[Git][security-tracker-team/security-tracker][master] Update note in dla-needed.txt

2021-07-19 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: e99c9a9a by Abhijith PA at 2021-07-20T09:33:23+05:30 Update note in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-36213/consul

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 91fe0e18 by Salvatore Bonaccorso at 2021-07-19T22:22:34+02:00 Add CVE-2021-36213/consul - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-36427/gthumb

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d7a1842a by Salvatore Bonaccorso at 2021-07-19T22:21:37+02:00 Add CVE-2020-36427/gthumb - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process more NFUs

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cce09b73 by Salvatore Bonaccorso at 2021-07-19T22:19:06+02:00 Process more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1b7725ab by Salvatore Bonaccorso at 2021-07-19T22:12:50+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 12cac4f7 by security tracker role at 2021-07-19T20:10:21+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add GHSA reference for CVE-2021-32760/containerd

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 149aca6c by Salvatore Bonaccorso at 2021-07-19T21:22:28+02:00 Add GHSA reference for CVE-2021-32760/containerd - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-32760/containerd

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aaca7211 by Salvatore Bonaccorso at 2021-07-19T21:19:23+02:00 Add CVE-2021-32760/containerd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: Take firmware-nonfree

2021-07-19 Thread Anton Gladky (@gladk)
= @@ -48,7 +48,7 @@ ffmpeg (Anton Gladky) NOTE: 20210719: https://salsa.debian.org/lts-team/packages/ffmpeg/-/blob/master/debian/changelog NOTE: 20210719: CVE-2020-22036 and CVE-2020-22032 are done. Many false-positive. Investigating. -- -firmware

[Git][security-tracker-team/security-tracker][master] LTS: give runc to Abhijith PA

2021-07-19 Thread Anton Gladky (@gladk)
-needed.txt = @@ -108,7 +108,7 @@ ruby-kaminari NOTE: 20210719: I believe the fix is just adding and extending the blacklist for ruby-kaminari. NOTE: 20210719: Will discuss this with Utkarsh (maintainer) shortly. -- -runc (Anton Gladky) +runc (Abhijith PA

[Git][security-tracker-team/security-tracker][master] Update NOTES for ruby-kaminari.

2021-07-19 Thread Markus Koschany (@apo)
to be written. Opened an issue at upstream, though somewhat inactive. (utkarsh) + NOTE: 20210719: https://people.debian.org/~apo/lts/ruby-kaminari/CVE-2020-11082.patch + NOTE: 20210719: I believe the fix is just adding and extending the blacklist for ruby-kaminari. + NOTE: 20210719: Will discuss

[Git][security-tracker-team/security-tracker][master] CVE-2021-34552: Reference as well directly the upstream commit merged

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0cf40dde by Salvatore Bonaccorso at 2021-07-19T17:42:08+02:00 CVE-2021-34552: Reference as well directly the upstream commit merged - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: update note on ffmpeg. Take runc.

2021-07-19 Thread Anton Gladky (@gladk)
. etc. (lamby) - NOTE: 20210719: WIP + NOTE: 20210719: https://salsa.debian.org/lts-team/packages/ffmpeg/-/blob/master/debian/changelog + NOTE: 20210719: CVE-2020-22036 and CVE-2020-22032 are done. Many false-positive. Investigating. -- firmware-nonfree -- @@ -104,7 +105,7 @@ ruby-kaminari

[Git][security-tracker-team/security-tracker][master] lts: reclaim nettle

2021-07-19 Thread Emilio Pozuelo Monfort (@pochu)
/dla-needed.txt = @@ -71,8 +71,8 @@ linux (Ben Hutchings) -- linux-4.19 (Ben Hutchings) -- -nettle - NOTE: 20210628: difficult backport, wip (Emilio) +nettle (Emilio) + NOTE: 20210719: difficult backport, wip (Emilio) -- nvidia-graphics-drivers NOTE

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2711-1 for thunderbird

2021-07-19 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: e0f7a0a7 by Emilio Pozuelo Monfort at 2021-07-19T12:44:03+02:00 Reserve DLA-2711-1 for thunderbird - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: take ffmpeg again

2021-07-19 Thread Anton Gladky (@gladk)
@@ ffmpeg NOTE: 20210607: going forward. There is a 3.4.x release branch, for example, NOTE: 20210607: but unclear on the compatibility as well as whether this one NOTE: 20210607: won't just be dropped too, etc. etc. (lamby) - NOTE: 20210704: WIP + NOTE: 20210719: WIP -- firmware-nonfree

[Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity

2021-07-19 Thread Holger Levsen (@holger)
Holger Levsen pushed to branch master at Debian Security Tracker / security-tracker Commits: ad26ed01 by Holger Levsen at 2021-07-19T12:01:34+02:00 semi-automatic unclaim after 2 weeks of inactivity Signed-off-by: Holger Levsen hol...@layer-acht.org - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2710-1 for rabbitmq-server

2021-07-19 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 1150eee6 by Abhijith PA at 2021-07-19T14:36:45+05:30 Reserve DLA-2710-1 for rabbitmq-server - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2021-07-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 509d196b by Moritz Muehlenhoff at 2021-07-19T10:58:30+02:00 NFUs drop one TODO for mongo-driver, if relevant it would get handled via k8s - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add tracking note for pillow

2021-07-19 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 49fb4688 by Neil Williams at 2021-07-19T09:19:41+01:00 Add tracking note for pillow - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2021-07-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d628d9aa by security tracker role at 2021-07-19T08:10:14+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list