[Git][security-tracker-team/security-tracker][master] Mark libmspack issues as no-dsa

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 43001e1d by Salvatore Bonaccorso at 2018-10-26T21:37:30Z Mark libmspack issues as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] add ruby2.1 to dla-needed.txt

2018-10-26 Thread Thorsten Alteholz
-needed.txt = @@ -83,6 +83,8 @@ qemu (Santiago) NOTE: 20181026: no fix yet for recent dsa issues, but start working on NOTE: pending no-dsa issues -- +ruby2.1 (Thorsten Alteholz) +-- salt (Antoine Beaupre) NOTE: 20180921: CVE-2017-7893 is not crucial since

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1555-1 for libmspack

2018-10-26 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: c2db21d3 by Thorsten Alteholz at 2018-10-26T20:50:07Z Reserve DLA-1555-1 for libmspack - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2018-10873/spice-gtk as no-dsa

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 44b7a5e2 by Salvatore Bonaccorso at 2018-10-26T15:38:11Z Mark CVE-2018-10873/spice-gtk as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] xpdf n/a

2018-10-26 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f13f3c7 by Moritz Muehlenhoff at 2018-10-26T14:41:43Z xpdf n/a salt no-dsa - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] mysql-5.7 fixed

2018-10-26 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 73355993 by Moritz Muehlenhoff at 2018-10-26T14:33:36Z mysql-5.7 fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 3 commits: data/dla-needed.txt: Correct ordering

2018-10-26 Thread Chris Lamb
. -- +prayer (Chris Lamb) + NOTE: 20181026: more information and patch can be found in bug #911842 (thorsten) +-- qemu (Santiago) NOTE: 20181026: no fix yet for recent dsa issues, but start working on NOTE: pending no-dsa issues -- -prayer - NOTE: 20181026: more information and patch can

[Git][security-tracker-team/security-tracker][master] privileges are taken care of in Jessie

2018-10-26 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 094f19ca by Thorsten Alteholz at 2018-10-26T11:32:15Z privileges are taken care of in Jessie - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Claim qemu in dla-needed.txt

2018-10-26 Thread Santiago R.R.
) + NOTE: 20181026: no fix yet for recent dsa issues, but start working on + NOTE: pending no-dsa issues -- salt (Antoine Beaupre) NOTE: 20180921: CVE-2017-7893 is not crucial since the managed system must be View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2016-6173/nsd

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e382895 by Salvatore Bonaccorso at 2018-10-26T09:04:23Z Add fixed version for CVE-2016-6173/nsd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 87b731a3 by Salvatore Bonaccorso at 2018-10-26T09:00:54Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add (unfortunately overlong) TODO item for CVE-2018-18653

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69b6c2a1 by Salvatore Bonaccorso at 2018-10-26T08:53:21Z Add (unfortunately overlong) TODO item for CVE-2018-18653 This seem at first glance a very specific issue for the Linux kernel as shiped

[Git][security-tracker-team/security-tracker][master] Add reference for CVE-2018-12479/open-build-service

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b7a44782 by Salvatore Bonaccorso at 2018-10-26T08:50:25Z Add reference for CVE-2018-12479/open-build-service - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2018-12478

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 92554219 by Salvatore Bonaccorso at 2018-10-26T08:47:24Z Update information on CVE-2018-12478 The issue affects the replace_using_package_version addiononal obs-service which is not part of

[Git][security-tracker-team/security-tracker][master] automatic update

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cec20b7e by security tracker role at 2018-10-26T08:10:22Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add bug reference for CVE-2018-16396/ruby2.5

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b46d634c by Salvatore Bonaccorso at 2018-10-26T06:51:22Z Add bug reference for CVE-2018-16396/ruby2.5 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add bug references for CVE-2018-16396/{ruby-openssl,ruby2.5}

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e698987 by Salvatore Bonaccorso at 2018-10-26T06:43:34Z Add bug references for CVE-2018-16396/{ruby-openssl,ruby2.5} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Demote crossroads severity to unimportant

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a9c21a93 by Salvatore Bonaccorso at 2018-10-26T06:41:27Z Demote crossroads severity to unimportant The issue is only exploitable during package build itself. For stable it is ever unlikely that

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-16396/ruby

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 00f3b66b by Salvatore Bonaccorso at 2018-10-26T06:31:24Z Add CVE-2018-16396/ruby - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-16395/ruby

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d92c47d3 by Salvatore Bonaccorso at 2018-10-26T06:24:43Z Add CVE-2018-16395/ruby - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] openjdk-9 removed from all suites

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cb84417e by Salvatore Bonaccorso at 2018-10-26T06:16:40Z openjdk-9 removed from all suites - - - - - 1 changed file: - data/packages/removed-packages Changes:

[Git][security-tracker-team/security-tracker][master] Fix typo in source package name for libmspack

2018-10-26 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 79987514 by Salvatore Bonaccorso at 2018-10-26T06:15:13Z Fix typo in source package name for libmspack - - - - - 1 changed file: - data/CVE/list Changes: