[Git][security-tracker-team/security-tracker][master] CVE-2023-3966/openvswitch - buster is not affected

2024-02-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: abbf2a15 by Tobias Frost at 2024-02-10T08:49:58+01:00 CVE-2023-3966/openvswitch - buster is not affected Vulnerable code introduced in 2.11.0, buster is at 2.10.7. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] LTS: claim openvswitch in dla-needed.txt

2024-02-09 Thread Tobias Frost (@tobi)
penvswitch +openvswitch (tobi) NOTE: 20240209: Added by Front-Desk (utkarsh) -- putty (santiago) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/367677e55c7fbf8b83c2834885a1b4c22a08eb86 -- View it on GitLab: https://salsa.debian.org/security-tr

[Git][security-tracker-team/security-tracker][master] werkzeug fixed in sid

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ad54942b by Moritz Muehlenhoff at 2024-02-10T00:15:38+01:00 werkzeug fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version for hugin issues fixed via unstable

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dadb1c96 by Salvatore Bonaccorso at 2024-02-09T23:19:53+01:00 Track fixed version for hugin issues fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add four new hugin issues

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 22339dba by Salvatore Bonaccorso at 2024-02-09T23:06:50+01:00 Add four new hugin issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-48104/sogo via unstable

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b4bd1a61 by Salvatore Bonaccorso at 2024-02-09T22:15:24+01:00 Track fixed version for CVE-2023-48104/sogo via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference vendor changes (Rocky Linux, RHEL) for CVE-2023-5388

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a6349adb by Salvatore Bonaccorso at 2024-02-09T22:07:06+01:00 Reference vendor changes (Rocky Linux, RHEL) for CVE-2023-5388 Debian should IMHO rather wait for the upstreamed patch and revisit

[Git][security-tracker-team/security-tracker][master] Add tempoary entry for diffoscope issue

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 312efc24 by Salvatore Bonaccorso at 2024-02-09T22:02:37+01:00 Add tempoary entry for diffoscope issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2024-24762

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c3de1d3b by Salvatore Bonaccorso at 2024-02-09T21:57:34+01:00 Add upstream tag information for CVE-2024-24762 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference the individual commits for CVE-2024-2481{5,6}

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 34d99fc2 by Salvatore Bonaccorso at 2024-02-09T21:52:27+01:00 Reference the individual commits for CVE-2024-2481{5,6} Both CVE entries reference the same merge commit. Split this up in the

[Git][security-tracker-team/security-tracker][master] Add additional reference for CVE-2023-42282/node-ip

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e2ed4bf by Salvatore Bonaccorso at 2024-02-09T21:39:16+01:00 Add additional reference for CVE-2023-42282/node-ip - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process two CVEs for mattermost, mark them for mattermost-server, itp'ed

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a4c7b8c0 by Salvatore Bonaccorso at 2024-02-09T21:32:53+01:00 Process two CVEs for mattermost, mark them for mattermost-server, itped - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0de4b7e4 by Salvatore Bonaccorso at 2024-02-09T21:29:47+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2024-25189 commits

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c4524eb3 by Salvatore Bonaccorso at 2024-02-09T21:18:09+01:00 Add upstream tag information for CVE-2024-25189 commits - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-24821/composer

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 852fafdd by Salvatore Bonaccorso at 2024-02-09T21:15:01+01:00 Add Debian bug reference for CVE-2024-24821/composer - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: de94d575 by security tracker role at 2024-02-09T20:11:58+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for commit in CVE-2024-24821

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2cee3cf2 by Salvatore Bonaccorso at 2024-02-09T21:03:12+01:00 Add upstream tag information for commit in CVE-2024-24821 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2022-0931

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ccbef89d by Salvatore Bonaccorso at 2024-02-09T20:55:44+01:00 Remove notes from CVE-2022-0931 Upstream did not acknowledge this as a security issue and neither considered a vulnerability by

[Git][security-tracker-team/security-tracker][master] Document progress on nss:

2024-02-09 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 19b117a2 by Tobias Frost at 2024-02-09T20:25:59+01:00 Document progress on nss: NOTE: 20240209: Tried to backport patches for CVE-2023-6135, however it is unclear which bits are required

[Git][security-tracker-team/security-tracker][master] libgit2 DSA

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 28bedaea by Moritz Mühlenhoff at 2024-02-09T20:08:35+01:00 libgit2 DSA - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] bugnums

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a75fc461 by Moritz Muehlenhoff at 2024-02-09T16:52:18+01:00 bugnums - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] clamav fixed in sid

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: bacb1d25 by Moritz Muehlenhoff at 2024-02-09T16:48:14+01:00 clamav fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] add NOTEs for commits to fix CVE-2024-25189

2024-02-09 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 8bc01791 by Thorsten Alteholz at 2024-02-09T16:40:38+01:00 add NOTEs for commits to fix CVE-2024-25189 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Re-claim zfs-linux

2024-02-09 Thread Utkarsh Gupta (@utkarsh)
CVE wasn't obvious but about to be ready; D/ELA to be out soon. (utkarsh) + NOTE: 20240209: I was out last to last week so couldn't process this but it's nearly ready. (utkarsh) -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] Add composer and openvswitch to dla-needed

2024-02-09 Thread Utkarsh Gupta (@utkarsh)
: = data/dla-needed.txt = @@ -51,6 +51,9 @@ cinder NOTE: 20230525: Added by Front-Desk (lamby) NOTE: 20230525: NB. CVE-2023-2088 filed against python-glance-store, python-os-brick, nova and cinder. -- +composer + NOTE: 20240209: Added by Front-Desk (utkarsh

[Git][security-tracker-team/security-tracker][master] Mark CVE-2024-2426{5,6,7}/gpac as end-of-life for buster

2024-02-09 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 0dc42cee by Utkarsh Gupta at 2024-02-09T19:58:24+05:30 Mark CVE-2024-2426{5,6,7}/gpac as end-of-life for buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2024-24815/ckeditor3 as end-of-life for buster

2024-02-09 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 26aecaa5 by Utkarsh Gupta at 2024-02-09T19:47:09+05:30 Mark CVE-2024-24815/ckeditor3 as end-of-life for buster - - - - - f079697f by Utkarsh Gupta at 2024-02-09T19:47:33+05:30 Mark

[Git][security-tracker-team/security-tracker][master] new python-multipart issue

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c333b87d by Moritz Muehlenhoff at 2024-02-09T14:44:27+01:00 new python-multipart issue - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] NFUs

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3b3a5ce1 by Moritz Muehlenhoff at 2024-02-09T14:37:02+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new ckeditor issues

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 2d1480d0 by Moritz Muehlenhoff at 2024-02-09T14:29:12+01:00 new ckeditor issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] gitlab n/a

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 15b8ec2b by Moritz Muehlenhoff at 2024-02-09T14:25:55+01:00 gitlab n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new node-ip issue

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 20298530 by Moritz Muehlenhoff at 2024-02-09T13:58:24+01:00 new node-ip issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new libjwt issue

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a2e66104 by Moritz Muehlenhoff at 2024-02-09T13:52:56+01:00 new libjwt issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] bookworm/bullseye triage

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 50881314 by Moritz Muehlenhoff at 2024-02-09T13:51:00+01:00 bookworm/bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] new composer issue

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cf4795ab by Moritz Muehlenhoff at 2024-02-09T11:07:59+01:00 new composer issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3318b31d by Moritz Muehlenhoff at 2024-02-09T11:03:12+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] rust-snow fixed in sid

2024-02-09 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9eb5fd82 by Moritz Muehlenhoff at 2024-02-09T09:35:21+01:00 rust-snow fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-02-09 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 115ec7bf by security tracker role at 2024-02-09T08:11:33+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list