[Git][security-tracker-team/security-tracker][master] Claim freeimage for buster.

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 51ecda99 by Ola Lundqvist at 2024-04-08T00:06:53+02:00 Claim freeimage for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Remove runc from dla-needed

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c41e578 by Ola Lundqvist at 2024-04-07T23:50:33+02:00 Remove runc from dla-needed - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add patch link for CVE-2021-41089

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: edd60855 by Daniel Leidert at 2024-04-07T23:33:37+02:00 Add patch link for CVE-2021-41089 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update findings for CVE-2023-49288

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: d0a41abf by Daniel Leidert at 2024-04-07T22:37:43+02:00 Update findings for CVE-2023-49288 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: release claim on docker.io in dla-needed.txt

2024-04-07 Thread Daniel Leidert (@dleidert)
: 20240310: Dropped from dla-needed.txt (ola/front-desk) NOTE: 20230311: Reverted decision to remove from this file since three CVEs are in bullseye. (ola) + NOTE: 20240407: Version 18.09.1+dfsg1-7.1+deb10u4 in Git has not been uploaded yet. (dleidert) -- dogecoin NOTE: 20230619: Added

[Git][security-tracker-team/security-tracker][master] automatic update

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 49c2eef2 by security tracker role at 2024-04-07T20:11:53+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Mark open CVE for lucene-solr as EOL for buster

2024-04-07 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0c329976 by Markus Koschany at 2024-04-07T21:55:09+02:00 Mark open CVE for lucene-solr as EOL for buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove lucene-solr from dla-needed.txt

2024-04-07 Thread Markus Koschany (@apo)
NOTE: 20231005: perma-added for LTS package-specific delegation (bwh) -- -lucene-solr - NOTE: 20240213: Added by Front-Desk (lamby) - NOTE: 20240407: Should the server components be disabled as in 3.6.2+dfsg-23 instead of trying to patch the CVEs? (dleidert) - NOTE: 20240407: I'm going to contact

[Git][security-tracker-team/security-tracker][master] LTS: claim docker.io in dla-needed.txt

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c2cea8e by Daniel Leidert at 2024-04-07T21:03:13+02:00 LTS: claim docker.io in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add Link to PR for CVE-2023-49288

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: 8ea09c58 by Daniel Leidert at 2024-04-07T20:34:27+02:00 Add Link to PR for CVE-2023-49288 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add notes regarding "fix" from 3.6.2+dfsg-23

2024-04-07 Thread Daniel Leidert (@dleidert)
: = data/dla-needed.txt = @@ -158,6 +158,8 @@ linux-5.10 -- lucene-solr NOTE: 20240213: Added by Front-Desk (lamby) + NOTE: 20240407: Should the server components be disabled as in 3.6.2+dfsg-23 instead of trying to patch the CVEs? (dleidert) + NOTE

[Git][security-tracker-team/security-tracker][master] LTS: release claim on lucene-solr in dla-needed.txt

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: b738fe72 by Daniel Leidert at 2024-04-07T20:13:21+02:00 LTS: release claim on lucene-solr in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim lucene-solr in dla-needed.txt

2024-04-07 Thread Daniel Leidert (@dleidert)
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker Commits: 79cce308 by Daniel Leidert at 2024-04-07T19:29:03+02:00 LTS: claim lucene-solr in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Claim libpgjava in dla-needed.txt

2024-04-07 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a83b404c by Markus Koschany at 2024-04-07T11:46:24+02:00 Claim libpgjava in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3784-1 for libcaca

2024-04-07 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 55b52a6c by Thorsten Alteholz at 2024-04-07T10:40:39+02:00 Reserve DLA-3784-1 for libcaca - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2024-30370 as NFU

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f0c92d52 by Salvatore Bonaccorso at 2024-04-07T10:32:05+02:00 Mark CVE-2024-30370 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-30166/mbedtls

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 10ed804c by Salvatore Bonaccorso at 2024-04-07T10:29:37+02:00 Add CVE-2024-30166/mbedtls - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-28836/mbedtls

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3b024d89 by Salvatore Bonaccorso at 2024-04-07T10:26:45+02:00 Add CVE-2024-28836/mbedtls - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 05ff1779 by Salvatore Bonaccorso at 2024-04-07T10:22:44+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c92c5df7 by security tracker role at 2024-04-07T08:12:22+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2024-28755 and CVE-2023-52353

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 229cc53e by Salvatore Bonaccorso at 2024-04-07T09:51:56+02:00 Update information on CVE-2024-28755 and CVE-2023-52353 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-50471 as no-dsa

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aa117f24 by Salvatore Bonaccorso at 2024-04-07T09:17:29+02:00 Mark CVE-2023-50471 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3783-1 for expat

2024-04-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 22b0e152 by Tobias Frost at 2024-04-07T09:14:11+02:00 Reserve DLA-3783-1 for expat - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Document relation from CVE-2024-2314, #1028479 and #1068297

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b094ddd2 by Salvatore Bonaccorso at 2024-04-07T09:07:53+02:00 Document relation from CVE-2024-2314, #1028479 and #1068297 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream commit for CVE-2023-50967/jose

2024-04-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3da12db9 by Salvatore Bonaccorso at 2024-04-07T08:51:38+02:00 Reference upstream commit for CVE-2023-50967/jose - - - - - 1 changed file: - data/CVE/list Changes: