[Git][security-tracker-team/security-tracker][master] CVE-2019-773{2,3}/liblivemedia: add upstream fix

2019-05-11 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: afb381c7 by Hugo Lefeuvre at 2019-05-12T05:44:15Z CVE-2019-773{2,3}/liblivemedia: add upstream fix + upstream fixed CVE-2019-7733 in 2019.05.12. Mark it postponed in jessie since it might be worth

[Git][security-tracker-team/security-tracker][master] Adding openjdk-7 to the list of packages to fix for jessie. Sounds serious enough.

2019-05-11 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 35cbf3c2 by Ola Lundqvist at 2019-05-11T21:33:21Z Adding openjdk-7 to the list of packages to fix for jessie. Sounds serious enough. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Ignoring CVE-2019-6470 following decision for stretch.

2019-05-11 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a97a36f8 by Ola Lundqvist at 2019-05-11T21:12:34Z Ignoring CVE-2019-6470 following decision for stretch. - - - - - 0185a0b3 by Ola Lundqvist at 2019-05-11T21:17:32Z Ignoring CVE-2017-12839 and

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-12839/mpg123 as no-dsa for stretch

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8fe69ead by Salvatore Bonaccorso at 2019-05-11T19:32:12Z Mark CVE-2017-12839/mpg123 as no-dsa for stretch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference additional needed commit for CVE-2019-11598

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ce305daf by Salvatore Bonaccorso at 2019-05-11T19:19:49Z Reference additional needed commit for CVE-2019-11598 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-11059/u-boot

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 77fcf018 by Salvatore Bonaccorso at 2019-05-11T12:08:43Z Add Debian bug reference for CVE-2019-11059/u-boot - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-11598/imagemagick: update notes concerning patch

2019-05-11 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e3dcaa9 by Hugo Lefeuvre at 2019-05-11T11:59:32Z CVE-2019-11598/imagemagick: update notes concerning patch - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2019-11059/u-boot

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b94328b by Salvatore Bonaccorso at 2019-05-11T11:43:49Z Add CVE-2019-11059/u-boot - - - - - f8b5f2af by Salvatore Bonaccorso at 2019-05-11T11:45:01Z Mark CVE-2019-11059 as no-dsa for stretch

[Git][security-tracker-team/security-tracker][master] Add CVE-2017-12839/mpg123, older issue in mpg123

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 37c6cd43 by Salvatore Bonaccorso at 2019-05-11T11:41:41Z Add CVE-2017-12839/mpg123, older issue in mpg123 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d74c93b0 by Salvatore Bonaccorso at 2019-05-11T11:40:07Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-9847/libreoffice

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 52406849 by Salvatore Bonaccorso at 2019-05-11T11:40:49Z Add CVE-2019-9847/libreoffice - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed: update faad2 entry

2019-05-11 Thread Hugo Lefeuvre
more - NOTE: patch and we will be fit for upload. + NOTE: 20190511: preparing upload for merged patches. + NOTE: I have a few patches pending for open issues. Will be PR-ed soon. -- ghostscript (Roberto C. Sánchez) -- View it on GitLab: https://salsa.debian.org/security-tracker-team

[Git][security-tracker-team/security-tracker][master] 2 commits: dla-needed: update liblivemedia entry

2019-05-11 Thread Hugo Lefeuvre
= @@ -64,6 +64,8 @@ libav liblivemedia (Hugo Lefeuvre) NOTE: 20190416: CVE-2019-773{2,3}: wait for upstream patch - hle NOTE: 20190502: not sure upstream was aware of them, contacted them via live555 ML. + NOTE: 20190511: my message on the ML is (still

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2019-6470/isc-dhcp

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ab05d727 by Salvatore Bonaccorso at 2019-05-11T08:46:25Z Update status for CVE-2019-6470/isc-dhcp - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed: update hdf5 entry

2019-05-11 Thread Hugo Lefeuvre
ask them for more information. + NOTE: 20190511: upstream was not aware of our undetermined issues. They have assigned + NOTE: a Jira issue for this: https://jira.hdfgroup.org/browse/HDFFV-10755 (hle) -- imagemagick (Hugo Lefeuvre, Markus Koschany) NOTE: 20181227: We should address the many o

[Git][security-tracker-team/security-tracker][master] dla-needed: add notes related to CVE-2019-11598

2019-05-11 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: c4ea09dd by Hugo Lefeuvre at 2019-05-11T08:15:50Z dla-needed: add notes related to CVE-2019-11598 I suspect the patch to contain issues and recommend to not upload it until any doubt removed. - - -

[Git][security-tracker-team/security-tracker][master] automatic update

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c645e690 by security tracker role at 2019-05-11T08:10:19Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-6470/isc-dhcp

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7bda7b1a by Salvatore Bonaccorso at 2019-05-11T06:59:10Z Add CVE-2019-6470/isc-dhcp - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-11884/linux

2019-05-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: de202f3f by Salvatore Bonaccorso at 2019-05-11T06:39:54Z Add CVE-2019-11884/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list