[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f0ac5c36 by Salvatore Bonaccorso at 2019-05-28T20:24:52Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-9154/jasper

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 331ba0e6 by Salvatore Bonaccorso at 2019-05-28T20:17:26Z Add CVE-2018-9154/jasper - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 08885669 by security tracker role at 2019-05-28T20:10:21Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add zookeeper to dsa-needed list

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e66e6b73 by Salvatore Bonaccorso at 2019-05-28T19:01:44Z Add zookeeper to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Remove no-dsa tagged entries for heimdal

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b0839a1 by Salvatore Bonaccorso at 2019-05-28T19:00:20Z Remove no-dsa tagged entries for heimdal - - - - - 14158ac5 by Salvatore Bonaccorso at 2019-05-28T19:00:59Z Add heimdal to dsa-needed

[Git][security-tracker-team/security-tracker][master] Remove unecessary unfixed entry

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dd70836 by Salvatore Bonaccorso at 2019-05-28T18:11:17Z Remove unecessary unfixed entry - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Drop simplesamlphp

2019-05-28 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 420cb79d by Chris Lamb at 2019-05-28T16:32:42Z data/dla-needed.txt: Drop simplesamlphp As the maintainer I have triaged all open issues and see no reason for releasing a jessie update at this point. -

[Git][security-tracker-team/security-tracker][master] Mark CVE-2018-15822/libav as removed, but unresolved in jessie.

2019-05-28 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b46a518 by Mike Gabriel at 2019-05-28T15:50:45Z Mark CVE-2018-15822/libav as removed, but unresolved in jessie. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-1000016/libav as removed

2019-05-28 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 875aa42f by Mike Gabriel at 2019-05-28T15:20:47Z Mark CVE-2019-116/libav as removed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2019-12219: affects libsdl-image, not libsdl

2019-05-28 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 386c1155 by Hugo Lefeuvre at 2019-05-28T15:01:49Z CVE-2019-12219: affects libsdl-image, not libsdl Very similar to CVE-2019-12220 and CVE-2019-1. The vulnerability lies in the sdl_image code

[Git][security-tracker-team/security-tracker][master] CVE-2019-12220: affects libsdl-image, not libsdl

2019-05-28 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 5bb51229 by Hugo Lefeuvre at 2019-05-28T14:54:16Z CVE-2019-12220: affects libsdl-image, not libsdl Very similar to CVE-2019-1. The vulnerability lies in the sdl_image code base. See patch

[Git][security-tracker-team/security-tracker][master] dla-needed: update regarding sdl issues

2019-05-28 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 873bb439 by Hugo Lefeuvre at 2019-05-28T14:45:13Z dla-needed: update regarding sdl issues - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Mark libav in jessie as not affected by CVE-2019-1000016,

2019-05-28 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: fd7f32b2 by Mike Gabriel at 2019-05-28T14:40:08Z data/CVE/list: Mark libav in jessie as not affected by CVE-2019-116, - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-12222: affects libsdl-image, not libsdl

2019-05-28 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 46a58742 by Hugo Lefeuvre at 2019-05-28T14:30:30Z CVE-2019-1: affects libsdl-image, not libsdl After investigating the issue, I found out that the vulnerability lies in the sdl_image code base.

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-11338/libav as removed

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f428a555 by Salvatore Bonaccorso at 2019-05-28T14:29:30Z Mark CVE-2019-11338/libav as removed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-9718/libav as removed

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 146a51c9 by Salvatore Bonaccorso at 2019-05-28T14:28:55Z Mark CVE-2019-9718/libav as removed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-9721/libav as removed

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 056030ef by Salvatore Bonaccorso at 2019-05-28T14:28:18Z Mark CVE-2019-9721/libav as removed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 4 commits: data/dla-needed.txt: update status of qemu.

2019-05-28 Thread Mike Gabriel
= @@ -101,6 +101,10 @@ python3.4 (Roberto C. Sánchez) NOTE: 20190519: Patches integrated for CVE-2018-14647, CVE-2019-9636, CVE-2019-9947 and CVE-2019-9740 (roberto) -- qemu (Mike Gabriel) + NOTE: 20190528: An upload candidate is waiting for being tested on real hardware. + NOTE: 20190528

[Git][security-tracker-team/security-tracker][master] mercurial fixed in tpu

2019-05-28 Thread Julien Cristau
Julien Cristau pushed to branch master at Debian Security Tracker / security-tracker Commits: 20aa21dd by Julien Cristau at 2019-05-28T13:59:59Z mercurial fixed in tpu - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: take php5

2019-05-28 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: e093b276 by Emilio Pozuelo Monfort at 2019-05-28T12:16:00Z dla: take php5 - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: retake poppler

2019-05-28 Thread Emilio Pozuelo Monfort
open CVEs (sunweaver) +poppler (Emilio) + NOTE: 20190528: backporting patches for fixed issues, some of these could be no-dsa (Emilio) -- python-urllib3 (Roberto C. Sánchez) NOTE: 20190518: Fix for CVE-2019-11236 has been backported (roberto) View it on GitLab: https://salsa.debian.org

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim libav

2019-05-28 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: ecf45c0a by Mike Gabriel at 2019-05-28T12:12:41Z data/dla-needed.txt: claim libav - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] fix syntax

2019-05-28 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 1136cf25 by Moritz Muehlenhoff at 2019-05-28T11:51:37Z fix syntax new tor browser/firefox issue - - - - - 1 changed file: - data/CVE/list Changes: =

Processing 0b775112910e7527b844d5205ebdf59ab78a9453 failed

2019-05-28 Thread security tracker role
The error message was: data/CVE/list:39682: expected CVE annotation, got: 'https://lists.clusterlabs.org/pipermail/users/2019-May/025822.html' Makefile:33: recipe for target 'all' failed make: *** [all] Error 1 ___ debian-security-tracker-commits

[Git][security-tracker-team/security-tracker][master] pacemaker: Link to necessary commits for backport of security fixes.

2019-05-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0b775112 by Markus Koschany at 2019-05-28T11:33:22Z pacemaker: Link to necessary commits for backport of security fixes. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] octavia n/a

2019-05-28 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9db9cedf by Moritz Muehlenhoff at 2019-05-28T11:14:34Z octavia n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 77b9f9f3 by Salvatore Bonaccorso at 2019-05-28T08:44:13Z Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2018-12886/gcc ignored on jessie

2019-05-28 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 41d5c070 by Emilio Pozuelo Monfort at 2019-05-28T08:28:39Z CVE-2018-12886/gcc ignored on jessie - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add initial source package status tracking for CVE-2019-123{78,79,80,81,82}

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ccd6f57e by Salvatore Bonaccorso at 2019-05-28T08:27:51Z Add initial source package status tracking for CVE-2019-123{78,79,80,81,82} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2019-05-28 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ee4fc785 by security tracker role at 2019-05-28T08:10:13Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] qemu fixed

2019-05-28 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b51400de by Moritz Muehlenhoff at 2019-05-28T07:24:46Z qemu fixed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1808-1 for sox

2019-05-28 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: f5c6a238 by Emilio Pozuelo Monfort at 2019-05-28T07:10:15Z Reserve DLA-1808-1 for sox - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: