[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-24790,puma: Mark as no-dsa for Stretch

2022-05-25 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 00630d0c by Markus Koschany at 2022-05-26T00:01:19+02:00 CVE-2022-24790,puma: Mark as no-dsa for Stretch Although all existing tests pass, the new test_requests_invalid tests never seem to finish.

[Git][security-tracker-team/security-tracker][master] Track fixes via experimental for nvidia-graphics-drivers-tesla-510 issues

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c5c0f11 by Salvatore Bonaccorso at 2022-05-25T23:47:04+02:00 Track fixes via experimental for nvidia-graphics-drivers-tesla-510 issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Try to clarify unimportant status for CVE-2022-29181

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ab8f18ba by Salvatore Bonaccorso at 2022-05-25T23:43:54+02:00 Try to clarify unimportant status for CVE-2022-29181 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1678/linux

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b87db4ed by Salvatore Bonaccorso at 2022-05-25T23:42:23+02:00 Add CVE-2022-1678/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add notes for CVE-2021-4261{2,3,4}/halibut

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 07211044 by Salvatore Bonaccorso at 2022-05-25T23:20:25+02:00 Add notes for CVE-2021-4261{2,3,4}/halibut Between 1.2 and 1.3 upstream an errorstate to track fatal errors was introduced. - - -

[Git][security-tracker-team/security-tracker][master] Adjust NOTE reference for CVE-2021-44974

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d48c3f27 by Salvatore Bonaccorso at 2022-05-25T22:14:54+02:00 Adjust NOTE reference for CVE-2021-44974 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fccec33d by security tracker role at 2022-05-25T20:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-1348/logrotate

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a7ba5157 by Salvatore Bonaccorso at 2022-05-25T21:58:20+02:00 Add Debian bug reference for CVE-2022-1348/logrotate - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1348/logrotate

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d34db2af by Salvatore Bonaccorso at 2022-05-25T21:45:15+02:00 Add CVE-2022-1348/logrotate - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1786/linux

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1774c89e by Salvatore Bonaccorso at 2022-05-25T21:16:41+02:00 Add CVE-2022-1786/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] chromium DSA

2022-05-25 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 319d33d4 by Moritz Mühlenhoff at 2022-05-25T20:27:58+02:00 chromium DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-29248/guzzle

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 05a9d326 by Salvatore Bonaccorso at 2022-05-25T18:08:06+02:00 Add CVE-2022-29248/guzzle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-1664/dpkg via unstable

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 40034b3c by Salvatore Bonaccorso at 2022-05-25T17:51:11+02:00 Track fixed version for CVE-2022-1664/dpkg via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3022-1 for dpkg

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 272d9d49 by Salvatore Bonaccorso at 2022-05-25T17:38:03+02:00 Reserve DLA-3022-1 for dpkg - - - - - 1 changed file: - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for dpkg update

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c175fda by Salvatore Bonaccorso at 2022-05-25T17:27:50+02:00 Reserve DSA number for dpkg update - - - - - 1 changed file: - data/DSA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reference upstream commits for CVE-2022-1664/dpkg

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ccf372f9 by Salvatore Bonaccorso at 2022-05-25T17:19:09+02:00 Reference upstream commits for CVE-2022-1664/dpkg - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1664/dpkg

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c5f7df41 by Salvatore Bonaccorso at 2022-05-25T17:08:15+02:00 Add CVE-2022-1664/dpkg - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process YottaDB CVEs

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: db85f774 by Neil Williams at 2022-05-25T15:59:09+01:00 Process YottaDB CVEs Confirmed with YottaDB upstream that YottaDB is built around a fork of FIS GT.M which is maintained separately from FIS.

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 43dfae96 by Neil Williams at 2022-05-25T15:54:43+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-42612,3,4/halibut 1.3-1

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: a9bff340 by Neil Williams at 2022-05-25T15:42:53+01:00 CVE-2021-42612,3,4/halibut 1.3-1 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] LTS: update subversion notes in dla-needed.txt

2022-05-25 Thread @roberto
d manually, appears to break multiple and possibly unrelated parts of the testsuite. (lamby) NOTE: 20220501: Done some analysis, worked on a patch, cannot find a way to test it, mailed results to Roberto C. Sánchez (enrico) + NOTE: 20220525: Based on the results of Enrico's analysis and so

[Git][security-tracker-team/security-tracker][master] add and claim cups

2022-05-25 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 16d199dc by Thorsten Alteholz at 2022-05-25T15:25:22+02:00 add and claim cups - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] new radare2 issues

2022-05-25 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 14505178 by Moritz Muehlenhoff at 2022-05-25T15:19:48+02:00 new radare2 issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-42248 golang-github-tidwall-gjson unfixed 1011616

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 03a7d97f by Neil Williams at 2022-05-25T11:46:13+01:00 CVE-2021-42248 golang-github-tidwall-gjson unfixed 1011616 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 34182988 by Neil Williams at 2022-05-25T11:39:57+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-4229/node-ua-parser-js not-affected, versions not uploaded

2022-05-25 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: bbb2773e by Neil Williams at 2022-05-25T11:24:36+01:00 CVE-2021-4229/node-ua-parser-js not-affected, versions not uploaded - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: add freerdp

2022-05-25 Thread Sylvain Beucler (@beuc)
= @@ -69,6 +69,9 @@ firmware-nonfree NOTE: 20210828: Most CVEs are difficult to backport. Contacted Ben regarding possible "ignore" tag NOTE: 20211207: Intend to release this week. -- +freerdp + NOTE: 20220525: ~40 minor CVEs, consider co

[Git][security-tracker-team/security-tracker][master] dla: add pjproject

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0debcbf2 by Sylvain Beucler at 2022-05-25T11:54:00+02:00 dla: add pjproject - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim redis.

2022-05-25 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 92010114 by Chris Lamb at 2022-05-25T10:32:16+01:00 data/dla-needed.txt: Claim redis. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim neutron.

2022-05-25 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 8eb002f6 by Chris Lamb at 2022-05-25T10:31:40+01:00 data/dla-needed.txt: Claim neutron. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-42218/ompl: stretch not-affected

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6048a85e by Sylvain Beucler at 2022-05-25T11:30:52+02:00 CVE-2021-42218/ompl: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] libxstream-java fixed in sid

2022-05-25 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 96b5e19b by Moritz Muehlenhoff at 2022-05-25T11:14:37+02:00 libxstream-java fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 32b23e7b by Salvatore Bonaccorso at 2022-05-25T10:49:19+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 324ae623 by Salvatore Bonaccorso at 2022-05-25T10:44:25+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] chromium fixed in sid

2022-05-25 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 65966f98 by Moritz Muehlenhoff at 2022-05-25T10:38:27+02:00 chromium fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f82c04c0 by security tracker role at 2022-05-25T08:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-21698/golang-github-prometheus-client-golang: stretch postponed

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 10ef6d47 by Sylvain Beucler at 2022-05-25T09:34:15+02:00 CVE-2022-21698/golang-github-prometheus-client-golang: stretch postponed - - - - - 20db17ba by Sylvain Beucler at 2022-05-25T09:44:10+02:00

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-23639/rust-crossbeam-utils via unstable

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aad31e88 by Salvatore Bonaccorso at 2022-05-25T08:12:03+02:00 Track fixed version for CVE-2022-23639/rust-crossbeam-utils via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fix via experimental for CVE-2021-27548 for now

2022-05-25 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f3fcbf5f by Salvatore Bonaccorso at 2022-05-25T08:09:49+02:00 Track fix via experimental for CVE-2021-27548 for now - - - - - 1 changed file: - data/CVE/list Changes: