[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-21428 as not-affected for stretch

2023-11-27 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 6619bfa5 by Anton Gladky at 2023-11-28T06:52:43+01:00 Mark CVE-2020-21428 as not-affected for stretch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-22084 for MariaDB

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c7192f64 by Salvatore Bonaccorso at 2023-11-28T06:45:53+01:00 Add CVE-2023-22084 for MariaDB - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Remove duplicate tracking of pending update for glewlwyd

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 88bfac79 by Salvatore Bonaccorso at 2023-11-28T06:30:30+01:00 Remove duplicate tracking of pending update for glewlwyd - - - - - 1 changed file: - data/next-oldstable-point-update.txt

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-45360/mediawiki as no-dsa for buster.

2023-11-27 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: b37cad8d by Guilhem Moulin at 2023-11-28T01:18:00+01:00 Mark CVE-2023-45360/mediawiki as no-dsa for buster. Prior to 1.32 all sysops could edit sitewide CSS/JS hence inject XSS via

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3670-1 for minizip

2023-11-27 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 72ec5d16 by Thorsten Alteholz at 2023-11-28T00:03:01+01:00 Reserve DLA-3670-1 for minizip - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] glewlwyd ospu

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 582f7bbb by Moritz Mühlenhoff at 2023-11-27T22:48:24+01:00 glewlwyd ospu - - - - - 1 changed file: - data/next-oldstable-point-update.txt Changes: =

[Git][security-tracker-team/security-tracker][master] nvidia-graphics-drivers-tesla,glewlwyd spu

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 114358ee by Moritz Mühlenhoff at 2023-11-27T22:45:57+01:00 nvidia-graphics-drivers-tesla,glewlwyd spu - - - - - 2 changed files: - data/CVE/list - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] libde265 spu/ospu

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 96805904 by Moritz Mühlenhoff at 2023-11-27T22:42:05+01:00 libde265 spu/ospu - - - - - 3 changed files: - data/CVE/list - data/next-oldstable-point-update.txt - data/next-point-update.txt

[Git][security-tracker-team/security-tracker][master] Process two more Mattermost CVEs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 470b6a71 by Salvatore Bonaccorso at 2023-11-27T22:07:26+01:00 Process two more Mattermost CVEs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process more NFUs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d8763a1 by Salvatore Bonaccorso at 2023-11-27T22:06:44+01:00 Process more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process two more Mattermost issues

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fa15386d by Salvatore Bonaccorso at 2023-11-27T22:01:34+01:00 Process two more Mattermost issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-49316

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e0a7dfe by Salvatore Bonaccorso at 2023-11-27T21:59:43+01:00 Add Debian bug reference for CVE-2023-49316 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-49316/php-phpseclib3

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 14073db3 by Salvatore Bonaccorso at 2023-11-27T21:49:42+01:00 Add CVE-2023-49316/php-phpseclib3 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some CVEs in Mattermost (mark as mattermost-server)

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 20820142 by Salvatore Bonaccorso at 2023-11-27T21:39:42+01:00 Process some CVEs in Mattermost (mark as mattermost-server) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-6287/check-mk

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5699fdbb by Salvatore Bonaccorso at 2023-11-27T21:39:05+01:00 Add CVE-2023-6287/check-mk - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some new NFUs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e9b9abcf by Salvatore Bonaccorso at 2023-11-27T21:37:51+01:00 Process some new NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-44034/linux

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e769efd by Salvatore Bonaccorso at 2023-11-27T21:26:09+01:00 Track fixed version for CVE-2022-44034/linux - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4d3813e2 by security tracker role at 2023-11-27T20:23:34+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add reference for CVE-2023-6121/linux

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3710ef67 by Salvatore Bonaccorso at 2023-11-27T21:09:43+01:00 Add reference for CVE-2023-6121/linux - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] samba fixed in sid

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: de9d9107 by Moritz Muehlenhoff at 2023-11-27T20:59:56+01:00 samba fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 68d07de7 by Salvatore Bonaccorso at 2023-11-27T20:42:19+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] fastdds DSA

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 53064de5 by Moritz Mühlenhoff at 2023-11-27T20:13:58+01:00 fastdds DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3669-1 for cryptojs

2023-11-27 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: cecc9598 by Guilhem Moulin at 2023-11-27T19:51:00+01:00 Reserve DLA-3669-1 for cryptojs - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim bouncycastle and squid in dla-needed.txt

2023-11-27 Thread Markus Koschany (@apo)
: = data/dla-needed.txt = @@ -29,7 +29,7 @@ bind9 (Thorsten Alteholz) NOTE: 20231008: backporting patches NOTE: 20231119: almost done with testing -- -bouncycastle +bouncycastle (Markus Koschany) NOTE: 20231127: Added by Front-Desk (Beuc) NOTE

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1ee4af7e by Salvatore Bonaccorso at 2023-11-27T19:13:25+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add additional CVE for glewlwyd bullseye-pu update

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c864d61 by Salvatore Bonaccorso at 2023-11-27T19:02:19+01:00 Add additional CVE for glewlwyd bullseye-pu update - - - - - 1 changed file: - data/next-oldstable-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add additional CVEs for hoteldruid

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 887df33a by Salvatore Bonaccorso at 2023-11-27T18:56:23+01:00 Add additional CVEs for hoteldruid Thanks for upstream to confirm the validity of the CVEs (though not yet published) - - - - -

[Git][security-tracker-team/security-tracker][master] CVE-2023-6277/tiff: buster postponed

2023-11-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9159033d by Sylvain Beucler at 2023-11-27T18:09:42+01:00 CVE-2023-6277/tiff: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-14744/kde4libs: precise stretch context

2023-11-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 7910bbdb by Sylvain Beucler at 2023-11-27T17:54:04+01:00 CVE-2019-14744/kde4libs: precise stretch context - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 35cf6256 by Moritz Muehlenhoff at 2023-11-27T17:11:29+01:00 bullseye/bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: add bouncycastle

2023-11-27 Thread Sylvain Beucler (@beuc)
-needed.txt = @@ -29,6 +29,10 @@ bind9 (Thorsten Alteholz) NOTE: 20231008: backporting patches NOTE: 20231119: almost done with testing -- +bouncycastle + NOTE: 20231127: Added by Front-Desk (Beuc) + NOTE: 20231127: Also fix pending no-dsa CVEs, in particular CVE

[Git][security-tracker-team/security-tracker][master] dla: add gimp-dds

2023-11-27 Thread Sylvain Beucler (@beuc)
= @@ -64,6 +64,9 @@ flatpak frr NOTE: 20231119: Added by Front-Desk (apo) -- +gimp-dds + NOTE: 20231127: Added by Front-Desk (Beuc) +-- gst-plugins-bad1.0 (Thorsten Alteholz) NOTE: 20231118: Added by Front-Desk (apo) -- View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] LTS: reclaim mediawiki in dla-needed.txt

2023-11-27 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: bce34a0d by Guilhem Moulin at 2023-11-27T12:57:33+01:00 LTS: reclaim mediawiki in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: add zfs-linux

2023-11-27 Thread Sylvain Beucler (@beuc)
= @@ -252,3 +252,6 @@ zabbix zbar NOTE: 20231119: Added by Front-Desk (apo) -- +zfs-linux + NOTE: 20231127: Added by Front-Desk (Beuc) +-- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim python-django.

2023-11-27 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 27e8ac71 by Chris Lamb at 2023-11-27T10:47:18+00:00 data/dla-needed.txt: Claim python-django. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-11-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 63c2ddcc by Moritz Muehlenhoff at 2023-11-27T11:26:48+01:00 bullseye/bookworm triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity

2023-11-27 Thread @roberto
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e8a90ad by Roberto C. Sánchez at 2023-11-27T04:23:35-05:00 semi-automatic unclaim after 2 weeks of inactivity Signed-off-by: Roberto C. Sánchez robe...@connexer.com - - - - - 1 changed file:

[Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2023-46118/rabbitmq-server

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 89dee89d by Salvatore Bonaccorso at 2023-11-27T10:17:28+01:00 Add fixed version via unstable for CVE-2023-46118/rabbitmq-server - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e383e38 by Salvatore Bonaccorso at 2023-11-27T09:28:54+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-11-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 37aca15d by security tracker role at 2023-11-27T08:11:38+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list