[Git][security-tracker-team/security-tracker][master] 9 commits: CVE-2023-38199,modsecurity-crs: mark buster as postponed

2023-07-30 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 01f830da by Markus Koschany at 2023-07-31T00:57:09+02:00 CVE-2023-38199,modsecurity-crs: mark buster as postponed Minor issue - - - - - 1da0ed93 by Markus Koschany at 2023-07-31T00:57:10+02:00

[Git][security-tracker-team/security-tracker][master] LTS: claim nodejs and cjose in dla-needed.txt

2023-07-30 Thread Guilhem Moulin (@guilhem)
: = data/dla-needed.txt = @@ -39,7 +39,7 @@ cinder NOTE: 20230525: Added by Front-Desk (lamby) NOTE: 20230525: NB. CVE-2023-2088 filed against python-glance-store, python-os-brick, nova and cinder. -- -cjose +cjose (guilhem) NOTE: 20230730: Added

[Git][security-tracker-team/security-tracker][master] 9 commits: Add cjose to dla-needed.txt

2023-07-30 Thread Markus Koschany (@apo)
] - libitext1-java (Minor issue) [bullseye] - libitext1-java (Minor issue) = data/dla-needed.txt = @@ -24,6 +24,9 @@ rather than remove/replace existing ones. amanda (Thorsten Alteholz) NOTE: 20230730: Added by Front-Desk

[Git][security-tracker-team/security-tracker][master] Reverse order of the CVEs for tiff

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fa588a70 by Salvatore Bonaccorso at 2023-07-31T00:03:00+02:00 Reverse order of the CVEs for tiff Seems that the the CVEs were swappend while filling in the details. CVE-2023-38288 is

[Git][security-tracker-team/security-tracker][master] 2 commits: update note

2023-07-30 Thread Thorsten Alteholz (@alteholz)
) NOTE: 20230730: Added by Front-Desk (apo) -- cairosvg (gladk) @@ -141,7 +141,7 @@ rails ring (Thorsten Alteholz) NOTE: 20221120: Added by Front-Desk (ta) NOTE: 20230507: testing package - NOTE: 20230716: testing package, not all tests pass yet + NOTE: 20230730: testing package, not all

[Git][security-tracker-team/security-tracker][master] fill in details for tiff issues

2023-07-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 0bdc959b by Moritz Muehlenhoff at 2023-07-30T23:33:09+02:00 fill in details for tiff issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] binutils fixed in sid

2023-07-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 41447f96 by Moritz Muehlenhoff at 2023-07-30T23:26:18+02:00 binutils fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fix via unstable for ntpsec issue

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d65b42cf by Salvatore Bonaccorso at 2023-07-30T23:12:20+02:00 Track fix via unstable for ntpsec issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a15e0ad5 by Salvatore Bonaccorso at 2023-07-30T22:20:54+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Adjust commit id for CVE-2018-12934 upstream commit

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1536b80c by Salvatore Bonaccorso at 2023-07-30T22:14:50+02:00 Adjust commit id for CVE-2018-12934 upstream commit - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6eeb5fa8 by security tracker role at 2023-07-30T20:12:29+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] older binutils issue fixed

2023-07-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: dd668a39 by Moritz Muehlenhoff at 2023-07-30T21:45:52+02:00 older binutils issue fixed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] librsvg fixed in sid

2023-07-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 18af1a2e by Moritz Muehlenhoff at 2023-07-30T21:36:35+02:00 librsvg fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] thunderbird DSA

2023-07-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 908d6736 by Moritz Mühlenhoff at 2023-07-30T21:21:06+02:00 thunderbird DSA - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-3648 does not affect buster or bullseye

2023-07-30 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: abb0a9d2 by Adrian Bunk at 2023-07-30T21:05:42+03:00 CVE-2023-3648 does not affect buster or bullseye - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-28864,chef: Link to CVE description, impact, remediation

2023-07-30 Thread Markus Koschany (@apo)
in Buster to backport the --unsafe switch, introduced in 1.0.21, might work (dleidert/inactive) -- +chef + NOTE: 20230730: Added by Front-Desk (apo) + NOTE: 20230730: We could just change the directory permissions to fix this problem. (apo) +-- cinder NOTE: 20230525: Added by Front-Desk

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-30577,amanda: Link to fixing commit

2023-07-30 Thread Markus Koschany (@apo)
the entire history of an update, please append notes rather than remove/replace existing ones. +-- +amanda + NOTE: 20230730: Added by Front-Desk (apo) -- cairosvg (gladk) NOTE: 20230323: Added by Front-Desk (gladk) View it on GitLab: https://salsa.debian.org/security-tracker-team/security

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2023-38408,openssh: triage as no-dsa for Buster

2023-07-30 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7e1b48a3 by Markus Koschany at 2023-07-30T17:11:21+02:00 CVE-2023-38408,openssh: triage as no-dsa for Buster Requires specific conditions like forwarding and an already compromised system. - - - -

[Git][security-tracker-team/security-tracker][master] 2 commits: Add upstream tag reference for CVE-2022-34927 fix upstream

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c9f932e by Salvatore Bonaccorso at 2023-07-30T15:05:45+02:00 Add upstream tag reference for CVE-2022-34927 fix upstream - - - - - 430234d8 by Salvatore Bonaccorso at 2023-07-30T15:07:16+02:00

[Git][security-tracker-team/security-tracker][master] LTS: set myself as a FD for next week

2023-07-30 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 5ed8ad67 by Anton Gladky at 2023-07-30T14:46:33+02:00 LTS: set myself as a FD for next week - - - - - 1 changed file: - org/lts-frontdesk.2023.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e980dc2 by Salvatore Bonaccorso at 2023-07-30T14:42:31+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b3c3dfe by security tracker role at 2023-07-30T08:12:11+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DSA numbers for linux update

2023-07-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d7732e4 by Salvatore Bonaccorso at 2023-07-30T08:52:16+02:00 Reserve DSA numbers for linux update Make them separate as exception (the not equal set of CVEs could be workarounded easily). -