[Git][security-tracker-team/security-tracker][master] Reserve DLA-3692-1 for curl

2023-12-18 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 72c00733 by Adrian Bunk at 2023-12-19T09:16:03+02:00 Reserve DLA-3692-1 for curl - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add erlang for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 80c613e8 by Salvatore Bonaccorso at 2023-12-19T08:07:08+01:00 Add erlang for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-6927 as NFU

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 43414a86 by Salvatore Bonaccorso at 2023-12-19T07:53:58+01:00 Add CVE-2023-6927 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-6610/linux as unimportant

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c4fbe4f5 by Salvatore Bonaccorso at 2023-12-19T07:28:53+01:00 Mark CVE-2023-6610/linux as unimportant - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Sync status for CVE-2023-5178 with kernel-sec

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 540601a5 by Salvatore Bonaccorso at 2023-12-19T07:27:39+01:00 Sync status for CVE-2023-5178 with kernel-sec - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Sync status for CVE-2023-46813 with kernel-sec

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 830bd132 by Salvatore Bonaccorso at 2023-12-19T07:26:53+01:00 Sync status for CVE-2023-46813 with kernel-sec - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Sync status for CVE-2023-4273 with kernel-sec

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ce7f2ccc by Salvatore Bonaccorso at 2023-12-19T07:26:04+01:00 Sync status for CVE-2023-4273 with kernel-sec - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Sync status for CVE-2023-1192 with kernel-sec

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e1bf5a3 by Salvatore Bonaccorso at 2023-12-19T07:23:44+01:00 Sync status for CVE-2023-1192 with kernel-sec - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track upstream status for libssh2 for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ec316325 by Salvatore Bonaccorso at 2023-12-19T06:27:25+01:00 Track upstream status for libssh2 for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixes for libxml2 via experimental

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 13fbaaf0 by Salvatore Bonaccorso at 2023-12-19T06:24:50+01:00 Track fixes for libxml2 via experimental - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for php-dompdf-svg-lib issues

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e9659a03 by Salvatore Bonaccorso at 2023-12-19T06:21:24+01:00 Track fixed version for php-dompdf-svg-lib issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed issues in openssh via unstable

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 42f14593 by Salvatore Bonaccorso at 2023-12-19T06:18:34+01:00 Track fixed issues in openssh via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] reclaim varnish in dla-needed.txt

2023-12-18 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 6ce4e477 by Abhijith PA at 2023-12-19T10:15:18+05:30 reclaim varnish in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim dropbear and libssh2 in dla-needed.txt

2023-12-18 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 405c351b by Guilhem Moulin at 2023-12-19T01:19:27+01:00 LTS: claim dropbear and libssh2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 5 commits: add openssh

2023-12-18 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: cb7a1cf7 by Thorsten Alteholz at 2023-12-19T00:20:24+01:00 add openssh - - - - - ef35183e by Thorsten Alteholz at 2023-12-19T00:24:29+01:00 add dropbear - - - - - bf93abcd by Thorsten Alteholz

[Git][security-tracker-team/security-tracker][master] dla: cacti status

2023-12-18 Thread Sylvain Beucler (@beuc)
= @@ -46,6 +46,7 @@ bouncycastle (Markus Koschany) cacti (Sylvain Beucler) NOTE: 20230906: Added by Front-Desk (lamby) NOTE: 20231205: Triaging CVEs backlog (Beuc) + NOTE: 20231218: Keep triaging CVEs backlog (Beuc) -- cairosvg NOTE: 20230323: Added

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-6817/linux

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b39125b6 by Salvatore Bonaccorso at 2023-12-18T21:52:18+01:00 Add CVE-2023-6817/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update status for ldap-account-manager and adjust bug reference

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 47cb9546 by Salvatore Bonaccorso at 2023-12-18T21:46:50+01:00 Update status for ldap-account-manager and adjust bug reference - - - - - 1 changed file: - data/embedded-code-copies

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 671371f8 by Salvatore Bonaccorso at 2023-12-18T21:43:23+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add two openssh issues

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c058a71e by Salvatore Bonaccorso at 2023-12-18T21:42:39+01:00 Add two openssh issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 109f92b7 by Salvatore Bonaccorso at 2023-12-18T21:25:20+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] libssh: Reference fixes from stable branch

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3b7174d6 by Salvatore Bonaccorso at 2023-12-18T21:16:51+01:00 libssh: Reference fixes from stable branch This is fixed both in 0.10.6 *and* 0.9.8 upstream. For now only referncing the commits

[Git][security-tracker-team/security-tracker][master] automatic update

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69cc5e69 by security tracker role at 2023-12-18T20:12:05+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add missing closing bracket in note

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ab9d10c0 by Salvatore Bonaccorso at 2023-12-18T21:04:43+01:00 Add missing closing bracket in note - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add reference for CVE-2023-48795 for dropbear

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 74d228df by Salvatore Bonaccorso at 2023-12-18T20:57:51+01:00 Add reference for CVE-2023-48795 for dropbear - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add references for CVE-2023-48795 for golang.org/x/crypto/ssh

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a02a19cf by Salvatore Bonaccorso at 2023-12-18T20:55:10+01:00 Add references for CVE-2023-48795 for golang.org/x/crypto/ssh - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-6918 and CVE-2023-6004

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dc38b515 by Salvatore Bonaccorso at 2023-12-18T20:53:09+01:00 Add CVE-2023-6918 and CVE-2023-6004 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add libssh references for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c571264 by Salvatore Bonaccorso at 2023-12-18T20:52:26+01:00 Add libssh references for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference for paramiko for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d9964c94 by Salvatore Bonaccorso at 2023-12-18T20:43:42+01:00 Add reference for paramiko for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add references for asyncssh for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9fd22f75 by Salvatore Bonaccorso at 2023-12-18T20:38:59+01:00 Add references for asyncssh for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] webkit2gtk DSA-5580-1

2023-12-18 Thread Alberto Garcia (@berto)
Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker Commits: ccba81f0 by Alberto Garcia at 2023-12-18T20:13:43+01:00 webkit2gtk DSA-5580-1 - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream commits for putty for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e1af06c by Salvatore Bonaccorso at 2023-12-18T19:35:22+01:00 Add upstream commits for putty for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add openssh to dsa-needed list

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d415ead6 by Salvatore Bonaccorso at 2023-12-18T19:24:25+01:00 Add openssh to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for putty via unstable

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7b8b547b by Salvatore Bonaccorso at 2023-12-18T19:23:08+01:00 Track fixed version for putty via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add further set of packages needing fixes for CVE-2023-48795

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 21aa766b by Salvatore Bonaccorso at 2023-12-18T18:12:38+01:00 Add further set of packages needing fixes for CVE-2023-48795 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference commit from OpenSSH implementing strict key exchange

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6bca640a by Salvatore Bonaccorso at 2023-12-18T18:05:03+01:00 Reference commit from OpenSSH implementing strict key exchange - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove additional space in note

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e6b8eb04 by Salvatore Bonaccorso at 2023-12-18T17:58:27+01:00 Remove additional space in note - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add oss-security reference for terrapin-attack post

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 44cb0645 by Salvatore Bonaccorso at 2023-12-18T17:54:13+01:00 Add oss-security reference for terrapin-attack post - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add initial tracking for CVE-2023-4879{5,6,7}

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5cc91c53 by Salvatore Bonaccorso at 2023-12-18T17:24:52+01:00 Add initial tracking for CVE-2023-4879{5,6,7} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] freeimage DSA

2023-12-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a3ef504 by Moritz Mühlenhoff at 2023-12-18T16:50:17+01:00 freeimage DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Update notes of squid and bouncycastle in dla-needed.txt and reclaim the

2023-12-18 Thread Markus Koschany (@apo)
: Added by Front-Desk (Beuc) NOTE: 20231127: Also fix pending no-dsa CVEs, in particular CVE-2020-26939 was fixed in stretch-lts (Beuc/front-desk) NOTE: 20231128: I can't find changes in PEMParser.java related to CVE-2023-33202, maybe contact upstream (Beuc/front-desk) + NOTE: 20231218

[Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity

2023-12-18 Thread @roberto
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: f66e7e98 by Roberto C. Sánchez at 2023-12-18T08:33:35-05:00 semi-automatic unclaim after 2 weeks of inactivity Signed-off-by: Roberto C. Sánchez robe...@connexer.com - - - - - 1 changed file:

[Git][security-tracker-team/security-tracker][master] NFU

2023-12-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 983b359e by Moritz Muehlenhoff at 2023-12-18T14:17:45+01:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: add note

2023-12-18 Thread Adrian Bunk (@bunk)
= @@ -236,6 +236,7 @@ varnish (Abhijith PA) wireshark (Adrian Bunk) NOTE: 20231118: Added by Front-Desk (apo) NOTE: 20231204: DLA pending (bunk) + NOTE: 20231218: Debugging a problem with the update. (bunk) -- zabbix NOTE: 20231015: Added by Front-Desk (ta

[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2023-0012

2023-12-18 Thread Alberto Garcia (@berto)
Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker Commits: 4cf9ac89 by Alberto Garcia at 2023-12-18T12:38:42+01:00 webkit2gtk / wpewebkit upstream advisory WSA-2023-0012 - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt

[Git][security-tracker-team/security-tracker][master] add reference for asterisk

2023-12-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: edc4b4ae by Moritz Muehlenhoff at 2023-12-18T09:35:25+01:00 add reference for asterisk - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 213405f8 by Salvatore Bonaccorso at 2023-12-18T09:28:32+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add three new libcrypto++ CVE entries

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6eb4bedb by Salvatore Bonaccorso at 2023-12-18T09:28:05+01:00 Add three new libcrypto++ CVE entries - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-12-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dae8f8c2 by security tracker role at 2023-12-18T08:12:01+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list