[Git][security-tracker-team/security-tracker][master] Add CVE-2020-706{1,2,3}/php issues

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1bfe14b6 by Salvatore Bonaccorso at 2020-02-28T06:50:42+01:00 Add CVE-2020-706{1,2,3}/php issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add assigned CVEs for wireshark

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c5dd026 by Salvatore Bonaccorso at 2020-02-28T06:42:13+01:00 Add assigned CVEs for wireshark - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2123-1 for pure-ftpd

2020-02-27 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 27445bec by Roberto C. Sánchez at 2020-02-27T18:54:56-05:00 Reserve DLA-2123-1 for pure-ftpd - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] update notes on CVE-2020-9274/pure-ftpd

2020-02-27 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: ef8e3564 by Roberto C. Sánchez at 2020-02-27T18:31:49-05:00 update notes on CVE-2020-9274/pure-ftpd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] update notes on CVE-2020-9274/pure-ftpd

2020-02-27 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: d691cbad by Roberto C. Sánchez at 2020-02-27T17:14:35-05:00 update notes on CVE-2020-9274/pure-ftpd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: Remove doubled note

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f87193fe by Salvatore Bonaccorso at 2020-02-27T23:06:05+01:00 Remove doubled note - - - - - 7b9943e8 by Salvatore Bonaccorso at 2020-02-27T23:06:53+01:00 Remove no-dsa tagged entry which got

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2122-1 for libusbmuxd

2020-02-27 Thread Dylan Aïssi
Dylan Aïssi pushed to branch master at Debian Security Tracker / security-tracker Commits: ffd4520e by Dylan Aïssi at 2020-02-27T23:04:38+01:00 Reserve DLA-2122-1 for libusbmuxd - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Changed python-bleach CVE from not-affected to ignored. Salvatore pointed out...

2020-02-27 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4176e72c by Ola Lundqvist at 2020-02-27T22:57:55+01:00 Changed python-bleach CVE from not-affected to ignored. Salvatore pointed out that it was a wrong conclusion but the fix is too invasive in

[Git][security-tracker-team/security-tracker][master] dla-needed: add and claim libusbmuxd

2020-02-27 Thread Dylan Aïssi
Dylan Aïssi pushed to branch master at Debian Security Tracker / security-tracker Commits: 98b3affb by Dylan Aïssi at 2020-02-27T22:37:12+01:00 dla-needed: add and claim libusbmuxd - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entry which got an update

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 265b5c86 by Salvatore Bonaccorso at 2020-02-27T22:29:02+01:00 Remove no-dsa tagged entry which got an update - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim pure-ftpd in dla-needed.txt

2020-02-27 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: a9e1cbcf by Roberto C. Sánchez at 2020-02-27T16:12:59-05:00 LTS: claim pure-ftpd in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream commit references for CVE-2020-704{1,2,3}/openfortivpn

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ddcca7c by Salvatore Bonaccorso at 2020-02-27T21:40:08+01:00 Add upstream commit references for CVE-2020-704{1,2,3}/openfortivpn - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-704{1,2,3}/openfortivpn

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 758085e0 by Salvatore Bonaccorso at 2020-02-27T21:37:28+01:00 Add CVE-2020-704{1,2,3}/openfortivpn - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ac04cbb3 by Salvatore Bonaccorso at 2020-02-27T21:33:23+01:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69bc2d44 by security tracker role at 2020-02-27T20:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Marked three vulnerabilities for wireshark as postponed.

2020-02-27 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 5ba438cf by Ola Lundqvist at 2020-02-27T20:43:47+01:00 Marked three vulnerabilities for wireshark as postponed. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2017-6363 marked as ignored for jessie following Debian Secutiry team.

2020-02-27 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 55b8e704 by Ola Lundqvist at 2020-02-27T20:30:55+01:00 CVE-2017-6363 marked as ignored for jessie following Debian Secutiry team. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2020-6802 as not affected for jessie. The vulnerable functionality...

2020-02-27 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: bcdf3a8a by Ola Lundqvist at 2020-02-27T20:08:51+01:00 Marked CVE-2020-6802 as not affected for jessie. The vulnerable functionality does not exist in this version. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Add reference to upstream issue for CVE-2020-1734/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4577d5d9 by Salvatore Bonaccorso at 2020-02-27T18:26:31+01:00 Add reference to upstream issue for CVE-2020-1734/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference to upstream issue for CVE-2020-1735/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 86c25213 by Salvatore Bonaccorso at 2020-02-27T18:24:36+01:00 Add reference to upstream issue for CVE-2020-1735/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference to upstream issue for CVE-2020-1736/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e9ca677 by Salvatore Bonaccorso at 2020-02-27T18:23:39+01:00 Add reference to upstream issue for CVE-2020-1736/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference to upstream issue for CVE-2020-1737/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 397268a0 by Salvatore Bonaccorso at 2020-02-27T18:22:40+01:00 Add reference to upstream issue for CVE-2020-1737/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream issue for CVE-2020-1738/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 970369f9 by Salvatore Bonaccorso at 2020-02-27T18:21:28+01:00 Add upstream issue for CVE-2020-1738/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream issue for CVE-2020-1739/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8292c91a by Salvatore Bonaccorso at 2020-02-27T18:20:34+01:00 Add upstream issue for CVE-2020-1739/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream issue for CVE-2020-1740/ansible

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c7ae754 by Salvatore Bonaccorso at 2020-02-27T18:19:23+01:00 Reference upstream issue for CVE-2020-1740/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-10064/wpa

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f135e512 by Salvatore Bonaccorso at 2020-02-27T17:53:24+01:00 Add CVE-2019-10064/wpa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] qtbase-opensource-src fixed

2020-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 510fadc8 by Moritz Muehlenhoff at 2020-02-27T16:48:33+01:00 qtbase-opensource-src fixed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2017-6363/libgd2

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0382a055 by Salvatore Bonaccorso at 2020-02-27T15:55:49+01:00 Add CVE-2017-6363/libgd2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2017-18640/snakeyaml

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c53a8c43 by Salvatore Bonaccorso at 2020-02-27T15:34:50+01:00 Add Debian bug reference for CVE-2017-18640/snakeyaml - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-18640/snakeyaml as no-dsa

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bb916022 by Salvatore Bonaccorso at 2020-02-27T15:17:57+01:00 Mark CVE-2017-18640/snakeyaml as no-dsa - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference mitigation commit for CVE-2017-18640/snakeyaml

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a2be2c0e by Salvatore Bonaccorso at 2020-02-27T15:03:07+01:00 Reference mitigation commit for CVE-2017-18640/snakeyaml - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] mark CVE-2020-9308 as not affected for Jessie, Stretch and Buster

2020-02-27 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: f2941bfa by Thorsten Alteholz at 2020-02-27T14:33:23+01:00 mark CVE-2020-9308 as not affected for Jessie, Stretch and Buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Revert "Update python-bleach TEMP-0951907-7D0FFB (#951907) to indicate jessie/stretch not affected"

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d5a1546f by Salvatore Bonaccorso at 2020-02-27T13:43:49+01:00 Revert Update python-bleach TEMP-0951907-7D0FFB (#951907) to indicate jessie/stretch not affected The code was several times

[Git][security-tracker-team/security-tracker][master] new wireshark issues

2020-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 020189d2 by Moritz Muehlenhoff at 2020-02-27T13:05:58+01:00 new wireshark issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-9274/pure-ftpd

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4964f4fa by Salvatore Bonaccorso at 2020-02-27T12:02:42+01:00 Add fixed version for CVE-2020-9274/pure-ftpd - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream commit for CVE-2015-9541/qtbase-opensource-src

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 84a74971 by Salvatore Bonaccorso at 2020-02-27T11:58:27+01:00 Add upstream commit for CVE-2015-9541/qtbase-opensource-src - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] new unimportant puppet issue

2020-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ec29d3b3 by Moritz Muehlenhoff at 2020-02-27T11:22:51+01:00 new unimportant puppet issue - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-8130/rake as no-dsa

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d61bfa32 by Salvatore Bonaccorso at 2020-02-27T11:02:21+01:00 Mark CVE-2020-8130/rake as no-dsa While there is a OS command injection issue here present, the attack surface is limited and

[Git][security-tracker-team/security-tracker][master] mojarra n/a

2020-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: fefc6f76 by Moritz Muehlenhoff at 2020-02-27T10:15:35+01:00 mojarra n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-9274/pure-ftpd

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f33fff4 by Salvatore Bonaccorso at 2020-02-27T09:39:02+01:00 Add Debian bug reference for CVE-2020-9274/pure-ftpd - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-9274/pure-ftpd

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f43a261 by Salvatore Bonaccorso at 2020-02-27T09:21:23+01:00 Add CVE-2020-9274/pure-ftpd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Process NFUs

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 426dfc1b by Salvatore Bonaccorso at 2020-02-27T09:12:13+01:00 Process NFUs - - - - - a3043933 by Salvatore Bonaccorso at 2020-02-27T09:19:46+01:00 Process some NFUs - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] automatic update

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c6503ba by security tracker role at 2020-02-27T08:10:13+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed versions for golang-go.crypto via unstable

2020-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 62f2fda3 by Salvatore Bonaccorso at 2020-02-27T09:05:19+01:00 Track fixed versions for golang-go.crypto via unstable - - - - - 1 changed file: - data/CVE/list Changes: