[Git][security-tracker-team/security-tracker][master] Reserve DLA-3485-1 for php-cas

2023-07-08 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7cb69a47 by Tobias Frost at 2023-07-08T15:43:53+02:00 Reserve DLA-3485-1 for php-cas - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2023-33460 does not affect ruby-yajl

2023-07-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 9513f0d4 by Tobias Frost at 2023-07-05T17:54:17+02:00 CVE-2023-33460 does not affect ruby-yajl ruby-yail embeds yajl version 1.0.12

[Git][security-tracker-team/security-tracker][master] LTS: claim renderdoc in dla-needed.txt

2023-07-03 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 8ccf3172 by Tobias Frost at 2023-07-03T21:59:35+02:00 LTS: claim renderdoc in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] xqilla also embeds yajl, is vulnerable to CVE-2017-16516 and CVE-2022-24795.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 0b62bb6d by Tobias Frost at 2023-07-02T19:20:51+02:00 xqilla also embeds yajl, is vulnerable to CVE-2017-16516 and CVE-2022-24795. - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Triage packages with embedded code copies of yajl for CVE-2022-24795,...

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ca70a32 by Tobias Frost at 2023-07-02T18:54:45+02:00 Triage packages with embedded code copies of yajl for CVE-2022-24795, CVE-2017-16516 and CVE-2023-33460 - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Fix typo in embedded-code-copies for yajl.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 93ed3e00 by Tobias Frost at 2023-07-02T17:51:54+02:00 Fix typo in embedded-code-copies for yajl. - - - - - 1 changed file: - data/embedded-code-copies Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-24795 and CVE-2017-16516 also affects yajl.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ec6a443 by Tobias Frost at 2023-07-02T14:19:51+02:00 CVE-2022-24795 and CVE-2017-16516 also affects yajl. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix version number of yajl upload

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: ce3a1614 by Tobias Frost at 2023-07-02T14:02:41+02:00 Fix version number of yajl upload - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3478-1 for yajl

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 4da854d9 by Tobias Frost at 2023-07-02T13:07:45+02:00 Reserve DLA-3478-1 for yajl - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update on php-cas situation.

2023-06-27 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 99cafcc4 by Tobias Frost at 2023-06-27T19:55:15+02:00 Update on php-cas situation. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim php-cas in dla-needed.txt

2023-06-27 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: cada0752 by Tobias Frost at 2023-06-27T13:25:08+02:00 LTS: claim php-cas in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add comment about state of nvidia-cuda-toolkit.

2023-06-27 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 08cb9f5d by Tobias Frost at 2023-06-27T13:24:40+02:00 Add comment about state of nvidia-cuda-toolkit. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim php-cas in dla-needed.txt

2023-06-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 029954c4 by Tobias Frost at 2023-06-09T12:11:44+02:00 LTS: claim php-cas in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim nvidia-cuda-toolkit in dla-needed.txt

2023-06-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 353a1c76 by Tobias Frost at 2023-06-09T12:10:43+02:00 LTS: claim nvidia-cuda-toolkit in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3437-1 for libssh

2023-05-29 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 74d73d98 by Tobias Frost at 2023-05-29T23:39:11+02:00 Reserve DLA-3437-1 for libssh - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3431-1 for sqlite

2023-05-22 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 91c61dfd by Tobias Frost at 2023-05-22T13:01:37+02:00 Reserve DLA-3431-1 for sqlite - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-31239/sqlite is not affecting buster

2023-05-22 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c555b72 by Tobias Frost at 2023-05-22T11:43:36+02:00 CVE-2021-31239/sqlite is not affecting buster The affected feature, AppendVFS, has been according upstream changelog introduced in sqlite3 version

[Git][security-tracker-team/security-tracker][master] LTS: claim sqlite in dla-needed.txt

2023-05-22 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: b4b5c823 by Tobias Frost at 2023-05-22T11:24:12+02:00 LTS: claim sqlite in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2023-2283/libssh [buster] vulnerable code introduced later.

2023-05-21 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 60062332 by Tobias Frost at 2023-05-21T15:56:01+02:00 CVE-2023-2283/libssh [buster] vulnerable code introduced later. Vulnerablity is in function pki_verify_data_signature and explained in [1] Commit

[Git][security-tracker-team/security-tracker][master] LTS: claim libssh in dla-needed.txt

2023-05-20 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: cd224cf6 by Tobias Frost at 2023-05-20T11:18:17+02:00 LTS: claim libssh in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] unclaim hdf5. It seems we'd need an SONAME bump and difficulties with the packageing.

2023-05-20 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: a982e752 by Tobias Frost at 2023-05-20T11:17:22+02:00 unclaim hdf5. It seems wed need an SONAME bump and difficulties with the packageing. - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] add note to CVE-2020-13434/CVE-2015-3416 (sqlite) with addtional

2023-05-14 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: cbcada12 by Tobias Frost at 2023-05-14T08:56:03+02:00 add note to CVE-2020-13434/CVE-2015-3416 (sqlite) with addtional information why this is not affecting sqlite2. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] CVE-2020-13434 (sqlite) does not affect buster.

2023-05-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 9bac5d7f by Tobias Frost at 2023-05-13T10:45:09+02:00 CVE-2020-13434 (sqlite) does not affect buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2115-3416 (sqlite) does not affect buster.

2023-05-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: aca0297a by Tobias Frost at 2023-05-13T08:36:34+02:00 CVE-2115-3416 (sqlite) does not affect buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim nvidia-graphics-drivers in dla-needed.txt

2023-05-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ad924df by Tobias Frost at 2023-05-07T09:49:27+02:00 LTS: claim nvidia-graphics-drivers in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim nvidia-graphics-drivers-legacy-390xx in dla-needed.txt

2023-05-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 18a80f0d by Tobias Frost at 2023-05-07T09:49:15+02:00 LTS: claim nvidia-graphics-drivers-legacy-390xx in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim hdf5 in dla-needed.txt

2023-05-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: bc31d78c by Tobias Frost at 2023-05-07T09:41:53+02:00 LTS: claim hdf5 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Triaging hdf5 for buster.

2023-05-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 02e08710 by Tobias Frost at 2023-05-06T16:46:20+02:00 Triaging hdf5 for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Triaging hdf5 -- fixed versions and upstream references.

2023-05-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: d5a88857 by Tobias Frost at 2023-05-06T16:18:46+02:00 Triaging hdf5 -- fixed versions and upstream references. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] libxml2: Fixing links from old git.gnome.org to gitlab.gnome.org.

2023-04-17 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: a4f40a27 by Tobias Frost at 2023-04-17T18:45:01+02:00 libxml2: Fixing links from old git.gnome.org to gitlab.gnome.org. (Migrate URLs from old https://git.gnome.org/browse/libxml2/commit/?id= to

[Git][security-tracker-team/security-tracker][master] Revert "Reserve DLA-3392-1 for syslog-ng"

2023-04-16 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 806e2cde by Tobias Frost at 2023-04-16T14:38:59+02:00 Revert Reserve DLA-3392-1 for syslog-ng This reverts commit 8a1b7c9fe564aeaad9de70672bc1f6c3f544eaec. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3392-1 for syslog-ng

2023-04-16 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a1b7c9f by Tobias Frost at 2023-04-16T14:36:58+02:00 Reserve DLA-3392-1 for syslog-ng - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3390-1 for zabbix

2023-04-12 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 312f67b1 by Tobias Frost at 2023-04-12T15:29:16+02:00 Reserve DLA-3390-1 for zabbix - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-46768/zabbix does not affect bullseye and buster, vulnerable feature...

2023-04-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: ca530a19 by Tobias Frost at 2023-04-10T17:44:12+02:00 CVE-2022-46768/zabbix does not affect bullseye and buster, vulnerable feature introduced in 5.4.0 only. Vulnerable feature ticket:

[Git][security-tracker-team/security-tracker][master] ignore CVE-2022-43515/zabbix for buster, as it is ignored on all other releases as well.

2023-04-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: e610a463 by Tobias Frost at 2023-04-10T17:34:46+02:00 ignore CVE-2022-43515/zabbix for buster, as it is ignored on all other releases as well. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-40626/zabbix not affecting buster.

2023-04-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 53539005 by Tobias Frost at 2023-04-10T17:30:54+02:00 CVE-2022-40626/zabbix not affecting buster. very likely introduced by commit

[Git][security-tracker-team/security-tracker][master] CVE-2022-23132 is not affecting buster.

2023-04-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 30f8383b by Tobias Frost at 2023-04-10T16:04:12+02:00 CVE-2022-23132 is not affecting buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3387-2 for udisks2

2023-04-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 05c65f6b by Tobias Frost at 2023-04-10T11:37:50+02:00 Reserve DLA-3387-2 for udisks2 - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Triage CVE-2019-17382 for buster: Same situation as for stretch/jessie, elaborate reason.

2023-04-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 1a03fca3 by Tobias Frost at 2023-04-09T19:11:24+02:00 Triage CVE-2019-17382 for buster: Same situation as for stretch/jessie, elaborate reason. The problem is sane-default, which affects only new

[Git][security-tracker-team/security-tracker][master] CVE-2022-24918 is not affecting buster.

2023-04-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: f07b6284 by Tobias Frost at 2023-04-09T18:39:25+02:00 CVE-2022-24918 is not affecting buster. The vulnerable code -- session handling by cookies -- is not present in 4.0.x. (patch part [0]) Upstream

[Git][security-tracker-team/security-tracker][master] CVE-2022-23134 is not affecting buster and bullseye:

2023-04-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: df0a35de by Tobias Frost at 2023-04-09T18:20:53+02:00 CVE-2022-23134 is not affecting buster and bullseye: Upstream comment [1] in upstream ticket ZBX-20384: 4.0 and 5.0 branches were excluded

[Git][security-tracker-team/security-tracker][master] LTS: claim zabbix in dla-needed.txt

2023-04-08 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 8cb7a7fe by Tobias Frost at 2023-04-08T08:43:03+02:00 LTS: claim zabbix in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3387-1 for udisks2

2023-04-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f234607 by Tobias Frost at 2023-04-07T22:33:09+02:00 Reserve DLA-3387-1 for udisks2 - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim udisks2 in dla-needed.txt

2023-04-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 9a78684a by Tobias Frost at 2023-04-05T19:25:00+02:00 LTS: claim udisks2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3380-1 for firmware-nonfree

2023-04-01 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 28c0f5e8 by Tobias Frost at 2023-04-01T16:05:16+02:00 Reserve DLA-3380-1 for firmware-nonfree - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3379-1 for intel-microcode

2023-04-01 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: a962697e by Tobias Frost at 2023-04-01T10:47:53+02:00 Reserve DLA-3379-1 for intel-microcode - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim firmware-nonfree in dla-needed.txt

2023-03-21 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 49588c38 by Tobias Frost at 2023-03-21T16:11:52+01:00 LTS: claim firmware-nonfree in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Document progress on intel-microcode.

2023-03-17 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 95dfae46 by Tobias Frost at 2023-03-17T20:09:33+01:00 Document progress on intel-microcode. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Document approach to intel-microcode.

2023-03-12 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: c8114c8f by Tobias Frost at 2023-03-12T19:07:05+01:00 Document approach to intel-microcode. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim intel-microcode in dla-needed.txt

2023-03-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: eb39682d by Tobias Frost at 2023-03-10T17:58:21+01:00 LTS: claim intel-microcode in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Free DLA-3355-1

2023-03-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 47d63ba9 by Tobias Frost at 2023-03-09T22:30:38+01:00 Free DLA-3355-1 - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3356-1 for wireless-regdb

2023-03-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dd0c36f by Tobias Frost at 2023-03-09T20:22:09+01:00 Reserve DLA-3356-1 for wireless-regdb - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark libde265 CVE-2022-47664/CVE-2022-47665 as fixed by DLA-3352-1.

2023-03-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 004bd0cc by Tobias Frost at 2023-03-06T19:12:43+01:00 Mark libde265 CVE-2022-47664/CVE-2022-47665 as fixed by DLA-3352-1. - - - - - 1 changed file: - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3352-1 for libde265

2023-03-04 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 4349b1f3 by Tobias Frost at 2023-03-04T18:21:05+01:00 Reserve DLA-3352-1 for libde265 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim libde265 in dla-needed.txt

2023-03-03 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: c0529747 by Tobias Frost at 2023-03-04T08:25:01+01:00 LTS: claim libde265 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Document progress on firmware-nonfree.

2023-03-03 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: ec9ad475 by Tobias Frost at 2023-03-04T08:04:20+01:00 Document progress on firmware-nonfree. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Revert "Devices affected by CVE-2021-2323 and CVE-2021-44545 are not supported...

2023-02-27 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 27ec5c5a by Tobias Frost at 2023-02-27T18:25:42+01:00 Revert Devices affected by CVE-2021-2323 and CVE-2021-44545 are not supported by busters kernel. (Firmware files also not present in

[Git][security-tracker-team/security-tracker][master] Devices affected by CVE-2021-2323 and CVE-2021-44545 are not supported by...

2023-02-26 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 10a39f85 by Tobias Frost at 2023-02-26T20:15:02+01:00 Devices affected by CVE-2021-2323 and CVE-2021-44545 are not supported by busters kernel. (Firmware files also not present in firmware-nonfree)

[Git][security-tracker-team/security-tracker][master] LTS: claim firmware-nonfree in dla-needed.txt

2023-02-26 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c0b0c0e by Tobias Frost at 2023-02-26T14:32:28+01:00 LTS: claim firmware-nonfree in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3340-1 for libgit2

2023-02-23 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 045a0647 by Tobias Frost at 2023-02-23T21:20:46+01:00 Reserve DLA-3340-1 for libgit2 - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: release claim on trafficserver in dla-needed.txt

2023-02-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 52bcd2ca by Tobias Frost at 2023-02-09T22:37:18+01:00 LTS: release claim on trafficserver in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim trafficserver in dla-needed.txt

2023-02-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f588121 by Tobias Frost at 2023-02-09T17:46:59+01:00 LTS: claim trafficserver in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3313-1 for wireshark

2023-02-08 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: e19dfaa3 by Tobias Frost at 2023-02-08T21:49:15+01:00 Reserve DLA-3313-1 for wireshark - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2023-0415 (wireshark) is not affecting buster.

2023-02-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 97153541 by Tobias Frost at 2023-02-07T08:38:00+01:00 CVE-2023-0415 (wireshark) is not affecting buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2023-0414 (wireshark) is not affecting buster.

2023-02-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: d895a354 by Tobias Frost at 2023-02-06T17:23:27+01:00 CVE-2023-0414 (wireshark) is not affecting buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add possible fixes for CVE-2022-4345 (wireshark)

2023-02-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 6898f7f2 by Tobias Frost at 2023-02-05T17:22:43+01:00 Add possible fixes for CVE-2022-4345 (wireshark) - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Replace possible fixing commit with one from the wireshark repo.

2023-02-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 5308c1f4 by Tobias Frost at 2023-02-05T16:50:48+01:00 Replace possible fixing commit with one from the wireshark repo. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] wireshark's CVE-2022-4344 does not affect buster.

2023-02-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: bf331bf0 by Tobias Frost at 2023-02-05T16:48:48+01:00 wiresharks CVE-2022-4344 does not affect buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] wireshark's CVE-2022-3190 does not affect buster.

2023-02-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: c2435b31 by Tobias Frost at 2023-02-05T14:45:13+01:00 wiresharks CVE-2022-3190 does not affect buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim wireshark in dla-needed.txt

2023-02-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: af108567 by Tobias Frost at 2023-02-05T09:13:29+01:00 LTS: claim wireshark in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3293-1 for modsecurity-crs

2023-01-30 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 709f5572 by Tobias Frost at 2023-01-30T19:15:37+01:00 Reserve DLA-3293-1 for modsecurity-crs - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reclaim modsecurity-crs

2023-01-29 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: ac91a2e0 by Tobias Frost at 2023-01-30T07:47:46+01:00 Reclaim modsecurity-crs - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3283-1 for modsecurity-apache

2023-01-26 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: a96eb0b6 by Tobias Frost at 2023-01-26T19:32:10+01:00 Reserve DLA-3283-1 for modsecurity-apache - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: release claim on ring in dla-needed.txt

2023-01-26 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: dade5e0b by Tobias Frost at 2023-01-26T16:34:35+01:00 LTS: release claim on ring in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Revert "more updates of fixed CVEs in libde265"

2023-01-25 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 252c6414 by Tobias Frost at 2023-01-25T08:59:41+01:00 Revert more updates of fixed CVEs in libde265 This reverts commit f5ccb5ef5b6175f466ba53e1556a9dafda7cd7d0. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] more updates of fixed CVEs in libde265

2023-01-24 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: f5ccb5ef by Tobias Frost at 2023-01-25T08:02:54+01:00 more updates of fixed CVEs in libde265 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2020-21594 was fixed in 1.0.3-1+deb10u1.

2023-01-24 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d040707 by Tobias Frost at 2023-01-25T07:30:46+01:00 CVE-2020-21594 was fixed in 1.0.3-1+deb10u1. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reverse DLA-3280-1 for libde265.

2023-01-24 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 0b157ca9 by Tobias Frost at 2023-01-24T23:00:49+01:00 Reverse DLA-3280-1 for libde265. - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Update bug numbers for CVE-2022-43245, CVE-2020-21596, CVE-2020-21594 (bugs have been splitted)

2023-01-22 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d46c29b by Tobias Frost at 2023-01-22T12:58:44+01:00 Update bug numbers for CVE-2022-43245, CVE-2020-21596, CVE-2020-21594 (bugs have been splitted) - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2022-48279 also affects modsecurity.

2023-01-20 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 666ae359 by Tobias Frost at 2023-01-21T08:47:49+01:00 CVE-2022-48279 also affects modsecurity. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add additional infos for modsecurity-apache.

2023-01-20 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 78dc280a by Tobias Frost at 2023-01-20T16:27:15+01:00 Add additional infos for modsecurity-apache. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim ring in dla-needed.txt

2023-01-16 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 13e6a3ee by Tobias Frost at 2023-01-16T16:56:18+01:00 LTS: claim ring in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3269-1 for libapreq2

2023-01-14 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 65afed84 by Tobias Frost at 2023-01-14T17:00:52+01:00 Reserve DLA-3269-1 for libapreq2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim libapreq2 in dla-needed.txt

2023-01-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 05feef75 by Tobias Frost at 2023-01-13T15:58:21+01:00 LTS: claim libapreq2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim libde265 in dla-needed.txt

2023-01-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e9b25ce by Tobias Frost at 2023-01-13T13:24:18+01:00 LTS: claim libde265 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim modsecurity-crs in dla-needed.txt

2023-01-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: f605b5e5 by Tobias Frost at 2023-01-13T12:09:19+01:00 LTS: claim modsecurity-crs in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-34145 - CVE-2021-34148 in bluez-firmware have been introduced only...

2022-12-29 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 3748b8c6 by Tobias Frost at 2022-12-29T16:38:00+01:00 CVE-2021-34145 - CVE-2021-34148 in bluez-firmware have been introduced only later, after bullseye release. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3250-1 for multipath-tools

2022-12-29 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 306e93e5 by Tobias Frost at 2022-12-29T11:18:27+01:00 Reserve DLA-3250-1 for multipath-tools - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim multipath-tools in dla-needed.txt

2022-12-16 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: bb8ee6f6 by Tobias Frost at 2022-12-16T18:26:46+01:00 LTS: claim multipath-tools in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3240-1 for libde2565.

2022-12-15 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: adaa8a72 by Tobias Frost at 2022-12-15T17:54:53+01:00 Reserve DLA-3240-1 for libde2565. - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-1253 does not affect buster and stretch.

2022-12-15 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 3772d3b8 by Tobias Frost at 2022-12-15T16:55:08+01:00 CVE-2022-1253 does not affect buster and stretch. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3238-1 for pngcheck

2022-12-13 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 67e0c308 by Tobias Frost at 2022-12-13T15:41:28+01:00 Reserve DLA-3238-1 for pngcheck - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim libde265 (while waiting for feedback on pngcheck)

2022-12-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: c5a4587a by Tobias Frost at 2022-12-10T13:38:18+01:00 Claim libde265 (while waiting for feedback on pngcheck) - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim pngcheck.

2022-12-10 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 099e0d6d by Tobias Frost at 2022-12-10T13:36:56+01:00 Claim pngcheck. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3232-1 for virglrenderer

2022-12-07 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: b6bc211d by Tobias Frost at 2022-12-07T18:08:59+01:00 Reserve DLA-3232-1 for virglrenderer - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim virglrenderer.

2022-12-05 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 1392dbcd by Tobias Frost at 2022-12-05T11:37:01+01:00 Claim virglrenderer. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3176-1 for clickhouse

2022-11-03 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 07a1fd77 by Tobias Frost at 2022-11-03T23:27:56+01:00 Reserve DLA-3176-1 for clickhouse - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] claim clickhouse

2022-10-29 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 99397b29 by Tobias Frost at 2022-10-29T11:01:35+02:00 claim clickhouse - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

<    1   2