[Git][security-tracker-team/security-tracker][master] Add CVE-2020-15365/libraw

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 62715326 by Salvatore Bonaccorso at 2020-06-30T06:47:44+02:00 Add CVE-2020-15365/libraw - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process more NFUs

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4c7a0729 by Salvatore Bonaccorso at 2020-06-30T06:53:58+02:00 Process more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5af37f42 by Salvatore Bonaccorso at 2020-06-30T06:30:15+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track nvidia-graphics-drivers-tesla-440 for CVE-2020-596{3,7}

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: df70fded by Salvatore Bonaccorso at 2020-06-30T07:21:43+02:00 Track nvidia-graphics-drivers-tesla-440 for CVE-2020-596{3,7} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Clarify associations between CVE-2020-1957 and CVE-2020-11989

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d1d96c9 by Salvatore Bonaccorso at 2020-06-30T06:37:19+02:00 Clarify associations between CVE-2020-1957 and CVE-2020-11989 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2263-1 for drupal7

2020-06-29 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 7840006e by Ola Lundqvist at 2020-06-29T23:47:42+02:00 Reserve DLA-2263-1 for drupal7 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim shiro.

2020-06-29 Thread Chris Lamb
-needed.txt = @@ -125,7 +125,8 @@ rails (Sylvain Beucler) ruby-rack NOTE: probably not affected (parse_cookies_header() is not available in Jessie, but code might hide somewhere else) (thorsten) -- -shiro +shiro (Chris Lamb) + NOTE: 20200629: Taking this now as I

[Git][security-tracker-team/security-tracker][master] Add coturn to dsa-needed list

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f0e89b16 by Salvatore Bonaccorso at 2020-06-29T12:31:48+02:00 Add coturn to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add temporary description for CVE-2020-4067/coturn

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ff4e8a6 by Salvatore Bonaccorso at 2020-06-29T12:30:36+02:00 Add temporary description for CVE-2020-4067/coturn - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Track fixed version for nvidia-graphics-drivers-legacy-390xx

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3d863603 by Salvatore Bonaccorso at 2020-06-29T08:32:05+02:00 Track fixed version for nvidia-graphics-drivers-legacy-390xx - - - - - a71e7da2 by Salvatore Bonaccorso at

[Git][security-tracker-team/security-tracker][master] new google-compute-image-packages issues

2020-06-29 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 32334cfa by Moritz Muehlenhoff at 2020-06-29T09:59:50+02:00 new google-compute-image-packages issues NFUs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entries for CVE-2020-606{1,2}/coturn

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 697b3dd5 by Salvatore Bonaccorso at 2020-06-29T12:33:21+02:00 Remove no-dsa tagged entries for CVE-2020-606{1,2}/coturn - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2cf73ff6 by security tracker role at 2020-06-29T08:10:18+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-4067/coturn

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1ec27737 by Salvatore Bonaccorso at 2020-06-29T12:29:42+02:00 Add CVE-2020-4067/coturn - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2020-14396/libvncserver/jessie: not affected

2020-06-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 6fc0010d by Mike Gabriel at 2020-06-29T15:51:34+02:00 CVE-2020-14396/libvncserver/jessie: not affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2018-21247/libvncserver fixed already in 0.9.11+dfsg-1.2

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a043fd81 by Salvatore Bonaccorso at 2020-06-29T15:50:46+02:00 CVE-2018-21247/libvncserver fixed already in 0.9.11+dfsg-1.2 - - - - - b8129f55 by Salvatore Bonaccorso at

[Git][security-tracker-team/security-tracker][master] CVE-2019-20840/libvncserver/jessie: not affected

2020-06-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: a7cd14c3 by Mike Gabriel at 2020-06-29T15:36:01+02:00 CVE-2019-20840/libvncserver/jessie: not affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-4067/coturn

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ac99f31f by Salvatore Bonaccorso at 2020-06-29T16:46:25+02:00 Add fixed version for CVE-2020-4067/coturn - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-14398/libvncserver/jessie: ignore, possibly ABI breakage

2020-06-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: e6049f97 by Mike Gabriel at 2020-06-29T16:50:00+02:00 CVE-2020-14398/libvncserver/jessie: ignore, possibly ABI breakage - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA for coturn update

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7933bbdf by Salvatore Bonaccorso at 2020-06-29T18:11:40+02:00 Reserve DSA for coturn update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] nvidia spu/ospu

2020-06-29 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b29de2a by Moritz Muehlenhoff at 2020-06-29T18:53:20+02:00 nvidia spu/ospu - - - - - 2 changed files: - data/next-oldstable-point-update.txt - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim coturn

2020-06-29 Thread Utkarsh Gupta
want to do the upload (thorsten) +jackson-databind (Utkarsh Gupta) + NOTE: 20200629: WIP (utkarsh) -- libdatetime-timezone-perl NOTE: 20200514: LTS update must wait on oldstable update first (via point release) to prevent newer version in LTS (roberto) View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] Track nvidia-graphics-driver-testla-418 as well for CVE-2020-59{63,67}

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b1fe6315 by Salvatore Bonaccorso at 2020-06-29T22:01:07+02:00 Track nvidia-graphics-driver-testla-418 as well for CVE-2020-59{63,67} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update notes for CVE-2020-11989

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b157e921 by Salvatore Bonaccorso at 2020-06-29T21:41:30+02:00 Update notes for CVE-2020-11989 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Several libvncserver issues fixed via unstable upload

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d49f0758 by Salvatore Bonaccorso at 2020-06-29T21:58:49+02:00 Several libvncserver issues fixed via unstable upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2262-1 for qemu

2020-06-29 Thread Adrian Bunk
-- -qemu (Adrian Bunk) - NOTE: 20200531: waiting for CVE-2020-13362 fix to be applied upstream (bunk) - NOTE: 20200615: work is ongoing (bunk) - NOTE: 20200629: pending release (bunk) --- rails (Sylvain Beucler) NOTE: 20200624: asked for upstream feedback on regression NOTE: 20200624: https

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-14145/openssh

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ef19fe3e by Salvatore Bonaccorso at 2020-06-29T21:51:56+02:00 Add CVE-2020-14145/openssh This is a coresponding issue to the already tracked CVE-2020-14002/putty issue. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Several frerdp2 issues fixed via unstable upload

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b5a98e8 by Salvatore Bonaccorso at 2020-06-29T21:56:58+02:00 Several frerdp2 issues fixed via unstable upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2020-06-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ec96ed1d by security tracker role at 2020-06-29T20:10:27+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list