[Git][security-tracker-team/security-tracker][master] Patch prepared for bind9 and unclaim to allow someone else to complete it.

2024-04-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 17e946dc by Ola Lundqvist at 2024-04-18T20:48:30+02:00 Patch prepared for bind9 and unclaim to allow someone else to complete it. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Added more information about bind9 work.

2024-04-17 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 808ec670 by Ola Lundqvist at 2024-04-17T23:41:03+02:00 Added more information about bind9 work. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-12214 update for openjpeg and freeimage

2024-04-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 08bd7be3 by Ola Lundqvist at 2024-04-14T13:48:42+02:00 CVE-2019-12214 update for openjpeg and freeimage Updated the information for CVE-2019-12214 based on information in

[Git][security-tracker-team/security-tracker][master] Claim bind9

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8d2ce1cd by Ola Lundqvist at 2024-04-13T00:26:56+02:00 Claim bind9 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Minor date correction.

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4325ceef by Ola Lundqvist at 2024-04-13T00:25:56+02:00 Minor date correction. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Added some notes about freeimage.

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 98b77fac by Ola Lundqvist at 2024-04-12T10:37:34+02:00 Added some notes about freeimage. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Removing claim since I will likely not have the time to work on the package for a few days.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b2c0ac9 by Ola Lundqvist at 2024-04-11T23:15:47+02:00 Removing claim since I will likely not have the time to work on the package for a few days. Do not want to prevent anyone from doing useful

[Git][security-tracker-team/security-tracker][master] 2 commits: Changed wording since the term tool can be misunderstood.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f1d2047 by Ola Lundqvist at 2024-04-11T22:34:48+02:00 Changed wording since the term tool can be misunderstood. - - - - - 4a0e4e2a by Ola Lundqvist at 2024-04-11T22:34:50+02:00 Changed a some CVEs

[Git][security-tracker-team/security-tracker][master] Removed postpone tag for buster freeimage CVEs since patches are available in fedora.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d965e06 by Ola Lundqvist at 2024-04-11T22:26:16+02:00 Removed postpone tag for buster freeimage CVEs since patches are available in fedora. The postpone tag should probably be removed for later

[Git][security-tracker-team/security-tracker][master] Removed postpone tag for buster freeimage CVE since patch is available in fedora.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 30068ece by Ola Lundqvist at 2024-04-11T22:11:20+02:00 Removed postpone tag for buster freeimage CVE since patch is available in fedora. The postpone tag should probably be removed for later

[Git][security-tracker-team/security-tracker][master] Tagged a few CVEs for freeimage as postponed.

2024-04-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d20822ee by Ola Lundqvist at 2024-04-10T22:19:21+02:00 Tagged a few CVEs for freeimage as postponed. Postponed because they are of DoS class and all reverse dependencies are tools used by a human

[Git][security-tracker-team/security-tracker][master] Claim freeimage for buster.

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 51ecda99 by Ola Lundqvist at 2024-04-08T00:06:53+02:00 Claim freeimage for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Remove runc from dla-needed

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c41e578 by Ola Lundqvist at 2024-04-07T23:50:33+02:00 Remove runc from dla-needed - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Tinymce is not affected in buster, removing from dla-needed.

2024-03-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 21503da9 by Ola Lundqvist at 2024-03-14T23:21:32+01:00 Tinymce is not affected in buster, removing from dla-needed. Checked the version difference for each CVE where the issue is claimed to be

[Git][security-tracker-team/security-tracker][master] Claim tinymce.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4df8d8a9 by Ola Lundqvist at 2024-03-12T20:49:26+01:00 Claim tinymce. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reverted decision to remove from dla-needed since four CVEs has been fixed in bullseye.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ed2cc5c0 by Ola Lundqvist at 2024-03-12T20:44:33+01:00 Reverted decision to remove from dla-needed since four CVEs has been fixed in bullseye. - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Noted reason for a few revert decisions in dla-needed for buster.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e1a0971 by Ola Lundqvist at 2024-03-12T20:40:41+01:00 Noted reason for a few revert decisions in dla-needed for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reverted decision to remove python-os-brick from dla-needed since...

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: b945d184 by Ola Lundqvist at 2024-03-12T20:36:42+01:00 Reverted decision to remove python-os-brick from dla-needed since CVE-2020-10755 is fixed in bullseye. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Reverted the decision to remove docker.io from dla-needed while keeping the...

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 58e9fdae by Ola Lundqvist at 2024-03-12T20:30:53+01:00 Reverted the decision to remove docker.io from dla-needed while keeping the no-dsa note for some CVEs. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Reverted the decision to remove cinder from dla-needed.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: cc51d2ec by Ola Lundqvist at 2024-03-12T20:25:02+01:00 Reverted the decision to remove cinder from dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reverted nvidia-cuda-toolkit removal from dla-needed.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a60f675a by Ola Lundqvist at 2024-03-12T20:22:03+01:00 Reverted nvidia-cuda-toolkit removal from dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reverted decision to mark CVEs as ignored back to no-dsa for buster.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 9aadc7a2 by Ola Lundqvist at 2024-03-12T20:07:38+01:00 Reverted decision to mark CVEs as ignored back to no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f95d3ce8 by Ola Lundqvist at 2024-03-10T23:20:12+01:00 Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster. - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed runc from dla-needed since no CVEs remain to be fixed.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f20876c2 by Ola Lundqvist at 2024-03-10T23:07:51+01:00 Removed runc from dla-needed since no CVEs remain to be fixed. - - - - - e722a127 by Ola Lundqvist at 2024-03-10T23:09:22+01:00 Reverted

[Git][security-tracker-team/security-tracker][master] Removed qemu from dla-needed. Ignored one CVE instead of no-dsa.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 40854a51 by Ola Lundqvist at 2024-03-10T00:26:32+01:00 Removed qemu from dla-needed. Ignored one CVE instead of no-dsa. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed python-glance-store when marking CVE-2024-1141 as no-dsa following buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 542ce46a by Ola Lundqvist at 2024-03-10T00:21:35+01:00 Removed python-glance-store when marking CVE-2024-1141 as no-dsa following buster. - - - - - 37959a54 by Ola Lundqvist at

[Git][security-tracker-team/security-tracker][master] Removed nvidia-cuda-toolkit from dla-needed since there were no CVEs...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: baecd314 by Ola Lundqvist at 2024-03-10T00:13:02+01:00 Removed nvidia-cuda-toolkit from dla-needed since there were no CVEs indicating that a fix is needed. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed knot-resolver from dla-needed and marked CVEs as either no-dsa or...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d002f8b by Ola Lundqvist at 2024-03-10T00:05:39+01:00 Removed knot-resolver from dla-needed and marked CVEs as either no-dsa or ignored following bullseye. - - - - - 039a4be0 by Ola Lundqvist at

[Git][security-tracker-team/security-tracker][master] Removed golang-go.crypto from dla-needed and marked one CVE as no-dsa for...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: dbde6826 by Ola Lundqvist at 2024-03-10T00:00:28+01:00 Removed golang-go.crypto from dla-needed and marked one CVE as no-dsa for buster following bullseye. - - - - - 2 changed files: -

[Git][security-tracker-team/security-tracker][master] Removed freeimage from dla-needed and marked its CVEs as postponed for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b7eb714 by Ola Lundqvist at 2024-03-09T23:57:45+01:00 Removed freeimage from dla-needed and marked its CVEs as postponed for buster following bullseye. - - - - - 2 changed files: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Removed exiftags from dla-needed and marked one CVE as no-dsa for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e215b731 by Ola Lundqvist at 2024-03-09T23:55:05+01:00 Removed exiftags from dla-needed and marked one CVE as no-dsa for buster following bullseye. - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Marked most CVEs for edk2 as no-dsa for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: bf6cd7b0 by Ola Lundqvist at 2024-03-09T23:52:46+01:00 Marked most CVEs for edk2 as no-dsa for buster following bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVEs for docker.io as no-dsa for buster and removed from dla-needed.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ebad433e by Ola Lundqvist at 2024-03-09T23:46:43+01:00 Marked CVEs for docker.io as no-dsa for buster and removed from dla-needed. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Removed cinder from dla-needed since all CVEs are no-dsa.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 202d1034 by Ola Lundqvist at 2024-03-09T23:31:58+01:00 Removed cinder from dla-needed since all CVEs are no-dsa. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Removed cairosvg from dla-needed since CVE-2023-27586 is too intrusive to fix in buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4414c335 by Ola Lundqvist at 2024-03-09T23:27:28+01:00 Removed cairosvg from dla-needed since CVE-2023-27586 is too intrusive to fix in buster. - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Removed cpio from dla-needed since there is no CVE to fix.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 38b460a8 by Ola Lundqvist at 2024-03-09T23:20:12+01:00 Removed cpio from dla-needed since there is no CVE to fix. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-46426 and CVE-2023-46427 end-of-life for buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d882f249 by Ola Lundqvist at 2024-03-09T23:14:28+01:00 Marked CVE-2023-46426 and CVE-2023-46427 end-of-life for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Ignore CVE-2023-52322 instead of no-dsa in buster even if fixed in bullseye.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c2265f4e by Ola Lundqvist at 2024-03-08T23:02:02+01:00 Ignore CVE-2023-52322 instead of no-dsa in buster even if fixed in bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 5 commits: Added libpgjava to dla-needed. Better to be safe than sorrow.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4309d77c by Ola Lundqvist at 2024-03-08T22:59:25+01:00 Added libpgjava to dla-needed. Better to be safe than sorrow. - - - - - 2c8bb864 by Ola Lundqvist at 2024-03-08T22:59:27+01:00 Ignore

[Git][security-tracker-team/security-tracker][master] 3 commits: Marked CVE-2014-7250 (kfreebsd-10) as end-of-life for buster.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ea883b0b by Ola Lundqvist at 2024-03-08T22:35:57+01:00 Marked CVE-2014-7250 (kfreebsd-10) as end-of-life for buster. - - - - - a3bbeff1 by Ola Lundqvist at 2024-03-08T22:35:58+01:00 CVE-2015-1554

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked CVEs for nvidia-graphics-drivers-legacy-340xx as ignored for buster.

2024-03-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fc30ba59 by Ola Lundqvist at 2024-03-07T23:54:31+01:00 Marked CVEs for nvidia-graphics-drivers-legacy-340xx as ignored for buster. - - - - - c7598151 by Ola Lundqvist at 2024-03-07T23:54:32+01:00

[Git][security-tracker-team/security-tracker][master] Marked CVE-2024-2236 as no-dsa following bullseye.

2024-03-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 3264f217 by Ola Lundqvist at 2024-03-07T22:57:54+01:00 Marked CVE-2024-2236 as no-dsa following bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Treat CVE-2024-2002 as minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 256a9424 by Ola Lundqvist at 2024-03-06T21:56:38+01:00 Treat CVE-2024-2002 as minor issue for buster. - - - - - 9cc8914a by Ola Lundqvist at 2024-03-06T21:56:38+01:00 Added expat to dla-needed. - -

[Git][security-tracker-team/security-tracker][master] 2 commits: Treat CVE-2024-27351 as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b498faf by Ola Lundqvist at 2024-03-06T21:51:53+01:00 Treat CVE-2024-27351 as a minor issue for buster. - - - - - 73dedb18 by Ola Lundqvist at 2024-03-06T21:51:53+01:00 Added ruby-rack to

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked three CVEs for suricata as minor issues for buster following bullseye.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: caf78ea3 by Ola Lundqvist at 2024-03-06T21:37:13+01:00 Marked three CVEs for suricata as minor issues for buster following bullseye. - - - - - 233c5ee0 by Ola Lundqvist at 2024-03-06T21:37:14+01:00

[Git][security-tracker-team/security-tracker][master] Treat CVE-2024-25269 as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c1ad0d65 by Ola Lundqvist at 2024-03-06T21:29:21+01:00 Treat CVE-2024-25269 as a minor issue for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Treat CVE-2023-5685 as minor issue in buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d6e6b82e by Ola Lundqvist at 2024-03-06T21:24:02+01:00 Treat CVE-2023-5685 as minor issue in buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added thunderbird to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e85cf6c by Ola Lundqvist at 2024-03-06T21:19:02+01:00 Added thunderbird to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Added wordpress to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8446e86f by Ola Lundqvist at 2024-03-06T21:17:01+01:00 Added wordpress to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Added iwd to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d22028c4 by Ola Lundqvist at 2024-03-06T21:03:48+01:00 Added iwd to dla-needed. - - - - - ccb877a4 by Ola Lundqvist at 2024-03-06T21:09:22+01:00 Added pdns-recursor to dla-needed. - - - - - 1

[Git][security-tracker-team/security-tracker][master] Added shim to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e44b0e5e by Ola Lundqvist at 2024-03-06T21:00:57+01:00 Added shim to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2024-27507 concluded as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 560f20fe by Ola Lundqvist at 2024-03-06T20:48:52+01:00 CVE-2024-27507 concluded as a minor issue for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVEs for golang-1.11 as postponed with limited support.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ba3d969f by Ola Lundqvist at 2024-03-06T20:45:06+01:00 Marked CVEs for golang-1.11 as postponed with limited support. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Added fontforge to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 42024d4f by Ola Lundqvist at 2024-03-06T20:42:23+01:00 Added fontforge to dla-needed. Arbitrary command execution is tricky even if this is an editor application and you should not load

[Git][security-tracker-team/security-tracker][master] Added libapache2-mod-auth-openidc to dla-needed.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: cebf4215 by Ola Lundqvist at 2024-03-05T00:19:10+01:00 Added libapache2-mod-auth-openidc to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Concluded that CVE-2024-25768 is a minor issue.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4da981b2 by Ola Lundqvist at 2024-03-05T00:08:30+01:00 Concluded that CVE-2024-25768 is a minor issue. The issue occurs if a null list buffer is provided but a non-zero length of that buffer is

[Git][security-tracker-team/security-tracker][master] Marked two CVEs for wireshark as no-dsa for buster following bookworm and bullseye.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a623b0d4 by Ola Lundqvist at 2024-03-04T23:48:05+01:00 Marked two CVEs for wireshark as no-dsa for buster following bookworm and bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-6917 as no-dsa for buster following bookworm and bullseye.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: aa87e4a0 by Ola Lundqvist at 2024-03-04T23:46:11+01:00 Marked CVE-2023-6917 as no-dsa for buster following bookworm and bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2020-36774 as no-dsa for buster.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a684666c by Ola Lundqvist at 2024-03-04T23:40:54+01:00 Marked CVE-2020-36774 as no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Postponed CVEs for buster just as for bullseye.

2023-11-24 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a7dd83b1 by Ola Lundqvist at 2023-11-24T20:12:29+00:00 Postponed CVEs for buster just as for bullseye. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-49208 as not affected for buster.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f4a918a4 by Ola Lundqvist at 2023-11-23T21:50:05+00:00 Marked CVE-2023-49208 as not affected for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added tinymce to dla-needed.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8905071c by Ola Lundqvist at 2023-11-23T21:44:06+00:00 Added tinymce to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-40030 as no-dsa for buster following bullseye.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ffc07270 by Ola Lundqvist at 2023-11-23T21:41:14+00:00 Marked CVE-2023-40030 as no-dsa for buster following bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-20246 as not affected for buster.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e7dc086 by Ola Lundqvist at 2023-11-23T21:29:24+00:00 Marked CVE-2023-20246 as not affected for buster. It should be marked as not affected for all versions since the vulnerability is only in

[Git][security-tracker-team/security-tracker][master] Added notes for httpie CVE-2023-48052.

2023-11-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 916163b2 by Ola Lundqvist at 2023-11-22T23:27:47+00:00 Added notes for httpie CVE-2023-48052. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 8 commits: Added firefox-esr to dla-needed. Already fixed in bullseye.

2023-11-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 68cf3b09 by Ola Lundqvist at 2023-11-22T22:32:12+00:00 Added firefox-esr to dla-needed. Already fixed in bullseye. - - - - - bcdde0f6 by Ola Lundqvist at 2023-11-22T22:32:12+00:00 Added thunderbird

[Git][security-tracker-team/security-tracker][master] Added strongswan to be fixed for LTS.

2023-11-21 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: deb0f964 by Ola Lundqvist at 2023-11-21T10:50:56+00:00 Added strongswan to be fixed for LTS. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Marked composer CVE-2023-43655 as minor issue.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c196dbfe by Ola Lundqvist at 2023-10-01T19:52:12+00:00 Marked composer CVE-2023-43655 as minor issue. This is only a vulnerability on an improper configuration. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Marked golang-golang-x-image CVEs as no-dsa for buster.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 76ca393a by Ola Lundqvist at 2023-10-01T19:46:41+00:00 Marked golang-golang-x-image CVEs as no-dsa for buster. it is a DoS vulnerability, rather minor and the package has limited support. - - - - -

[Git][security-tracker-team/security-tracker][master] 3 commits: Buster no-dsa for gcc-7 and gcc-8 following bullseye decision.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: aee2a5c4 by Ola Lundqvist at 2023-10-01T19:31:36+00:00 Buster no-dsa for gcc-7 and gcc-8 following bullseye decision. - - - - - 4a2dfb1a by Ola Lundqvist at 2023-10-01T19:38:24+00:00 Marked

[Git][security-tracker-team/security-tracker][master] 2 commits: Added a note about the work needed after upgrade of borgbackup.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 345ff70f by Ola Lundqvist at 2023-10-01T19:18:20+00:00 Added a note about the work needed after upgrade of borgbackup. - - - - - 66bd8cb9 by Ola Lundqvist at 2023-10-01T19:28:31+00:00 Marked a few

[Git][security-tracker-team/security-tracker][master] Marked a few CVEs as end-of-life for buster.

2023-09-29 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 56490f6a by Ola Lundqvist at 2023-09-29T18:46:49+00:00 Marked a few CVEs as end-of-life for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added gst-plugins-bad1.0 to dla-needed following decision for bookworm.

2023-09-28 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 55bc8f67 by Ola Lundqvist at 2023-09-28T21:12:17+00:00 Added gst-plugins-bad1.0 to dla-needed following decision for bookworm. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Added exim4 to dla-needed following decision for bookworm.

2023-09-28 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e8e75c4c by Ola Lundqvist at 2023-09-28T20:54:35+00:00 Added exim4 to dla-needed following decision for bookworm. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Added python-reportlab to dla-needed since it has been fixed in all later...

2023-09-26 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a978d068 by Ola Lundqvist at 2023-09-26T14:24:52+00:00 Added python-reportlab to dla-needed since it has been fixed in all later releases and seems to be important. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] 2 commits: Added trafficserver to dla-needed with a note about low prio due to few users.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: abd42ec2 by Ola Lundqvist at 2023-06-19T07:17:24+02:00 Added trafficserver to dla-needed with a note about low prio due to few users. - - - - - c6fd8a48 by Ola Lundqvist at 2023-06-19T07:17:24+02:00

[Git][security-tracker-team/security-tracker][master] Added php-dompdf to dla-needed with a note about low prio.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 15d8fb71 by Ola Lundqvist at 2023-06-18T22:25:11+02:00 Added php-dompdf to dla-needed with a note about low prio. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Added sabnzbdplus to dla-needed.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 61a98063 by Ola Lundqvist at 2023-06-18T22:06:32+02:00 Added sabnzbdplus to dla-needed. - - - - - 75065857 by Ola Lundqvist at 2023-06-18T22:10:18+02:00 Added ruby-doorkeeper to dla-needed. - - - -

[Git][security-tracker-team/security-tracker][master] 4 commits: Marked golang-1.11 CVEs as no-dsa for buster following bullseye.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2bc45273 by Ola Lundqvist at 2023-06-18T21:46:34+02:00 Marked golang-1.11 CVEs as no-dsa for buster following bullseye. - - - - - 22287c80 by Ola Lundqvist at 2023-06-18T21:49:11+02:00 Marked

[Git][security-tracker-team/security-tracker][master] Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 00d9ac0a by Ola Lundqvist at 2023-06-18T21:41:44+02:00 Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed. Following the decision for golang-1.11 package. - - - - - 1

[Git][security-tracker-team/security-tracker][master] 5 commits: Marked gpac CVE-2023-3291 end-of-life.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 08297450 by Ola Lundqvist at 2023-06-18T21:34:53+02:00 Marked gpac CVE-2023-3291 end-of-life. - - - - - f19d2d30 by Ola Lundqvist at 2023-06-18T21:34:54+02:00 Marked librabbitmq CVE-2023-35789 no-dsa

[Git][security-tracker-team/security-tracker][master] Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f871edfc by Ola Lundqvist at 2023-06-18T10:30:15+02:00 Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 1497f27f by Ola Lundqvist at 2023-06-18T10:26:21+02:00 Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm. CVE-2023-34410 CVE-2023-33285 and CVE-2023-32763 - -

[Git][security-tracker-team/security-tracker][master] 3 commits: Marked nagvis CVE-2022-46945 as no-dsa following bullseye decision.

2023-06-16 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 618740db by Ola Lundqvist at 2023-06-16T23:42:14+02:00 Marked nagvis CVE-2022-46945 as no-dsa following bullseye decision. - - - - - 3682307e by Ola Lundqvist at 2023-06-16T23:42:16+02:00 Marked

[Git][security-tracker-team/security-tracker][master] Added libx11 to dla-needed.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 944fcbc4 by Ola Lundqvist at 2023-06-15T22:45:06+02:00 Added libx11 to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Marked golang-gihub-gib-gonic-gin CVE-2023-29401 as no-dsa (minor issue) for buster.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d2ec5a05 by Ola Lundqvist at 2023-06-15T22:36:50+02:00 Marked golang-gihub-gib-gonic-gin CVE-2023-29401 as no-dsa (minor issue) for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Added python-mechanize to dla-needed.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 01c88224 by Ola Lundqvist at 2023-06-15T22:23:45+02:00 Added python-mechanize to dla-needed. - - - - - 1b93beb5 by Ola Lundqvist at 2023-06-15T22:23:46+02:00 Marked rust-h2 CVE-2023-26964 as no-dsa

[Git][security-tracker-team/security-tracker][master] Marked yajl CVE-2023-33460 as postponed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: defddfbb by Ola Lundqvist at 2023-06-14T23:19:29+02:00 Marked yajl CVE-2023-33460 as postponed. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added wordpress to dla-needed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f5a29e4e by Ola Lundqvist at 2023-06-14T23:07:22+02:00 Added wordpress to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Added opensc to dla-needed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 43340316 by Ola Lundqvist at 2023-06-14T22:40:24+02:00 Added opensc to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Added minidlna to dla-needed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: b5d1c8c6 by Ola Lundqvist at 2023-06-14T22:07:28+02:00 Added minidlna to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Added maradns to dla-needed with a note of low prio.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a51aaeea by Ola Lundqvist at 2023-06-14T21:53:11+02:00 Added maradns to dla-needed with a note of low prio. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Marked imagemagick CVE-2023-3195 as no-dsa.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ca1db473 by Ola Lundqvist at 2023-06-14T21:43:23+02:00 Marked imagemagick CVE-2023-3195 as no-dsa. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked hoteldruid CVE-2023-34537 as no-dsa (minor issue).

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c4868c6 by Ola Lundqvist at 2023-06-14T21:32:24+02:00 Marked hoteldruid CVE-2023-34537 as no-dsa (minor issue). This follows the practice for many other CVEs with XSS class. - - - - - fd9d2737 by

[Git][security-tracker-team/security-tracker][master] Added grpc to dla-needed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d39061d by Ola Lundqvist at 2023-06-14T21:26:43+02:00 Added grpc to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Marked several frr CVEs as no-dsa (minor issue).

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c5f1c2c5 by Ola Lundqvist at 2023-06-14T21:15:15+02:00 Marked several frr CVEs as no-dsa (minor issue). This follows the practice for similar CVEs in the past for the same package. They are all

[Git][security-tracker-team/security-tracker][master] Marked tang CVE-2023-1672 as no-dsa for buster following bullseye.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d7d9296a by Ola Lundqvist at 2023-06-14T21:01:52+02:00 Marked tang CVE-2023-1672 as no-dsa for buster following bullseye. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-1055 (389-ds-base) as no-dsa for buster folloring decision for bullseye.

2023-06-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ba7b9288 by Ola Lundqvist at 2023-06-12T23:05:57+02:00 Marked CVE-2023-1055 (389-ds-base) as no-dsa for buster folloring decision for bullseye. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Added libusrsctp to the packages to fix for buster.

2023-06-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fdca6ddf by Ola Lundqvist at 2023-06-12T23:00:32+02:00 Added libusrsctp to the packages to fix for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: add epiphany-browser to dla-needed.txt

2023-04-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ad382ea0 by Ola Lundqvist at 2023-04-23T22:56:28+02:00 LTS: add epiphany-browser to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

  1   2   3   >