[Git][security-tracker-team/security-tracker][master] release slurm-llnl

2022-05-28 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: b352b4f4 by Thorsten Alteholz at 2022-05-29T00:09:07+02:00 release slurm-llnl - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: da94a5b0 by security tracker role at 2022-05-28T20:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add note for slurm-wlm in dsa-needed list

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ccc997f by Salvatore Bonaccorso at 2022-05-28T21:27:34+02:00 Add note for slurm-wlm in dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for rsyslog update

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: daf1e5e3 by Salvatore Bonaccorso at 2022-05-28T21:19:37+02:00 Reserve DSA number for rsyslog update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: add libmatio

2022-05-28 Thread Sylvain Beucler (@beuc)
= @@ -130,6 +130,9 @@ liblouis NOTE: 20220503: CVE-2022-26981 patch applied in salsa lts-team repo, NOTE: 20220503: Patch not applied upstream yet. -- +libmatio + NOTE: 20220528: lots of postponed minor vulnerabilities, no past stretch security upload

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim qemu

2022-05-28 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 87021e6e by Abhijith PA at 2022-05-28T21:24:32+05:30 data/dla-needed.txt: claim qemu - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2022-1215/libinput: reference introductory commit + stretch not-affected

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4f6ea281 by Sylvain Beucler at 2022-05-28T17:44:29+02:00 CVE-2022-1215/libinput: reference introductory commit + stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: add jupyter-notebook

2022-05-28 Thread Sylvain Beucler (@beuc)
-needed.txt = @@ -106,6 +106,9 @@ intel-microcode isync NOTE: 20220523: Follow buster: harmonize with with Debian 10.10 and possibly 11.2 (3 CVEs) (Beuc/front-desk) -- +jupyter-notebook + NOTE: 20220528: wrt CVE-2021-32798, caja is bundled (not external), cf

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2022-25844/angular.js: stretch ignored

2022-05-28 Thread Sylvain Beucler (@beuc)
: rebuild reverse-dependencies if needed, e.g. DLA-2402-1 -> DLA-2453-1/DLA-2454-1/DLA-2455-1; also check buster status (Beuc/front-desk) -- +grunt + NOTE: 20220528: upcoming stable update (cf. #1010211) + 1 new CVE (Beuc/front-desk) +-- halibut (Anton) NOTE: 20220528: Programming languag

[Git][security-tracker-team/security-tracker][master] 3 commits: Remove mysql-connector-java from dla-needed.txt

2022-05-28 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a64575f9 by Markus Koschany at 2022-05-28T16:35:50+02:00 Remove mysql-connector-java from dla-needed.txt mysql-connector-java requires a new upstream release because details about CVE-2022-21363

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-31783/liblouis

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d12ad33 by Salvatore Bonaccorso at 2022-05-28T13:42:40+02:00 Add Debian bug reference for CVE-2022-31783/liblouis - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove bug reference associated with CVE-2021-4261{2,3,4}

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ead0f97b by Salvatore Bonaccorso at 2022-05-28T12:46:16+02:00 Remove bug reference associated with CVE-2021-4261{2,3,4} As the crashing reported there is not associated with the CVEs. - - - -

[Git][security-tracker-team/security-tracker][master] Sync status with kernel-sec for CVE-2022-1786

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5dc5baa1 by Salvatore Bonaccorso at 2022-05-28T12:32:05+02:00 Sync status with kernel-sec for CVE-2022-1786 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add oss-security reference for CVE-2022-1786

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 036f64c9 by Salvatore Bonaccorso at 2022-05-28T12:30:24+02:00 Add oss-security reference for CVE-2022-1786 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: take halibut

2022-05-28 Thread Anton Gladky (@gladk)
OTE: 20220528: Programming language C. -- haproxy NOTE: 20220523: Follow buster: harmonize with with Debian 10.0 and 10.6 (3 CVEs) (Beuc/front-desk) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4852dde80a09a6e967bea594cb5bf61c7e0cd9c1 -- V

[Git][security-tracker-team/security-tracker][master] dla: add halibut

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 69ac6bfc by Sylvain Beucler at 2022-05-28T11:46:15+02:00 dla: add halibut - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add pypdf2

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 429a3b74 by Sylvain Beucler at 2022-05-28T11:36:35+02:00 dla: add pypdf2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Claim pidgin

2022-05-28 Thread @gusnan
Andreas Rönnquist pushed to branch master at Debian Security Tracker / security-tracker Commits: f6492da9 by Andreas Rönnquist at 2022-05-28T11:35:46+02:00 Claim pidgin - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: Fix typo

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b5981190 by Sylvain Beucler at 2022-05-28T11:24:24+02:00 Fix typo - - - - - 75260e87 by Sylvain Beucler at 2022-05-28T11:24:24+02:00 dla: add pyjwt - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7317e706 by Salvatore Bonaccorso at 2022-05-28T11:05:32+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-31782/freetype

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2867c324 by Salvatore Bonaccorso at 2022-05-28T11:02:27+02:00 Add CVE-2022-31782/freetype - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: add pidgin

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0afa0860 by Sylvain Beucler at 2022-05-28T11:01:33+02:00 dla: add pidgin - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-31783/liblouis

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 079e11e6 by Salvatore Bonaccorso at 2022-05-28T10:46:32+02:00 Add CVE-2022-31783/liblouis - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] lts-cve-triage.py: clarify report header

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ef438048 by Sylvain Beucler at 2022-05-28T10:44:26+02:00 lts-cve-triage.py: clarify report header - - - - - 1 changed file: - bin/lts-cve-triage.py Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-12827,CVE-2019-15297/asterisk: precise stretch triage

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 50a0c977 by Sylvain Beucler at 2022-05-28T10:41:37+02:00 CVE-2019-12827,CVE-2019-15297/asterisk: precise stretch triage - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add for now back a todo item for CVE-2021-4270{0,2,4}

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: faf785b6 by Salvatore Bonaccorso at 2022-05-28T10:32:12+02:00 Add for now back a todo item for CVE-2021-4270{0,2,4} As pointed out in the previous commit f134d659cbbe

[Git][security-tracker-team/security-tracker][master] CVE-2021-42700,CVE-2021-42702,CVE-2021-42704/inkscape: add reference

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f134d659 by Sylvain Beucler at 2022-05-28T10:26:21+02:00 CVE-2021-42700,CVE-2021-42702,CVE-2021-42704/inkscape: add reference - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] asterisk uses packaged libpjproject-dev

2022-05-28 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: cba9b4c7 by Abhijith PA at 2022-05-28T13:44:26+05:30 asterisk uses packaged libpjproject-dev - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0850d5ab by security tracker role at 2022-05-28T08:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2022-1897,CVE-2022-1898/vim: stretch postponed

2022-05-28 Thread Sylvain Beucler (@beuc)
with with Debian 10.9 (1 Debian-specific CVE) (Beuc/front-desk) -- +blender + NOTE: 20220528: 3 CVEs now fixed in unstable, but maintainer never was approached to fix in stable/oldstable, + NOTE: 20220528: maybe coordinate with them (Beuc/front-desk) +-- cgal NOTE: 20220421: many no-dsa issues

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3031-1 for modsecurity-apache

2022-05-28 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e45b3ad by Chris Lamb at 2022-05-28T08:40:23+01:00 Reserve DLA-3031-1 for modsecurity-apache - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for libmobi issues

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f4ddfb3d by Salvatore Bonaccorso at 2022-05-28T08:48:39+02:00 Add Debian bug reference for libmobi issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process one NFU

2022-05-28 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8c4a8acb by Salvatore Bonaccorso at 2022-05-28T08:27:03+02:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2022-26498, CVE-2022-26499 not affected for stretch

2022-05-28 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 400c5735 by Abhijith PA at 2022-05-28T11:54:24+05:30 CVE-2022-26498, CVE-2022-26499 not affected for stretch - - - - - 1 changed file: - data/CVE/list Changes: