[Git][security-tracker-team/security-tracker][master] CVE-2023-47272 assigned for roundcube issue

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c24dd72 by Salvatore Bonaccorso at 2023-11-06T08:12:41+01:00 CVE-2023-47272 assigned for roundcube issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2023-5341/imagemagick

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 914818ab by Salvatore Bonaccorso at 2023-11-06T06:36:44+01:00 Track fixed version via unstable for CVE-2023-5341/imagemagick - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] update notes

2023-11-05 Thread Thorsten Alteholz (@alteholz)
= @@ -31,7 +31,7 @@ audiofile bind9 (Thorsten Alteholz) NOTE: 20230921: Added by Front-Desk (apo) NOTE: 20231008: backporting patches - NOTE: 20231023: testing package + NOTE: 20231105: still testing package -- cacti (guilhem) NOTE: 20230906: Added

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3646-1 for open-vm-tools

2023-11-05 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 77ba81e6 by Bastien Roucariès at 2023-11-05T22:14:56+00:00 Reserve DLA-3646-1 for open-vm-tools - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3645-1 for trafficserver

2023-11-05 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 324cc691 by Adrian Bunk at 2023-11-05T23:46:29+02:00 Reserve DLA-3645-1 for trafficserver - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] more sudo-rs references

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e72cb96a by Moritz Muehlenhoff at 2023-11-05T21:25:56+01:00 more sudo-rs references - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process one more NFU

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 96136488 by Salvatore Bonaccorso at 2023-11-05T21:21:45+01:00 Process one more NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-5574/xorg-server

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 419556d0 by Salvatore Bonaccorso at 2023-11-05T21:19:31+01:00 Add Debian bug reference for CVE-2023-5574/xorg-server - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9eb29180 by Salvatore Bonaccorso at 2023-11-05T21:18:56+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add three new redmine issues

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8f1d417e by Salvatore Bonaccorso at 2023-11-05T21:18:27+01:00 Add three new redmine issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d3b1d9b by security tracker role at 2023-11-05T20:12:22+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add roundcube entry (no CVE yet)

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b4853a4c by Salvatore Bonaccorso at 2023-11-05T21:05:08+01:00 Add roundcube entry (no CVE yet) - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Move listing CVE-2023-39456 to CVE entry only (only affects bookworm update)

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e891c2c by Salvatore Bonaccorso at 2023-11-05T21:00:54+01:00 Move listing CVE-2023-39456 to CVE entry only (only affects bookworm update) - - - - - 2 changed files: - data/CVE/list -

[Git][security-tracker-team/security-tracker][master] Consider now CVE-2023-5189 as NFU

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2fdf51e5 by Salvatore Bonaccorso at 2023-11-05T20:55:16+01:00 Consider now CVE-2023-5189 as NFU The issue from context in https://bugzilla.redhat.com/show_bug.cgi?id=2234387 looks to be

[Git][security-tracker-team/security-tracker][master] exfatprogs spu, python-websockets ospu

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e947dbf5 by Moritz Mühlenhoff at 2023-11-05T20:51:29+01:00 exfatprogs spu, python-websockets ospu - - - - - 2 changed files: - data/next-oldstable-point-update.txt -

[Git][security-tracker-team/security-tracker][master] ATS, openjdk-17 DSAs

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d9581022 by Moritz Mühlenhoff at 2023-11-05T20:44:11+01:00 ATS, openjdk-17 DSAs - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] GraalVM is not in OpenJDK

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 35db4c69 by Moritz Muehlenhoff at 2023-11-05T20:36:41+01:00 GraalVM is not in OpenJDK - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 1cf10d84 by Moritz Muehlenhoff at 2023-11-05T17:51:49+01:00 bullseye/bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-46361/jbig2dec

2023-11-05 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f19e58d8 by Salvatore Bonaccorso at 2023-11-05T12:15:50+01:00 Add Debian bug reference for CVE-2023-46361/jbig2dec - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] matrix-synapse fixed in sid

2023-11-05 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e10b33b6 by Moritz Muehlenhoff at 2023-11-05T11:52:04+01:00 matrix-synapse fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage node-json5 for buster LTS (CVE-2022-46175)

2023-11-05 Thread Chris Lamb (@lamby)
: = data/dla-needed.txt = @@ -140,6 +140,10 @@ netty (Markus Koschany) NOTE: 20231104: Added by Front-Desk (lamby) NOTE: 20231104: For, at least, CVE-2023-44487. (lamby) -- +node-json5 + NOTE: 20231105: Added by Front-Desk (lamby) + NOTE