[Git][security-tracker-team/security-tracker][master] Reference upstream commits for exim4 addressing CVE-2023-51766

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e42ad9fa by Salvatore Bonaccorso at 2023-12-25T08:37:09+01:00 Reference upstream commits for exim4 addressing CVE-2023-51766 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-51766/exim4 via unstable

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c008ab0a by Salvatore Bonaccorso at 2023-12-25T08:34:26+01:00 Track fixed version for CVE-2023-51766/exim4 via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim tinyxml and xerces-c in dla-needed.txt

2023-12-24 Thread Guilhem Moulin (@guilhem)
: = data/dla-needed.txt = @@ -257,7 +257,7 @@ tinymce NOTE: 20231216: upstream's patch is backportable, as the code has changed a NOTE: 20231216: lot. (spwhitton) -- -tinyxml +tinyxml (guilhem) NOTE: 20231224: Added by Front-Desk (ta) -- tomcat9

[Git][security-tracker-team/security-tracker][master] add cjson

2023-12-24 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a1db8af by Thorsten Alteholz at 2023-12-25T00:41:12+01:00 add cjson - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: add paramiko

2023-12-24 Thread Thorsten Alteholz (@alteholz)
NOTE: 20231224: Added by Front-Desk (ta) -- @@ -269,6 +272,9 @@ wireshark (Adrian Bunk) NOTE: 20231204: DLA pending (bunk) NOTE: 20231218: Debugging a problem with the update. (bunk) -- +xerces-c + NOTE: 20231225: Added by Front-Desk (ta) +-- zabbix NOTE: 20231015: Added by Front-Desk (ta

[Git][security-tracker-team/security-tracker][master] add upstream reference for hamster-time-tracker

2023-12-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b4f9d10 by Moritz Muehlenhoff at 2023-12-24T23:48:23+01:00 add upstream reference for hamster-time-tracker - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] more gitlab issues fixed in sid

2023-12-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 156430c8 by Moritz Muehlenhoff at 2023-12-24T23:37:26+01:00 more gitlab issues fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2023-37536

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 49b65454 by Salvatore Bonaccorso at 2023-12-24T22:05:05+01:00 Update information for CVE-2023-37536 The initial triaging of this CVE was likely specific for HCL, but the available information

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-41337/h2o

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ca2c066 by Salvatore Bonaccorso at 2023-12-24T21:40:22+01:00 Add Debian bug reference for CVE-2023-41337/h2o - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-51763 as NFU

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d175a9ca by Salvatore Bonaccorso at 2023-12-24T21:37:21+01:00 Mark CVE-2023-51763 as NFU For reviewers: the gems/csv_builder/ embedded in gitlab seems unrelated to this project. - - - - - 1

[Git][security-tracker-team/security-tracker][master] Track proposed update for postfix via bookworm-pu

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 01260601 by Salvatore Bonaccorso at 2023-12-24T21:11:21+01:00 Track proposed update for postfix via bookworm-pu - - - - - 1 changed file: - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] mark postfix as no-dsa for bookworm and bullseye

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b162bae2 by Salvatore Bonaccorso at 2023-12-24T21:09:57+01:00 mark postfix as no-dsa for bookworm and bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] gitlab issues fixed in sid (more to investigate)

2023-12-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d7368f17 by Moritz Muehlenhoff at 2023-12-24T20:48:00+01:00 gitlab issues fixed in sid (more to investigate) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] zfs-linux fixed in sid

2023-12-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 322ffb57 by Moritz Muehlenhoff at 2023-12-24T20:38:16+01:00 zfs-linux fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] add libde265

2023-12-24 Thread Thorsten Alteholz (@alteholz)
= @@ -98,6 +98,9 @@ keystone knot-resolver NOTE: 20231029: Added by Front-Desk (gladk) -- +libde265 (Thorsten Alteholz) + NOTE: 20231224: Added by Front-Desk (ta) +-- libreoffice NOTE: 20231217: Added by Front-Desk (utkarsh) -- View it on GitLab

[Git][security-tracker-team/security-tracker][master] add tinyxml

2023-12-24 Thread Thorsten Alteholz (@alteholz)
= @@ -248,6 +248,9 @@ tinymce NOTE: 20231216: upstream's patch is backportable, as the code has changed a NOTE: 20231216: lot. (spwhitton) -- +tinyxml + NOTE: 20231224: Added by Front-Desk (ta) +-- tomcat9 (rouca) NOTE: 20231129: Added by Front-Desk

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-41337/h2o

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4575a64c by Salvatore Bonaccorso at 2023-12-24T14:48:51+01:00 Add CVE-2023-41337/h2o - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-50247/h2o

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a226832 by Salvatore Bonaccorso at 2023-12-24T14:46:01+01:00 Add CVE-2023-50247/h2o - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: add putty

2023-12-24 Thread Thorsten Alteholz (@alteholz)
-needed.txt Changes: = data/dla-needed.txt = @@ -158,6 +158,12 @@ nvidia-cuda-toolkit openssh (santiago) NOTE: 20231219: Added by Front-Desk (ta) -- +postfix + NOTE: 20231224: Added by Front-Desk (ta) +-- +putty + NOTE

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-51767

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 38f3a802 by Salvatore Bonaccorso at 2023-12-24T14:23:37+01:00 Add Debian bug reference for CVE-2023-51767 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim haproxy in dla-needed.txt

2023-12-24 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: edcd64ff by Tobias Frost at 2023-12-24T12:05:17+01:00 LTS: claim haproxy in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Update fixed commits/versions for CVE-2023-7008

2023-12-24 Thread Luca Boccassi (@bluca)
Luca Boccassi pushed to branch master at Debian Security Tracker / security-tracker Commits: 05275644 by Luca Boccassi at 2023-12-24T11:58:10+01:00 Update fixed commits/versions for CVE-2023-7008 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-20180: mark as not affected for buster and earlier

2023-12-24 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a6a8f28 by Bastien Roucariès at 2023-12-24T10:54:13+00:00 CVE-2021-20180: mark as not affected for buster and earlier - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Fix affected versions for CVE-2023-7008

2023-12-24 Thread Luca Boccassi (@bluca)
Luca Boccassi pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ce9a6c8 by Luca Boccassi at 2023-12-24T11:48:51+01:00 Fix affected versions for CVE-2023-7008 - - - - - 0eaa3d90 by Luca Boccassi at 2023-12-24T11:48:52+01:00 CVE-2023-7008 is now fixed in unstable

[Git][security-tracker-team/security-tracker][master] Add libssh to dsa-needed list (with a note on deferring the updates)

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a798fa70 by Salvatore Bonaccorso at 2023-12-24T11:33:30+01:00 Add libssh to dsa-needed list (with a note on deferring the updates) - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for putty update

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a1aa964c by Salvatore Bonaccorso at 2023-12-24T11:24:02+01:00 Reserve DSA number for putty update - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Drop not-affected tagging for CVE-2023-39360/cacti in bullseye

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c3cae937 by Salvatore Bonaccorso at 2023-12-24T10:52:31+01:00 Drop not-affected tagging for CVE-2023-39360/cacti in bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-51448/cacti

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4926f610 by Salvatore Bonaccorso at 2023-12-24T10:51:02+01:00 Update status for CVE-2023-51448/cacti - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-50250/cacti

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6a872a67 by Salvatore Bonaccorso at 2023-12-24T10:46:27+01:00 Update status for CVE-2023-50250/cacti - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Clarify situation around CVE-2023-49088 (incomplete fix for CVE-2023-39515)

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1a7fe188 by Salvatore Bonaccorso at 2023-12-24T10:29:55+01:00 Clarify situation around CVE-2023-49088 (incomplete fix for CVE-2023-39515) - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] LTS: claim libssh in dla-needed.txt

2023-12-24 Thread Sean Whitton (@spwhitton)
Sean Whitton pushed to branch master at Debian Security Tracker / security-tracker Commits: 39e3c58c by Sean Whitton at 2023-12-24T09:04:40+00:00 LTS: claim libssh in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add references for CVE-2023-51765 and add Debian bug reference

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6927b2ab by Salvatore Bonaccorso at 2023-12-24T09:59:04+01:00 Add references for CVE-2023-51765 and add Debian bug reference - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug referende for CVE-2023-51766/exim4

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 99cef40f by Salvatore Bonaccorso at 2023-12-24T09:57:12+01:00 Add Debian bug referende for CVE-2023-51766/exim4 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fix via experimental for CVE-2023-7008/systemd

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d62bad12 by Salvatore Bonaccorso at 2023-12-24T09:43:17+01:00 Track fix via experimental for CVE-2023-7008/systemd - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-51767/openssh

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c7890b1e by Salvatore Bonaccorso at 2023-12-24T09:32:37+01:00 Add CVE-2023-51767/openssh - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Split up temporary SMTP smuggling attacker entry as per assigned CVEs

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ad7c1211 by Salvatore Bonaccorso at 2023-12-24T09:28:28+01:00 Split up temporary SMTP smuggling attacker entry as per assigned CVEs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-12-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 36b0c9b6 by security tracker role at 2023-12-24T08:12:02+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list