[Git][security-tracker-team/security-tracker][master] 3 commits: Add CVE-2018-19477/ghostscript

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0b51b27c by Salvatore Bonaccorso at 2018-11-23T07:49:47Z Add CVE-2018-19477/ghostscript - - - - - 78bf4505 by Salvatore Bonaccorso at 2018-11-23T07:50:51Z Add CVE-2018-19476/ghostscript - - - -

[Git][security-tracker-team/security-tracker][master] new tryton-client issue

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e645f0fb by Moritz Muehlenhoff at 2018-11-22T08:51:46Z new tryton-client issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new webkit issues

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b77daa5 by Moritz Muehlenhoff at 2018-11-22T09:37:01Z new webkit issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 86757c1f by security tracker role at 2018-11-22T08:10:19Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 03060355 by Salvatore Bonaccorso at 2018-11-22T08:16:19Z Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 3 commits: inline explanation for why a package is unclaimed

2018-11-22 Thread Antoine Beaupré
Antoine Beaupré pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c97790c by Antoine Beaupré at 2018-11-22T16:52:53Z inline explanation for why a package is unclaimed A little more verbose explanation will help in diagnosing why a specific package was unclaimed.

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-19416/sysstat

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3425be32 by Salvatore Bonaccorso at 2018-11-22T14:59:13Z Add CVE-2018-19416/sysstat - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2015-5297: add patch that was finally used by upstream

2018-11-22 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 836f0781 by Thorsten Alteholz at 2018-11-22T15:22:07Z CVE-2015-5297: add patch that was finally used by upstream - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1587-1 for pixman

2018-11-22 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a165833 by Thorsten Alteholz at 2018-11-22T16:00:03Z Reserve DLA-1587-1 for pixman - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: mark CVE-2018-19058 of poppler as minor issue

2018-11-22 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: efd38359 by Thorsten Alteholz at 2018-11-22T19:01:55Z mark CVE-2018-19058 of poppler as minor issue - - - - - 5f14653e by Thorsten Alteholz at 2018-11-22T19:01:55Z no dla for poppler - - - - - 2

[Git][security-tracker-team/security-tracker][master] NFUs

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 8fa3499c by Moritz Muehlenhoff at 2018-11-22T19:21:01Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] openssl fixed

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: bda4c257 by Moritz Muehlenhoff at 2018-11-22T19:28:16Z openssl fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] minihttpd fixed

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 05da8232 by Moritz Muehlenhoff at 2018-11-22T19:00:51Z minihttpd fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] amanda non-issues

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 554ac35f by Moritz Muehlenhoff at 2018-11-22T19:55:38Z amanda non-issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c1937d3a by security tracker role at 2018-11-22T20:10:27Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] drop mariadb, all fixed

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 87cdc1d4 by Moritz Muehlenhoff at 2018-11-22T18:57:38Z drop mariadb, all fixed - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] two PHP issues n/a

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 34393789 by Moritz Muehlenhoff at 2018-11-22T19:17:39Z two PHP issues n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new libsndfile issue

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b470ccf5 by Moritz Muehlenhoff at 2018-11-22T19:29:28Z new libsndfile issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE for tryton-client issue assigned by MITRE

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ffd438f9 by Salvatore Bonaccorso at 2018-11-22T20:07:52Z CVE for tryton-client issue assigned by MITRE - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2018-0735 as not-affected for openssl1.0

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 02e6e8b0 by Salvatore Bonaccorso at 2018-11-23T04:57:14Z Mark CVE-2018-0735 as not-affected for openssl1.0 >From IRC discussion: bigeasy for CVE-2018-0735 I would remove openssl1.0

[Git][security-tracker-team/security-tracker][master] Add followup commit for CVE-2018-19409/ghostscript

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c41ccc24 by Salvatore Bonaccorso at 2018-11-23T05:18:09Z Add followup commit for CVE-2018-19409/ghostscript - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Claim ghostscript in dla-needed.txt

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 210bd7b8 by Markus Koschany at 2018-11-22T20:23:51Z Claim ghostscript in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2018-19274,phpbb3: Link to fixing commit

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 975f9083 by Markus Koschany at 2018-11-22T21:45:56Z CVE-2018-19274,phpbb3: Link to fixing commit - - - - - 7d55fdc0 by Markus Koschany at 2018-11-22T21:46:40Z Claim phpbb3 in dla-needed.txt - - - -

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1588-1 for icecast2

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2aa0f4a3 by Markus Koschany at 2018-11-22T21:53:17Z Reserve DLA-1588-1 for icecast2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2018-19115,keepalived: Link to Debian bug.

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ab04823a by Markus Koschany at 2018-11-22T22:53:31Z CVE-2018-19115,keepalived: Link to Debian bug. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-19416/sysstat

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 59eb9031 by Salvatore Bonaccorso at 2018-11-22T20:49:11Z Add bug reference for CVE-2018-19416/sysstat - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2018-19358,gnome-keyring: no-dsa for Jessie

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0011af4b by Markus Koschany at 2018-11-22T20:55:39Z CVE-2018-19358,gnome-keyring: no-dsa for Jessie - - - - - 54026d69 by Markus Koschany at 2018-11-22T20:56:27Z Merge branch master of

[Git][security-tracker-team/security-tracker][master] 3 commits: Add ghostscript to dsa-needed list

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 71192006 by Salvatore Bonaccorso at 2018-11-22T21:17:54Z Add ghostscript to dsa-needed list - - - - - 299fb36e by Salvatore Bonaccorso at 2018-11-22T21:46:59Z Add php issue (no CVE assigned yet)

[Git][security-tracker-team/security-tracker][master] gitlab fixed

2018-11-22 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: dde530fd by Moritz Muehlenhoff at 2018-11-22T22:01:52Z gitlab fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1590-1 for openjdk-7

2018-11-22 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 1a5f4d48 by Emilio Pozuelo Monfort at 2018-11-22T22:08:10Z Reserve DLA-1590-1 for openjdk-7 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Adjust affectness information for CVE-2018-19443/tryton-client

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aaba8130 by Salvatore Bonaccorso at 2018-11-22T22:23:12Z Adjust affectness information for CVE-2018-19443/tryton-client The vulnerable version 5.0.0 was never in Debian, and the next upload to

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-19432/libsndfile

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f44b05ad by Salvatore Bonaccorso at 2018-11-22T20:24:46Z Add bug reference for CVE-2018-19432/libsndfile - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1589-1 for keepalived

2018-11-22 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 16019827 by Markus Koschany at 2018-11-22T21:56:06Z Reserve DLA-1589-1 for keepalived - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add on top of the list first bug report for imap_open() php issue

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e600159 by Salvatore Bonaccorso at 2018-11-22T21:56:26Z Add on top of the list first bug report for imap_open() php issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2018-4372/webkit2gtk

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b8973ad8 by Salvatore Bonaccorso at 2018-11-22T22:11:51Z Add fixed version for CVE-2018-4372/webkit2gtk - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove CVE-2018-0735 from openssl1.0

2018-11-22 Thread Sebastian Siewior
Sebastian Siewior pushed to branch master at Debian Security Tracker / security-tracker Commits: 12615d5f by Sebastian Andrzej Siewior at 2018-11-22T22:16:53Z Remove CVE-2018-0735 from openssl1.0 This was fixed as part of CVE-2018-5407. Signed-off-by: Sebastian Andrzej Siewior

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add note note

2018-11-22 Thread Abhijith PA
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 78575bd3 by Abhijith PA at 2018-11-23T02:05:50Z data/dla-needed.txt: Add note note - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add new git issue with falling back to cwd if a command is not in $PATH

2018-11-22 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e0cb34d by Salvatore Bonaccorso at 2018-11-23T05:44:31Z Add new git issue with falling back to cwd if a command is not in $PATH A possible attack scenario consist of a user operating on a

[Git][security-tracker-team/security-tracker][master] Add libsndfile to dla-needed

2018-11-22 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 805f43b8 by Hugo Lefeuvre at 2018-11-23T06:33:38Z Add libsndfile to dla-needed - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt