[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-1700/ceph as not affected for versions olde thatn 11.1.0 upstream

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d78a7c00 by Salvatore Bonaccorso at 2020-02-01T07:51:05+01:00 Mark CVE-2020-1700/ceph as not affected for versions olde thatn 11.1.0 upstream - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-1700/ceph

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e1298119 by Salvatore Bonaccorso at 2020-02-01T07:43:03+01:00 Add CVE-2020-1700/ceph - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-1719/wildfly

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 04c9e3a6 by Salvatore Bonaccorso at 2020-02-01T07:40:23+01:00 Add CVE-2020-1719/wildfly - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] take qemu/qt

2020-01-31 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b004bdd by Moritz Muehlenhoff at 2020-01-31T19:50:42-08:00 take qemu/qt - - - - - 1 changed file: - data/dsa-needed.txt Changes: = data/dsa-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2093-1 for firefox-esr

2020-01-31 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 127c6fdc by Emilio Pozuelo Monfort at 2020-02-01T04:44:59+01:00 Reserve DLA-2093-1 for firefox-esr - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2092-1 for qtbase-opensource-src

2020-01-31 Thread Mike Gabriel
-opensource-src (Mike Gabriel) - NOTE: 20200131: https://salsa.debian.org/qt-kde-team/qt/qtbase/merge_requests/12 --- radare2 NOTE: 20190816: Affected by CVE-2019-14745. Vulnerable code is in NOTE: libr/core/bin.c. Many no-dsa issues in Jessie and Stretch. View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libidn2 update

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 68fc5701 by Salvatore Bonaccorso at 2020-02-01T00:00:38+01:00 Reserve DSA number for libidn2 update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] prosody-modules DSA

2020-01-31 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e07e479d by Moritz Muehlenhoff at 2020-01-31T13:51:45-08:00 prosody-modules DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2091-1 for libjackson-json-java

2020-01-31 Thread Adrian Bunk
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 26beabef by Adrian Bunk at 2020-01-31T23:49:32+02:00 Reserve DLA-2091-1 for libjackson-json-java - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-18634/sudo as no-dsa for buster

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 96a12e61 by Salvatore Bonaccorso at 2020-01-31T22:38:59+01:00 Mark CVE-2019-18634/sudo as no-dsa for buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-7919/golang

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a7595d1 by Salvatore Bonaccorso at 2020-01-31T22:30:41+01:00 Add CVE-2020-7919/golang - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-18634: Add additional note on the 1.8.26 change for sudo

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bd010e7e by Salvatore Bonaccorso at 2020-01-31T22:05:42+01:00 CVE-2019-18634: Add additional note on the 1.8.26 change for sudo - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix typo in NOTE

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 67fd5f65 by Salvatore Bonaccorso at 2020-01-31T21:48:45+01:00 Fix typo in NOTE - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-18634/sudo

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ae203d33 by Salvatore Bonaccorso at 2020-01-31T21:45:08+01:00 Add Debian bug reference for CVE-2019-18634/sudo - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-8492: Group entries by source packages

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 875fe5de by Salvatore Bonaccorso at 2020-01-31T21:27:49+01:00 CVE-2020-8492: Group entries by source packages - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 4 commits: Tagged CVE-2020-8432 as ignored in jessie for u-boot following decision for stretch.

2020-01-31 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d042d8f8 by Ola Lundqvist at 2020-01-31T21:23:02+01:00 Tagged CVE-2020-8432 as ignored in jessie for u-boot following decision for stretch. - - - - - aece597c by Ola Lundqvist at

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-18634/sudo

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 28223c0d by Salvatore Bonaccorso at 2020-01-31T21:21:04+01:00 Update information on CVE-2019-18634/sudo - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ee03af7d by security tracker role at 2020-01-31T20:10:24+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] storebackup no-dsa

2020-01-31 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: baae8e76 by Moritz Muehlenhoff at 2020-01-31T11:21:20-08:00 storebackup no-dsa - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: take firefox-esr

2020-01-31 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b156fa5 by Emilio Pozuelo Monfort at 2020-01-31T17:27:28+01:00 dla: take firefox-esr - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim salt

2020-01-31 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: b36ecf0e by Mike Gabriel at 2020-01-31T16:25:57+01:00 data/dla-needed.txt: claim salt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Update comments for spamassassin

2020-01-31 Thread Mike Gabriel
: = data/dla-needed.txt = @@ -101,7 +101,8 @@ slurm-llnl NOTE: Regression found. (abhijith) -- spamassassin (Mike Gabriel) - NOTE: 20200131: Code not checked whether it is actually vulnerable since it likely is. + NOTE: 20200131: Code not checked

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add MR URL for qtbase-opensource-src.

2020-01-31 Thread Mike Gabriel
: = data/dla-needed.txt = @@ -75,6 +75,7 @@ python-reportlab (Hugo Lefeuvre) qemu (Utkarsh Gupta) -- qtbase-opensource-src (Mike Gabriel) + NOTE: 20200131: https://salsa.debian.org/qt-kde-team/qt/qtbase/merge_requests/12 -- radare2 NOTE

[Git][security-tracker-team/security-tracker][master] data/CVE/list: mark qtbase-opensource-src/jessie as not affected by CVE-2020-0570

2020-01-31 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: c1f58961 by Mike Gabriel at 2020-01-31T16:20:40+01:00 data/CVE/list: mark qtbase-opensource-src/jessie as not affected by CVE-2020-0570 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Four more CVEs for exiv2 were affecting only experimental

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: baf5bfa1 by Salvatore Bonaccorso at 2020-01-31T13:55:29+01:00 Four more CVEs for exiv2 were affecting only experimental More importantly those were then later on fixed in an upstream version

[Git][security-tracker-team/security-tracker][master] Update tracking for CVE-2018-14046/exiv2

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 49be85c1 by Salvatore Bonaccorso at 2020-01-31T13:47:31+01:00 Update tracking for CVE-2018-14046/exiv2 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update tracking for CVE-2018-17229 and CVE-2018-17230 in exiv2

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: db442333 by Salvatore Bonaccorso at 2020-01-31T13:43:51+01:00 Update tracking for CVE-2018-17229 and CVE-2018-17230 in exiv2 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add sudo to dsa-needed list

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: de21d7f9 by Salvatore Bonaccorso at 2020-01-31T13:01:30+01:00 Add sudo to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Take care of releasing DSA for spamassassin as prepared by noahm

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 31f05106 by Salvatore Bonaccorso at 2020-01-31T13:00:53+01:00 Take care of releasing DSA for spamassassin as prepared by noahm - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process more NFUs

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1b2ccf13 by Salvatore Bonaccorso at 2020-01-31T12:51:29+01:00 Process more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fd2def2 by Salvatore Bonaccorso at 2020-01-31T12:42:29+01:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: hiredis fixed in DLA-2083-1.

2020-01-31 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a15c740 by Chris Lamb at 2020-01-31T11:23:36+01:00 dla-needed.txt: hiredis fixed in DLA-2083-1. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: add qtbase-opensource-src and claim it

2020-01-31 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ff5b270 by Mike Gabriel at 2020-01-31T11:13:38+01:00 data/dla-needed.txt: add qtbase-opensource-src and claim it - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim spamassassin

2020-01-31 Thread Mike Gabriel
/dla-needed.txt = @@ -103,7 +103,7 @@ slurm-llnl NOTE: 20191125: up for testing https://people.debian.org/~abhijith/upload/slurm-llnl_14.03.9-5+deb8u5.dsc NOTE: Regression found. (abhijith) -- -spamassassin +spamassassin (Mike Gabriel) NOTE: 20200131

[Git][security-tracker-team/security-tracker][master] automatic update

2020-01-31 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e1de1610 by security tracker role at 2020-01-31T08:10:16+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list