[Git][security-tracker-team/security-tracker][master] 3 commits: The PoC given is not reproducible in buster but this CVE is an

2024-03-10 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 376c6d8e by Abhijith PA at 2024-03-11T10:41:16+05:30 The PoC given is not reproducible in buster but this CVE is an general issue from an incomplete fix from 4.0.10. But too invasive patch for a minor

[Git][security-tracker-team/security-tracker][master] Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f95d3ce8 by Ola Lundqvist at 2024-03-10T23:20:12+01:00 Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster. - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed runc from dla-needed since no CVEs remain to be fixed.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f20876c2 by Ola Lundqvist at 2024-03-10T23:07:51+01:00 Removed runc from dla-needed since no CVEs remain to be fixed. - - - - - e722a127 by Ola Lundqvist at 2024-03-10T23:09:22+01:00 Reverted

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 82315a7e by Salvatore Bonaccorso at 2024-03-10T21:24:22+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9d71cfe5 by security tracker role at 2024-03-10T20:12:25+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version for azure-uamqp-python issues

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: da44f932 by Salvatore Bonaccorso at 2024-03-10T20:48:25+01:00 Track fixed version for azure-uamqp-python issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2024-28757/expat

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9ec7fda0 by Salvatore Bonaccorso at 2024-03-10T20:44:30+01:00 Track fixed version via unstable for CVE-2024-28757/expat - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim expat in dla-needed.txt

2024-03-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 60343264 by Tobias Frost at 2024-03-10T20:13:31+01:00 LTS: claim expat in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: release claim on nss in dla-needed.txt

2024-03-10 Thread Tobias Frost (@tobi)
, nova and cinder. (lamby) -- -nss (tobi) +nss NOTE: 20240121: Added by Front-Desk (apo) NOTE: 20240310: CVE-2023-6135: Upstream suggests to wait until they have a patch for 3.90 (their LTS version) available and backport from there. NOTE: 20230310: see also: Message-ID: View

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3757-1 for nss.

2024-03-10 Thread Tobias Frost (@tobi)
they have a patch for 3.90 (their LTS version) available and backport from there. + NOTE: 20240310: CVE-2023-6135: Upstream suggests to wait until they have a patch for 3.90 (their LTS version) available and backport from there. + NOTE: 20230310: see also: Message-ID: -- nvidia-graphics-drivers

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3756-1 for wordpress

2024-03-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c79e5d0 by Markus Koschany at 2024-03-10T18:21:29+01:00 Reserve DLA-3756-1 for wordpress - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-28757/expat

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a003d1a5 by Salvatore Bonaccorso at 2024-03-10T16:05:46+01:00 Add Debian bug reference for CVE-2024-28757/expat - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-22749/gpac

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 077a4509 by Salvatore Bonaccorso at 2024-03-10T15:56:45+01:00 Add Debian bug reference for CVE-2024-22749/gpac - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-5685/jboss-xnio

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 050d95d3 by Salvatore Bonaccorso at 2024-03-10T15:24:53+01:00 Add Debian bug reference for CVE-2023-5685/jboss-xnio - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Note that debdiff for php-dompdf-svg-lib is ready for review

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 172a53b7 by Salvatore Bonaccorso at 2024-03-10T15:03:43+01:00 Note that debdiff for php-dompdf-svg-lib is ready for review - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libuv1 update

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0be146b2 by Salvatore Bonaccorso at 2024-03-10T13:53:00+01:00 Reserve DSA number for libuv1 update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c658dd07 by Salvatore Bonaccorso at 2024-03-10T13:45:30+01:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 970c9078 by security tracker role at 2024-03-10T08:11:50+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-28757/expat

2024-03-10 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e71f4193 by Salvatore Bonaccorso at 2024-03-10T09:00:19+01:00 Add CVE-2024-28757/expat - - - - - 1 changed file: - data/CVE/list Changes: =