tracker-team/security-tracker][master] Add CVE-2018-12404/nss

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fd92cce1 by Salvatore Bonaccorso at 2018-12-11T07:21:15Z Add CVE-2018-12404/nss - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] two PHP issues unimportant

2018-12-10 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d06707b9 by Moritz Muehlenhoff at 2018-12-10T21:44:51Z two PHP issues unimportant - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] php DSA

2018-12-10 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 605a9ca6 by Moritz Muehlenhoff at 2018-12-10T21:34:49Z php DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f447b405 by Salvatore Bonaccorso at 2018-12-10T20:38:28Z Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove product association from CVE-2017-1000500

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f5019891 by Salvatore Bonaccorso at 2018-12-10T20:21:04Z Remove product association from CVE-2017-1000500 It turned out to be a reservation duplicate of the assigned CVE-2017-12161. - - - - -

[Git][security-tracker-team/security-tracker][master] Remove notes for CVE-2016-8489

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a4756596 by Salvatore Bonaccorso at 2018-12-10T20:19:56Z Remove notes for CVE-2016-8489 This was a reservation duplicate of CVE-2016-10242 and in concequence REJECTed. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-15889/libpodofo

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2606cc57 by Salvatore Bonaccorso at 2018-12-10T20:18:16Z Add bug reference for CVE-2018-15889/libpodofo - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS/php5 status update

2018-12-10 Thread Roberto C . Sánchez
-needed.txt = @@ -94,6 +94,7 @@ pdns-recursor (Abhijith PA) NOTE: 20181203: Affected by same vulnerability as pdns -- php5 (Roberto C. Sánchez) + NOTE: 20181210: Upstream released 5.6.39 just a few days ago, that version will be packaged (roberto) -- polarssl

[Git][security-tracker-team/security-tracker][master] automatic update

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8fe99f21 by security tracker role at 2018-12-10T20:10:21Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2018-6352/libpodofo

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cd0fe072 by Salvatore Bonaccorso at 2018-12-10T20:05:29Z Add fixed version for CVE-2018-6352/libpodofo The fix for CVE-2018-5296 limited the number of objects to 8388607 according to the

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-5783

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: af8f20ac by Salvatore Bonaccorso at 2018-12-10T16:30:08Z Add bug reference for CVE-2018-5783 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Adjust status for CVE-2018-6392/libav

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3f82c226 by Salvatore Bonaccorso at 2018-12-10T15:54:52Z Adjust status for CVE-2018-6392/libav - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Fix status for CVE-2018-6621 and mark it as removed as the status was triaged

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cedb4dbe by Salvatore Bonaccorso at 2018-12-10T15:52:10Z Fix status for CVE-2018-6621 and mark it as removed as the status was triaged - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix CVE-2018-6912/libav: Add status as removed

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6a3398df by Salvatore Bonaccorso at 2018-12-10T15:51:23Z Fix CVE-2018-6912/libav: Add status as removed - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 4 commits: CVE-2018,6912,libav: Jessie is not affected.

2018-12-10 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 37817c4c by Markus Koschany at 2018-12-10T14:03:56Z CVE-2018,6912,libav: Jessie is not affected. Vulnerable code is not present. - - - - - ab22ff3c by Markus Koschany at 2018-12-10T14:12:13Z

[Git][security-tracker-team/security-tracker][master] mark CVE-2018-19628 as not-affected for Jessie

2018-12-10 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 1bb604b0 by Thorsten Alteholz at 2018-12-10T14:14:25Z mark CVE-2018-19628 as not-affected for Jessie - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim ghostscript

2018-12-10 Thread Lucas Kanashiro
Lucas Kanashiro pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e797263 by Lucas Kanashiro at 2018-12-10T12:31:07Z data/dla-needed.txt: claim ghostscript - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Triage CVE-2018-19842 in radare2 for jessie LTS.

2018-12-10 Thread Chris Lamb
= @@ -107,8 +107,6 @@ qemu qtsvg-opensource-src NOTE: 20181210: Needs more investigation around related packages/upstream etc. (lamby) -- -radare2 --- samba (Emilio Pozuelo) NOTE: 20181203: regression in upstream fix, waiting for confirmed regression fix -- View

[Git][security-tracker-team/security-tracker][master] Add two new mxml issues: CVE-2018-20004 and CVE-2018-20005

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7913fce4 by Salvatore Bonaccorso at 2018-12-10T09:17:11Z Add two new mxml issues: CVE-2018-20004 and CVE-2018-20005 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-20002/binutils

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 66b695e4 by Salvatore Bonaccorso at 2018-12-10T09:13:43Z Add CVE-2018-20002/binutils - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-20001/libav

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f73c1a52 by Salvatore Bonaccorso at 2018-12-10T09:12:02Z Add CVE-2018-20001/libav - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFU

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1aed2478 by Salvatore Bonaccorso at 2018-12-10T09:10:57Z Process NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Unclaim qtsvg-opensource-src; needs further work/waiting on upstream etc.

2018-12-10 Thread Chris Lamb
: = data/dla-needed.txt = @@ -104,7 +104,8 @@ policykit-1 (Santiago) -- qemu -- -qtsvg-opensource-src (Chris Lamb) +qtsvg-opensource-src + NOTE: 20181210: Needs more investigation around related packages/upstream etc. (lamby) -- radare2

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-16876/ansible

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 58d43ce2 by Salvatore Bonaccorso at 2018-12-10T09:08:10Z Add bug reference for CVE-2018-16876/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1604-1 for lxml

2018-12-10 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 71a0b2f9 by Chris Lamb at 2018-12-10T08:43:42Z Reserve DLA-1604-1 for lxml - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2018-12-10 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9f9159f9 by security tracker role at 2018-12-10T08:10:17Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list