[Git][security-tracker-team/security-tracker][master] 3 commits: add yajl

2023-07-02 Thread Thorsten Alteholz (@alteholz)
) -- +yajl (tobi) + NOTE: 20230702: Added by Front-Desk (ta) +-- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ab48cb7e37aa9475bb69485eab889d5f8f70bb5d...430ae6821506cd4290eacaa2d66eb4b328c866e2 -- View it on GitLab: https://salsa.debian.org

[Git][security-tracker-team/security-tracker][master] dla: take tiff

2023-07-02 Thread Adrian Bunk (@bunk)
= @@ -251,7 +251,7 @@ symfony (guilhem) syncthing (Abhijith PA) NOTE: 20230616: Added by Front-Desk (opal) -- -tiff +tiff (Adrian Bunk) NOTE: 20230702: Added by Front-Desk (ta) -- webkit2gtk (Emilio) View it on GitLab: https://salsa.debian.org/security-tracker

[Git][security-tracker-team/security-tracker][master] automatic update

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69c7d7ef by security tracker role at 2023-07-02T20:13:36+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track nvidia-graphics-drivers-tesla-510 as removed from everywhere

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5b13c039 by Salvatore Bonaccorso at 2023-07-02T21:22:16+02:00 Track nvidia-graphics-drivers-tesla-510 as removed from everywhere - - - - - 1 changed file: - data/packages/removed-packages

[Git][security-tracker-team/security-tracker][master] Track fixed versions via unstable for nvidia-graphics-drivers-tesla-510 issues

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 07e4135c by Salvatore Bonaccorso at 2023-07-02T21:21:35+02:00 Track fixed versions via unstable for nvidia-graphics-drivers-tesla-510 issues - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-24809,nethack: fixed in unstable

2023-07-02 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 003e787b by Markus Koschany at 2023-07-02T21:05:35+02:00 CVE-2023-24809,nethack: fixed in unstable - - - - - 4e08f493 by Markus Koschany at 2023-07-02T21:10:47+02:00 Claim mediawiki and erlang in

[Git][security-tracker-team/security-tracker][master] Fix one source package name

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f3e36f6e by Salvatore Bonaccorso at 2023-07-02T21:00:20+02:00 Fix one source package name - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] add tiff

2023-07-02 Thread Thorsten Alteholz (@alteholz)
= @@ -251,6 +251,9 @@ symfony (guilhem) syncthing (Abhijith PA) NOTE: 20230616: Added by Front-Desk (opal) -- +tiff + NOTE: 20230702: Added by Front-Desk (ta) +-- webkit2gtk (Emilio) NOTE: 20230512: Re-added (pochu) NOTE: 20230512: checking if upgrade

[Git][security-tracker-team/security-tracker][master] add gst-plugins-*

2023-07-02 Thread Thorsten Alteholz (@alteholz)
-needed.txt = @@ -79,6 +79,15 @@ grpc NOTE: 20230614: Added by Front-Desk (opal) NOTE: 20230618: CVE-2023-32731 fix will need a massive rewrite (rouca) -- +gst-plugins-bad1.0 (Thorsten Alteholz) + NOTE: 20230702: Added by Front-Desk (ta) +-- +gst-plugins-base1.0

[Git][security-tracker-team/security-tracker][master] Remove some source package listings for yajl issues

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fede245d by Salvatore Bonaccorso at 2023-07-02T20:47:14+02:00 Remove some source package listings for yajl issues Link:

[Git][security-tracker-team/security-tracker][master] xqilla also embeds yajl, is vulnerable to CVE-2017-16516 and CVE-2022-24795.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 0b62bb6d by Tobias Frost at 2023-07-02T19:20:51+02:00 xqilla also embeds yajl, is vulnerable to CVE-2017-16516 and CVE-2022-24795. - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Triage packages with embedded code copies of yajl for CVE-2022-24795,...

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ca70a32 by Tobias Frost at 2023-07-02T18:54:45+02:00 Triage packages with embedded code copies of yajl for CVE-2022-24795, CVE-2017-16516 and CVE-2023-33460 - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] LTS: take openimageio

2023-07-02 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 787f91d4 by Anton Gladky at 2023-07-02T18:47:46+02:00 LTS: take openimageio - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Fix typo in embedded-code-copies for yajl.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 93ed3e00 by Tobias Frost at 2023-07-02T17:51:54+02:00 Fix typo in embedded-code-copies for yajl. - - - - - 1 changed file: - data/embedded-code-copies Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-16516 and CVE-2022-24795 for now as unfixed according to #1040036

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ae4f8aa by Salvatore Bonaccorso at 2023-07-02T14:43:41+02:00 Mark CVE-2017-16516 and CVE-2022-24795 for now as unfixed according to #1040036 - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2022-24795 and CVE-2017-16516 also affects yajl.

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ec6a443 by Tobias Frost at 2023-07-02T14:19:51+02:00 CVE-2022-24795 and CVE-2017-16516 also affects yajl. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track proposed yajl updates via {bookworm,bullseye}-pu

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 792006c2 by Salvatore Bonaccorso at 2023-07-02T14:03:25+02:00 Track proposed yajl updates via {bookworm,bullseye}-pu - - - - - 2 changed files: - data/next-oldstable-point-update.txt -

[Git][security-tracker-team/security-tracker][master] Fix version number of yajl upload

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: ce3a1614 by Tobias Frost at 2023-07-02T14:02:41+02:00 Fix version number of yajl upload - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3478-1 for yajl

2023-07-02 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 4da854d9 by Tobias Frost at 2023-07-02T13:07:45+02:00 Reserve DLA-3478-1 for yajl - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2023-3439: Ass oss-security post reference

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6cb21833 by Salvatore Bonaccorso at 2023-07-02T13:03:11+02:00 CVE-2023-3439: Ass oss-security post reference - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] yajl fixed in sid

2023-07-02 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: fa735f95 by Moritz Muehlenhoff at 2023-07-02T12:12:27+02:00 yajl fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] libheif fixed in sid

2023-07-02 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 0371b96c by Moritz Muehlenhoff at 2023-07-02T12:11:32+02:00 libheif fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track version where whitedb starts using system yajl library

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1cbd3529 by Salvatore Bonaccorso at 2023-07-02T11:48:30+02:00 Track version where whitedb starts using system yajl library - - - - - 1 changed file: - data/embedded-code-copies Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-37360/pacparser

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c07d7c54 by Salvatore Bonaccorso at 2023-07-02T09:23:19+02:00 Add CVE-2023-37360/pacparser - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-37365/hnswlib

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 513b6bcc by Salvatore Bonaccorso at 2023-07-02T09:22:29+02:00 Add CVE-2023-37365/hnswlib - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 47d87ec6 by Salvatore Bonaccorso at 2023-07-02T09:20:52+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-36191 /sqlite3

2023-07-02 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4447a429 by Salvatore Bonaccorso at 2023-07-02T08:45:59+02:00 Add CVE-2023-36191 /sqlite3 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] add fix references for CVEless entries

2023-07-02 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b5ea0ec9 by Moritz Mühlenhoff at 2023-07-02T08:44:02+02:00 add fix references for CVEless entries - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] gst-plugins DSAs

2023-07-02 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 00022cc3 by Moritz Mühlenhoff at 2023-07-02T08:38:17+02:00 gst-plugins DSAs - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =