[Git][security-tracker-team/security-tracker][master] dla: take 3

2020-08-17 Thread Adrian Bunk
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 4658c06b by Adrian Bunk at 2020-08-18T08:56:27+03:00 dla: take 3 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] LTS: Update status of CVE-2020-13631/sqlite3 for stretch

2020-08-17 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ecfee3e by Roberto C. Sánchez at 2020-08-17T19:19:09-04:00 LTS: Update status of CVE-2020-13631/sqlite3 for stretch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: Update status of CVE-2020-9327/sqlite3 for stretch

2020-08-17 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: b4b4808e by Roberto C. Sánchez at 2020-08-17T18:58:43-04:00 LTS: Update status of CVE-2020-9327/sqlite3 for stretch - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Remove no-dsa entries for upcoming imagemagick release.

2020-08-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b6aaba24 by Markus Koschany at 2020-08-18T00:35:56+02:00 Remove no-dsa entries for upcoming imagemagick release. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix DLA/list entry for imagemagick. Whitespace was missing.

2020-08-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fc929a70 by Markus Koschany at 2020-08-18T00:23:30+02:00 Fix DLA/list entry for imagemagick. Whitespace was missing. - - - - - 1 changed file: - data/DLA/list Changes:

Processing 66a90d93e3c781b25d725f9f4c3f56e80a05f5c1 failed

2020-08-17 Thread security tracker role
The error message was: data/DLA/list:2: invalid cross reference 'CVE-2019-13297CVE-2019-11470' make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-l

[Git][security-tracker-team/security-tracker][master] CVE-2019-13305,imagemagick: Fixed in 8:6.9.7.4+dfsg-11+deb9u8

2020-08-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 66a90d93 by Markus Koschany at 2020-08-18T00:19:45+02:00 CVE-2019-13305,imagemagick: Fixed in 8:6.9.7.4+dfsg-11+deb9u8 This issue was fixed by DSA-4715-1 but apparently it was missing from the annou

Processing 150174dbc2efc09a92a505d5b51880d9e66bf310 failed

2020-08-17 Thread security tracker role
The error message was: data/DLA/list:2: invalid cross reference 'CVE-2019-13297CVE-2019-11470' make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-l

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2333-1 for imagemagick

2020-08-17 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 150174db by Markus Koschany at 2020-08-18T00:15:49+02:00 Reserve DLA-2333-1 for imagemagick - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] LTS: Update status of CVE-2019-19645/sqlite3 for stretch

2020-08-17 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: a3a58056 by Roberto C. Sánchez at 2020-08-17T18:13:48-04:00 LTS: Update status of CVE-2019-19645/sqlite3 for stretch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2332-1 for sane-backends

2020-08-17 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ae181ea3 by Sylvain Beucler at 2020-08-17T22:44:37+02:00 Reserve DLA-2332-1 for sane-backends - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2020-08-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4bf2cf7d by security tracker role at 2020-08-17T20:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] ghostscript: add upstream version, distinguish CVEs in common patch

2020-08-17 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f6eb9ee9 by Sylvain Beucler at 2020-08-17T16:50:59+02:00 ghostscript: add upstream version, distinguish CVEs in common patch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: update status of sqlite3

2020-08-17 Thread Roberto C . Sánchez
: = data/dla-needed.txt = @@ -170,6 +170,7 @@ software-properties -- sqlite3 (Roberto C. Sánchez) NOTE: 20200712: Vulnerable to at least CVE-2020-13630. (lamby) + NOTE: 20200817: New CVEs have appeared. Working on those now. (roberto) -- squid3 (Markus Koschany

[Git][security-tracker-team/security-tracker][master] Unclaim apache2 for the moment & add notes

2020-08-17 Thread Utkarsh Gupta
NOTE: 20200808: Seems affected by CVE-2020-9490, CVE-2020-11993 +apache2 + NOTE: 20200808: Seems affected by CVE-2020-9490, CVE-2020-11993 (abhijith) + NOTE: 20200817: Too intrusive. Re-visit back later -> experimenting fixes for ELTS. (utkarsh) -- ark (Abhijith PA) NOTE: 20200731: given

[Git][security-tracker-team/security-tracker][master] Take ruby-*

2020-08-17 Thread Utkarsh Gupta
= @@ -145,11 +145,11 @@ qtbase-opensource-src -- ruby-doorkeeper -- -ruby-json-jwt +ruby-json-jwt (Utkarsh Gupta) -- ruby-kaminari (Chris Lamb) -- -ruby-rack-cors +ruby-rack-cors (Utkarsh Gupta) NOTE: 20200817: Was fixed in DLA-2096-1 for jessie LTS but is now re

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage ruby-rack-cors for stretch LTS (CVE-2019-18978)

2020-08-17 Thread Chris Lamb
: = data/dla-needed.txt = @@ -149,6 +149,9 @@ ruby-json-jwt -- ruby-kaminari (Chris Lamb) -- +ruby-rack-cors + NOTE: 20200817: Was fixed in DLA-2096-1 for jessie LTS but is now re-vulnerable again in stretch LTS AFAICT. (lamby) +-- samba

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage ruby-doorkeeper for stretch LTS (CVE-2020-10187)

2020-08-17 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: a5be2722 by Chris Lamb at 2020-08-17T11:55:29+01:00 data/dla-needed.txt: Triage ruby-doorkeeper for stretch LTS (CVE-2020-10187) - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim ruby-kaminari.

2020-08-17 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: e21cee13 by Chris Lamb at 2020-08-17T11:54:58+01:00 data/dla-needed.txt: Claim ruby-kaminari. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage ruby-json-jwt for stretch LTS (CVE-2019-18848)

2020-08-17 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 281097ff by Chris Lamb at 2020-08-17T11:54:22+01:00 data/dla-needed.txt: Triage ruby-json-jwt for stretch LTS (CVE-2019-18848) - - - - - 1 changed file: - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage ruby-kaminari for stretch LTS (CVE-2020-11082)

2020-08-17 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 31cec9fa by Chris Lamb at 2020-08-17T11:53:48+01:00 data/dla-needed.txt: Triage ruby-kaminari for stretch LTS (CVE-2020-11082) - - - - - 1 changed file: - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] automatic update

2020-08-17 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7b63bbb8 by security tracker role at 2020-08-17T08:10:14+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2331-1 for posgresql-9.6

2020-08-17 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 0fc35c50 by Emilio Pozuelo Monfort at 2020-08-17T10:03:42+02:00 Reserve DLA-2331-1 for posgresql-9.6 - - - - - 1 changed file: - data/DLA/list Changes: =