[Git][security-tracker-team/security-tracker][master] openjpeg2: mark CVE-2018-5727 in jessie

2019-01-21 Thread Hugo Lefeuvre
IPCAMERA01 3.3.4.2103 devices = data/dla-needed.txt = @@ -90,10 +90,6 @@ nss NOTE: 20181217: Contacted Mozilla security with a request for access to the BZ issue. (roberto) NOTE: 20190121: If you intend to take up this package

[Git][security-tracker-team/security-tracker][master] remove no-dsa since issue was addressed in dla

2019-01-21 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 1d3388cc by Hugo Lefeuvre at 2019-01-22T07:21:30Z remove no-dsa since issue was addressed in dla - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1636-1 for aria2

2019-01-21 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: c0e73060 by Hugo Lefeuvre at 2019-01-22T07:03:13Z Reserve DLA-1636-1 for aria2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2019-4240/gitlab

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c4d7081 by Salvatore Bonaccorso at 2019-01-22T06:15:30Z Add fixed version for CVE-2019-4240/gitlab - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-6501/qemu

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ca3bb81 by Salvatore Bonaccorso at 2019-01-22T06:14:30Z Add CVE-2019-6501/qemu - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-3808, CVE-2019-3809 and CVE-2019-3810 for src:moodle

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ace2989e by Salvatore Bonaccorso at 2019-01-22T06:13:05Z Add CVE-2019-3808, CVE-2019-3809 and CVE-2019-3810 for src:moodle - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] stretch triage

2019-01-21 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 915804fa by Moritz Muehlenhoff at 2019-01-21T22:12:23Z stretch triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] NFUs

2019-01-21 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f39d53db by Moritz Muehlenhoff at 2019-01-21T21:35:55Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2016-10739/glibc for tracking

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b1d34630 by Salvatore Bonaccorso at 2019-01-21T20:55:41Z Add Debian bug reference for CVE-2016-10739/glibc for tracking - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2016-10739/glibc as no-dsa

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b2b5299 by Salvatore Bonaccorso at 2019-01-21T20:52:59Z Mark CVE-2016-10739/glibc as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream reference for CVE-2016-10739/glibc

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1754f673 by Salvatore Bonaccorso at 2019-01-21T20:39:37Z Add upstream reference for CVE-2016-10739/glibc - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2016-10739/glibc

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cc7c6519 by Salvatore Bonaccorso at 2019-01-21T20:14:40Z Add CVE-2016-10739/glibc - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Demote severity of CVE-2019-6129 to unimportant across source packages

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0194b263 by Salvatore Bonaccorso at 2019-01-21T20:11:41Z Demote severity of CVE-2019-6129 to unimportant across source packages Reasoning explained in upstream report at

[Git][security-tracker-team/security-tracker][master] automatic update

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d25b1d30 by security tracker role at 2019-01-21T20:10:31Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] libpng: CVE-2019-6129 in Jessie

2019-01-21 Thread Hugo Lefeuvre
in LibTIFF 4.0.10 has a memory ...) = data/dla-needed.txt = @@ -68,9 +68,6 @@ krb5 (Thorsten Alteholz) -- libav (Mike Gabriel) -- -libpng (Hugo Lefeuvre) - NOTE: 20190121: Are we sure? Quoting upstream on CVE-2019-6129: &q

[Git][security-tracker-team/security-tracker][master] pdns-recursor fixed

2019-01-21 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 32858254 by Moritz Muehlenhoff at 2019-01-21T16:52:34Z pdns-recursor fixed libpng non-issue - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed: claim libpng

2019-01-21 Thread Hugo Lefeuvre
= @@ -68,7 +68,7 @@ krb5 (Thorsten Alteholz) -- libav (Mike Gabriel) -- -libpng +libpng (Hugo Lefeuvre) NOTE: 20190121: Are we sure? Quoting upstream on CVE-2019-6129: "I think this is not a security issue at all". (lamby) -- libjpeg-turbo View it

[Git][security-tracker-team/security-tracker][master] Add assigned CVEs for drupal7 isues

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e2cf27da by Salvatore Bonaccorso at 2019-01-21T16:38:02Z Add assigned CVEs for drupal7 isues - - - - - 2 changed files: - data/CVE/list - data/DSA/list Changes:

[Git][security-tracker-team/security-tracker][master] Add note for future claimants of nss

2019-01-21 Thread Roberto C . Sánchez
with a request for access to the BZ issue. (roberto) + NOTE: 20190121: If you intend to take up this package, please email me and I will provide a detailed summary of what has been done so far. (roberto) -- openjpeg2 NOTE: CVE-2018-5727: investigated the issue, might not be easy to patch, not sure

[Git][security-tracker-team/security-tracker][master] Remove note on CVE-2019-6256, confirmed that the fix was in 2018.11.26

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bd5f70ca by Salvatore Bonaccorso at 2019-01-21T16:18:04Z Remove note on CVE-2019-6256, confirmed that the fix was in 2018.11.26 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fix for CVE-2018-20540/liblas

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b6c35acc by Salvatore Bonaccorso at 2019-01-21T16:16:24Z Track fix for CVE-2018-20540/liblas - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: add libjpeg-turbo

2019-01-21 Thread Thorsten Alteholz
-needed.txt = @@ -71,6 +71,9 @@ libav (Mike Gabriel) libpng NOTE: 20190121: Are we sure? Quoting upstream on CVE-2019-6129: "I think this is not a security issue at all". (lamby) -- +libjpeg-turbo + NOTE: 20190121: as Mike is an Uploader:, probabl

[Git][security-tracker-team/security-tracker][master] new pdns-recursor isues

2019-01-21 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ae401730 by Moritz Muehlenhoff at 2019-01-21T15:54:18Z new pdns-recursor isues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Adjust libav version for CVE-2017-11684

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e7182ff5 by Salvatore Bonaccorso at 2019-01-21T15:53:35Z Adjust libav version for CVE-2017-11684 The upstream version 11.11 contained the fix smacker: fix integer overflow with pts_inc which

[Git][security-tracker-team/security-tracker][master] dla-needed: claim aria2

2019-01-21 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: a9cc3efa by Hugo Lefeuvre at 2019-01-21T15:49:34Z dla-needed: claim aria2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage libpng for jessie.

2019-01-21 Thread Chris Lamb
. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt = @@ -68,6 +68,9 @@ krb5 (Thorsten Alteholz) -- libav (Mike Gabriel) -- +libpng + NOTE: 20190121: Are we sure? Quoting upstream on CVE

[Git][security-tracker-team/security-tracker][master] 5 commits: add openssh

2019-01-21 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ba09897 by Thorsten Alteholz at 2019-01-21T15:06:13Z add openssh - - - - - 830540c5 by Thorsten Alteholz at 2019-01-21T15:06:14Z mark CVE-2018-20712 as no-dsa for jessie - - - - - 1fab3234 by

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-11684 (libav) fixed since at least 6:11.12-1~deb8u1.

2019-01-21 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: d02d69f8 by Mike Gabriel at 2019-01-21T14:43:51Z Mark CVE-2017-11684 (libav) fixed since at least 6:11.12-1~deb8u1. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Make clar status of CVE-2018-11761/tika (and respectively CVE-2018-11796)

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: af213f7a by Salvatore Bonaccorso at 2019-01-21T13:06:33Z Make clar status of CVE-2018-11761/tika (and respectively CVE-2018-11796) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2019-01-21 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f9d99c12 by Moritz Muehlenhoff at 2019-01-21T08:13:52Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2019-01-21 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ee591fd by security tracker role at 2019-01-21T08:10:19Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list