[Git][security-tracker-team/security-tracker][master] 2 commits: follow sec team with ignoring CVE-2023-45853 for Buster

2023-11-19 Thread Thorsten Alteholz (@alteholz)
) - minizip NOTE: https://github.com/madler/zlib/pull/843 NOTE: https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c = data/dla-needed.txt = @@ -285,6 +285,3 @@ zabbix zbar NOTE: 20231119

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-20031 as NFU

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 665a6def by Salvatore Bonaccorso at 2023-11-20T07:06:54+01:00 Mark CVE-2023-20031 as NFU According to the upstream advisory it is for Products Confirmed Not Vulnerable covering Open Source

[Git][security-tracker-team/security-tracker][master] LTS: note in dla_neded

2023-11-19 Thread Anton Gladky (@gladk)
: 20231120: many CVEs, check with ASAN is needed. (gladk) -- frr NOTE: 20231119: Added by Front-Desk (apo) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16e6f3b6512b453ff0939ec5f3289d8b7bca143b -- View it on GitLab: https://salsa.debian.org

[Git][security-tracker-team/security-tracker][master] Reference upstream issue for CVE-2023-48011

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 253fabd0 by Salvatore Bonaccorso at 2023-11-20T06:57:34+01:00 Reference upstream issue for CVE-2023-48011 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Take netatalk and libde265

2023-11-19 Thread Anton Gladky (@gladk)
-needed.txt = @@ -106,7 +106,7 @@ keystone knot-resolver NOTE: 20231029: Added by Front-Desk (gladk) -- -libde265 +libde265 (gladk) NOTE: 20231119: Added by Front-Desk (apo) NOTE: 20231119: Fix along with postponed issues. -- @@ -138,7 +138,7 @@ mediawiki

[Git][security-tracker-team/security-tracker][master] dla: take gimp

2023-11-19 Thread Adrian Bunk (@bunk)
= @@ -77,7 +77,7 @@ freeimage (gladk) frr NOTE: 20231119: Added by Front-Desk (apo) -- -gimp +gimp (Adrian Bunk) NOTE: 20231117: Added by Front-Desk (apo) -- gnutls28 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] dla: give back libstb and add note to recommend waiting for upstream merging of fixes

2023-11-19 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: abee3c89 by Adrian Bunk at 2023-11-19T23:25:59+02:00 dla: give back libstb and add note to recommend waiting for upstream merging of fixes - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2023-5157 does not affect galera-3

2023-11-19 Thread Adrian Bunk (@bunk)
: 20231119: Added by Front-Desk (apo) -- -galera-3 (Adrian Bunk) - NOTE: 20231028: Added by Front-Desk (gladk) - NOTE: 20231028: Acc. to CVE notes the open issue is fixed in 26.4.12. Please, try to find a corresponding commit and try to backport it. Otherwise - no-dsa. (gladk) - NOTE: 20231113

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-48011: link to correct fixing commit again

2023-11-19 Thread Markus Koschany (@apo)
.txt = @@ -277,7 +277,7 @@ vlc wireshark (Adrian Bunk) NOTE: 20231118: Added by Front-Desk (apo) -- -wordpress +wordpress (Markus Koschany) NOTE: 20231119: Added by Front-Desk (apo) -- zabbix View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tra

[Git][security-tracker-team/security-tracker][master] NFUs

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 280b5aa1 by Moritz Muehlenhoff at 2023-11-19T21:29:52+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add golang-1.19 to ignored packages, will be RMed soon

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 91cc2688 by Moritz Mühlenhoff at 2023-11-19T21:12:48+01:00 Add golang-1.19 to ignored packages, will be RMed soon - - - - - 1 changed file: - data/packages/ignored-debian-bug-packages

[Git][security-tracker-team/security-tracker][master] new derby issue

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5b7c7a2e by Moritz Muehlenhoff at 2023-11-19T21:10:55+01:00 new derby issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] bugnums

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5ea1efad by Moritz Muehlenhoff at 2023-11-19T21:09:16+01:00 bugnums - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-5981/gnutls28 as no-dsa

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dea2c17 by Salvatore Bonaccorso at 2023-11-19T21:03:23+01:00 Mark CVE-2023-5981/gnutls28 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-46175: Add upstream tag information and adjust commit reference

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 15f8683e by Salvatore Bonaccorso at 2023-11-19T21:02:20+01:00 CVE-2022-46175: Add upstream tag information and adjust commit reference - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixes which were included between 4.0.6-1~deb12u1 and 4.0.11-1~deb12u1...

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f54e74ed by Salvatore Bonaccorso at 2023-11-19T20:57:33+01:00 Track fixes which were included between 4.0.6-1~deb12u1 and 4.0.11-1~deb12u1 directly as well in DSA list - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] pixman non issue

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 790c86cd by Moritz Muehlenhoff at 2023-11-19T20:56:17+01:00 pixman non issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] janino unimportant

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e8efb7b2 by Moritz Muehlenhoff at 2023-11-19T20:50:18+01:00 janino unimportant - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] mark two barbican issues as RH-specific

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 4cbe2803 by Moritz Muehlenhoff at 2023-11-19T20:41:52+01:00 mark two barbican issues as RH-specific - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add fix from upstream for node-json5 CVE-2022-46175

2023-11-19 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: b7b3a286 by Bastien Roucariès at 2023-11-19T19:39:03+00:00 Add fix from upstream for node-json5 CVE-2022-46175 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add myself for node-json5

2023-11-19 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f8669ae by Bastien Roucariès at 2023-11-19T19:37:41+00:00 Add myself for node-json5 - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] wireshark DSA

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c73e3a30 by Moritz Mühlenhoff at 2023-11-19T20:27:43+01:00 wireshark DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim amanda in dla-needed.txt

2023-11-19 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: a63f0bd4 by Tobias Frost at 2023-11-19T20:26:07+01:00 LTS: claim amanda in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] wireshark updates

2023-11-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ed2dc02 by Moritz Muehlenhoff at 2023-11-19T20:21:11+01:00 wireshark updates - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-45853/zlib

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 519fa4ad by Salvatore Bonaccorso at 2023-11-19T19:16:33+01:00 Update status for CVE-2023-45853/zlib - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-48052/httpie

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4898b641 by Salvatore Bonaccorso at 2023-11-19T13:40:03+01:00 Add CVE-2023-48052/httpie - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ae8273b3 by Salvatore Bonaccorso at 2023-11-19T13:39:20+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed for audiofile via unstable

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c03d677 by Salvatore Bonaccorso at 2023-11-19T13:36:13+01:00 Track fixed for audiofile via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-46604/activemq via unstable

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ec5c578a by Salvatore Bonaccorso at 2023-11-19T13:34:50+01:00 Track fixed version for CVE-2023-46604/activemq via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] data/ela-needed.txt: claim varnish

2023-11-19 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 74505a75 by Abhijith PA at 2023-11-19T17:15:14+05:30 data/ela-needed.txt: claim varnish - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] update note

2023-11-19 Thread Thorsten Alteholz (@alteholz)
= @@ -27,7 +27,7 @@ amanda bind9 (Thorsten Alteholz) NOTE: 20230921: Added by Front-Desk (apo) NOTE: 20231008: backporting patches - NOTE: 20231105: still testing package + NOTE: 20231119: almost done with testing -- cacti NOTE: 20230906: Added by Front

[Git][security-tracker-team/security-tracker][master] 2 commits: mark CVE-2023-42118 as postponed for Buster

2023-11-19 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: bbdc482f by Thorsten Alteholz at 2023-11-19T12:25:47+01:00 mark CVE-2023-42118 as postponed for Buster - - - - - 5e55e16e by Thorsten Alteholz at 2023-11-19T12:26:57+01:00 mark CVE for libspf2 as

[Git][security-tracker-team/security-tracker][master] automatic update

2023-11-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 937b8b8e by security tracker role at 2023-11-19T08:11:30+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list