[Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity

2021-12-27 Thread Jeremiah C. Foster (@jeremiah)
Jeremiah C. Foster pushed to branch master at Debian Security Tracker / security-tracker Commits: 1a76800c by Jeremiah C. Foster at 2021-12-28T01:05:24-05:00 semi-automatic unclaim after 2 weeks of inactivity Signed-off-by: Jeremiah C. Foster jerem...@jeremiahfoster.com - - - - - 1

[Git][security-tracker-team/security-tracker][master] 2 commits: fix for CVE-2020-18442 postponed until now

2021-12-27 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: d71330d3 by Thorsten Alteholz at 2021-12-28T00:47:49+01:00 fix for CVE-2020-18442 postponed until now - - - - - 8c446b4c by Thorsten Alteholz at 2021-12-28T00:48:42+01:00 Reserve DLA-2859-1 for

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2017-14107 has been fixed with recent upload

2021-12-27 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: f432120d by Thorsten Alteholz at 2021-12-27T23:48:58+01:00 CVE-2017-14107 has been fixed with recent upload - - - - - f6ec7c5b by Thorsten Alteholz at 2021-12-28T00:40:28+01:00 Reserve DLA-2858-1

[Git][security-tracker-team/security-tracker][master] RPKI updates

2021-12-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c53e3aa1 by Moritz Mühlenhoff at 2021-12-27T23:27:03+01:00 RPKI updates - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2857-1 for postgis

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 389a533b by Adrian Bunk at 2021-12-28T00:01:58+02:00 Reserve DLA-2857-1 for postgis - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2856-1 for okular

2021-12-27 Thread Adrian Bunk (@bunk)
on the lts NOTE: mailing list tomorrow (apo) -- -okular (Adrian Bunk) --- paramiko (Utkarsh) NOTE: 20211227: CVE-2018-7750 and CVE-2018-1000805 were fixed in DLA-1556-1 NOTE: 20211227: in jessie but are unfixed in stretch (bunk) View it on GitLab: https://salsa.debian.org/security

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-4173/vim

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8626a43f by Salvatore Bonaccorso at 2021-12-27T21:29:36+01:00 Add CVE-2021-4173/vim - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bf667dcc by Salvatore Bonaccorso at 2021-12-27T21:29:06+01:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b236f0ab by security tracker role at 2021-12-27T20:10:16+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2021-4024/libpod via unstable

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 50baac2a by Salvatore Bonaccorso at 2021-12-27T21:06:41+01:00 Add fixed version for CVE-2021-4024/libpod via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update upstream commits for 3.4 branch for CVE-2021-4024/libpod

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 188c61a5 by Salvatore Bonaccorso at 2021-12-27T21:01:18+01:00 Update upstream commits for 3.4 branch for CVE-2021-4024/libpod - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2855-1 for monit

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: efcc7d15 by Adrian Bunk at 2021-12-27T21:12:56+02:00 Reserve DLA-2855-1 for monit - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Take paramiko

2021-12-27 Thread Utkarsh Gupta (@utkarsh)
= @@ -84,7 +84,7 @@ nvidia-graphics-drivers (Markus Koschany) -- okular (Adrian Bunk) -- -paramiko +paramiko (Utkarsh) NOTE: 20211227: CVE-2018-7750 and CVE-2018-1000805 were fixed in DLA-1556-1 NOTE: 20211227: in jessie but are unfixed in stretch (bunk

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2854-1 for novnc

2021-12-27 Thread Utkarsh Gupta (@utkarsh)
ruby2.3 - security update {CVE-2021-41817 CVE-2021-41819} [stretch] - ruby2.3 2.3.3-1+deb9u11 = data/dla-needed.txt = @@ -73,10 +73,6 @@ lxml (Utkarsh) -- monit (Adrian Bunk) -- -novnc (Utkarsh) - NOTE: 20211227

[Git][security-tracker-team/security-tracker][master] dla: take postgis

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: a1b735d0 by Adrian Bunk at 2021-12-27T19:06:29+02:00 dla: take postgis - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-3197, CVE-2020-28243, CVE-2021-25282, CVE-2021-25284/salt: reference...

2021-12-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e5e6ad54 by Sylvain Beucler at 2021-12-27T17:48:16+01:00 CVE-2021-3197,CVE-2020-28243,CVE-2021-25282,CVE-2021-25284/salt: reference regression follow-up reports for salt/stretch regression

[Git][security-tracker-team/security-tracker][master] dla: add paramiko

2021-12-27 Thread Adrian Bunk (@bunk)
= @@ -88,6 +88,10 @@ nvidia-graphics-drivers (Markus Koschany) -- okular (Adrian Bunk) -- +paramiko + NOTE: 20211227: CVE-2018-7750 and CVE-2018-1000805 were fixed in DLA-1556-1 + NOTE: 20211227: in jessie but are unfixed in stretch (bunk) +-- pgbouncer (Christoph

[Git][security-tracker-team/security-tracker][master] Take novnc

2021-12-27 Thread Utkarsh Gupta (@utkarsh)
2 days. (utkarsh) + NOTE: 20211227: waiting on upstream to get feedback. (utkarsh) -- libraw NOTE: 20211227: 7 CVEs that were fixed for jessie in DLA-1734-1 are unfixed @@ -72,7 +73,7 @@ lxml (Utkarsh) -- monit (Adrian Bunk) -- -novnc +novnc (Utkarsh) NOTE: 20211227: CVE-2017-18635

[Git][security-tracker-team/security-tracker][master] dla: take okular

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 52a6ffca by Adrian Bunk at 2021-12-27T18:31:56+02:00 dla: take okular - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add novnc

2021-12-27 Thread Adrian Bunk (@bunk)
= @@ -72,6 +72,10 @@ lxml (Utkarsh) -- monit (Adrian Bunk) -- +novnc + NOTE: 20211227: CVE-2017-18635 was fixed in jessie in DLA-1946-1 + NOTE: 20211227: but is unfixed in stretch (bunk) +-- nvidia-graphics-drivers (Markus Koschany) NOTE: package is in non-free

[Git][security-tracker-team/security-tracker][master] dla: take monit

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 00b6e67b by Adrian Bunk at 2021-12-27T18:20:41+02:00 dla: take monit - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] mesa: CVE-2019-5068 code is not built in stretch

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 6735c716 by Adrian Bunk at 2021-12-27T18:13:02+02:00 mesa: CVE-2019-5068 code is not built in stretch - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-2870 and CVE-2017-6311 in gdk-pixbuf as ignored, not not-affected in stretch

2021-12-27 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 063b72dd by Adrian Bunk at 2021-12-27T10:33:00+02:00 Mark CVE-2017-2870 and CVE-2017-6311 in gdk-pixbuf as ignored, not not-affected in stretch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2021-41229/bluez

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9db5f556 by Salvatore Bonaccorso at 2021-12-27T09:16:19+01:00 Track fixed version for CVE-2021-41229/bluez - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2021-12-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f62dde9 by security tracker role at 2021-12-27T08:10:10+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list