[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-18197/libxslt

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e78b67e by Salvatore Bonaccorso at 2019-10-19T12:24:02Z Add Debian bug reference for CVE-2019-18197/libxslt - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2019-17596/golang-1.12

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4711fe38 by Salvatore Bonaccorso at 2019-10-19T12:25:07Z Add fixed version for CVE-2019-17596/golang-1.12 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2019-17596/golang-1.13

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a162174 by Salvatore Bonaccorso at 2019-10-19T12:26:27Z Add fixed version for CVE-2019-17596/golang-1.13 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-16723/cacti: upstream published a new fix

2019-10-19 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f11ca68 by Hugo Lefeuvre at 2019-10-19T13:35:55Z CVE-2019-16723/cacti: upstream published a new fix - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Fix Typo3 to TYPO3

2019-10-19 Thread Henri Salo
Henri Salo pushed to branch master at Debian Security Tracker / security-tracker Commits: d6827f4b by Henri Salo at 2019-10-19T08:58:32Z Fix Typo3 to TYPO3 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-18197/libxlt

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e176e7d4 by Salvatore Bonaccorso at 2019-10-19T09:48:15Z Add CVE-2019-18197/libxlt - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Fix minor typos

2019-10-19 Thread Henri Salo
Henri Salo pushed to branch master at Debian Security Tracker / security-tracker Commits: 8327a5a7 by Henri Salo at 2019-10-19T08:52:16Z Fix minor typos - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-11779

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 093ede5c by Salvatore Bonaccorso at 2019-10-19T22:11:43Z Update information on CVE-2019-11779 Directly reference the upstream issue and fixes in the 1.5.x and 1.6.x branches. According to

[Git][security-tracker-team/security-tracker][master] CVE-2019-16865,pillow: Mark as no-dsa for Jessie

2019-10-19 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 728a31ed by Markus Koschany at 2019-10-19T21:58:47Z CVE-2019-16865,pillow: Mark as no-dsa for Jessie Jessie is affected but I believe the risk of introducing regressions is too high in this case.

[Git][security-tracker-team/security-tracker][master] automatic update

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 12843ed4 by security tracker role at 2019-10-19T20:10:24Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-11778/mosquitto

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f14e7b7e by Salvatore Bonaccorso at 2019-10-19T22:06:07Z Update information on CVE-2019-11778/mosquitto - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-15939,opencv: Mark as postponed for Jessie

2019-10-19 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: cb9acbb2 by Markus Koschany at 2019-10-19T21:30:38Z CVE-2019-15939,opencv: Mark as postponed for Jessie Minor issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] patches for mosquitto CVE-2019-11778 CVE-2019-11779

2019-10-19 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 84830518 by Thorsten Alteholz at 2019-10-19T21:48:59Z patches for mosquitto CVE-2019-11778 CVE-2019-11779 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ce16fb44 by security tracker role at 2019-10-19T08:10:23Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-17596/golang

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 47bd9acb by Salvatore Bonaccorso at 2019-10-19T06:16:38Z Add CVE-2019-17596/golang - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-18198/linux

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 13af5cd8 by Salvatore Bonaccorso at 2019-10-19T07:04:49Z Add CVE-2019-18198/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug references for CVE-2019-17596

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8588ddc9 by Salvatore Bonaccorso at 2019-10-19T06:39:43Z Add Debian bug references for CVE-2019-17596 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1965-1 for nfs-utils

2019-10-19 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ea3dfda3 by Sylvain Beucler at 2019-10-19T14:22:48Z Reserve DLA-1965-1 for nfs-utils - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-15140/imagemagick: add followup patch

2019-10-19 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 57ce08d1 by Hugo Lefeuvre at 2019-10-19T14:26:52Z CVE-2019-15140/imagemagick: add followup patch this is probably minor, but still nice to take into account when cherry picking 5caef6e97f3f575 - - -

[Git][security-tracker-team/security-tracker][master] CVE-2019-15139/imagemagick: add followup patch

2019-10-19 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 1bf395d4 by Hugo Lefeuvre at 2019-10-19T14:48:29Z CVE-2019-15139/imagemagick: add followup patch partly reverts 6d46f0a046a5... - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] DLA-1965-1: Add epoch to version for nfs-utils

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ce94337 by Salvatore Bonaccorso at 2019-10-19T14:55:23Z DLA-1965-1: Add epoch to version for nfs-utils - - - - - 1 changed file: - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-18209/etherpad-lite

2019-10-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dce19b01 by Salvatore Bonaccorso at 2019-10-19T15:04:53Z Add CVE-2019-18209/etherpad-lite - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed: update imagemagick notes

2019-10-19 Thread Hugo Lefeuvre
. (hle) - NOTE: 20191015: two new CVEs, check. + NOTE: 20191019: preparing an update for the new batch of CVEs. + NOTE: CVE-2019-17540: unclear upstream fixes in ImageMagick6, this is very messy. -- imapfilter NOTE: 20190910: No patch exists but a possible solution. Note that openssl