[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2024-23944/zookeeper

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d5b368e5 by Salvatore Bonaccorso at 2024-03-25T05:50:43+01:00 Track fixed version for CVE-2024-23944/zookeeper - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-52159/gross

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 80585956 by Salvatore Bonaccorso at 2024-03-25T05:48:55+01:00 Track fixed version for CVE-2023-52159/gross - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3772-1 for python3.7

2024-03-24 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 9510f5cf by Adrian Bunk at 2024-03-24T23:48:24+02:00 Reserve DLA-3772-1 for python3.7 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3771-1 for python2.7

2024-03-24 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: f209db39 by Adrian Bunk at 2024-03-24T23:40:04+02:00 Reserve DLA-3771-1 for python2.7 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-22513

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ff6befe3 by Salvatore Bonaccorso at 2024-03-24T22:36:18+01:00 Add Debian bug reference for CVE-2024-22513 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream issue for anope

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 85452258 by Salvatore Bonaccorso at 2024-03-24T22:35:27+01:00 Reference upstream issue for anope - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add issue tracker for putty/dla

2024-03-24 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e969a86 by Bastien Roucariès at 2024-03-24T21:12:52+00:00 Add issue tracker for putty/dla - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add initial tracking for CVE-2024-30161/Qt

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 28bd7013 by Salvatore Bonaccorso at 2024-03-24T22:07:23+01:00 Add initial tracking for CVE-2024-30161/Qt - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference to oss-security post for emacs issues

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ef898d2 by Salvatore Bonaccorso at 2024-03-24T21:58:41+01:00 Add reference to oss-security post for emacs issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 14ab63be by Salvatore Bonaccorso at 2024-03-24T21:53:32+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-30156/varnish

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 33e73703 by Salvatore Bonaccorso at 2024-03-24T21:36:01+01:00 Add CVE-2024-30156/varnish - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] mark three CVEs as ignored for bullseye/buster, only relevant for AD

2024-03-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 810bdcd3 by Moritz Mühlenhoff at 2024-03-24T21:32:12+01:00 mark three CVEs as ignored for bullseye/buster, only relevant for AD - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] samba DSA

2024-03-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 33d1ae08 by Moritz Mühlenhoff at 2024-03-24T21:17:12+01:00 samba DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add tempoary tracking for emacs issues

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: db393889 by Salvatore Bonaccorso at 2024-03-24T21:11:44+01:00 Add tempoary tracking for emacs issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] libmicrohttpd ospu

2024-03-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 381c2067 by Moritz Mühlenhoff at 2024-03-24T21:10:41+01:00 libmicrohttpd ospu - - - - - 1 changed file: - data/next-oldstable-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add myself for putty/dla

2024-03-24 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 80797d36 by Bastien Roucariès at 2024-03-24T19:42:43+00:00 Add myself for putty/dla - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream issue reference for CVE-2024-23944

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c7dd21c by Salvatore Bonaccorso at 2024-03-24T20:39:32+01:00 Add upstream issue reference for CVE-2024-23944 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream tags for commits of CVE-2024-23944

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 198abefb by Salvatore Bonaccorso at 2024-03-24T20:32:02+01:00 Reference upstream tags for commits of CVE-2024-23944 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] data/embedded-code-copies: Update the clamav/rar embedding status

2024-03-24 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 68a173c3 by Adrian Bunk at 2024-03-24T20:31:04+02:00 data/embedded-code-copies: Update the clamav/rar embedding status - - - - - 1 changed file: - data/embedded-code-copies Changes:

[Git][security-tracker-team/security-tracker][master] dla: remove clamav, the non-free unrar code is in src:libclamunrar

2024-03-24 Thread Adrian Bunk (@bunk)
) -- -clamav - NOTE: 20240324: Added by Front-Desk (ta) - NOTE: 20240324: there is no CVE for clamav but CVE-2023-40477 affects the embedded version of unrar --- composer (rouca) NOTE: 20240209: Added by Front-Desk (utkarsh) NOTE: 20240304: Need to backport bullseye (rouca) View it on GitLab

[Git][security-tracker-team/security-tracker][master] 2 commits: add commits to fix CVE-2024-23944

2024-03-24 Thread Thorsten Alteholz (@alteholz)
(utkarsh) NOTE: 20240212: Added by Front-Desk (utkarsh) -- +zookeeper + NOTE: 20240324: Added by Front-Desk (ta) +-- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4734816754d286e8198e442b3e182bdfd2047a14...f8ad0fa1faaeb144ce9d02cf39543698cddf73f3

[Git][security-tracker-team/security-tracker][master] Add note about sendmail status

2024-03-24 Thread @rouca
: 20240311: please coordinate with the package maintainer to help make this happen. (Beuc/front-desk) + NOTE: 20240324: some issue coordinate with myself and security team (rouca) -- shim NOTE: 20240306: Added by Front-Desk (opal) View it on GitLab: https://salsa.debian.org/security-tracker

[Git][security-tracker-team/security-tracker][master] add clamav

2024-03-24 Thread Thorsten Alteholz (@alteholz)
= @@ -40,6 +40,10 @@ bind9 (Sean Whitton) NOTE: 20240218: Added by Front-Desk (lamby) NOTE: 20240218: CVE-2023-4408 CVE-2023-50387 CVE-2023-50868 CVE-2023-5517 CVE-2023-5679 already fixed in bullseye. (lamby) -- +clamav + NOTE: 20240324: Added by Front-Desk

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for cacti update

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b2aaf5ef by Salvatore Bonaccorso at 2024-03-24T13:40:55+01:00 Reserve DSA number for cacti update - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-25100/libmojolicious-perl

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c7c5ffb by Salvatore Bonaccorso at 2024-03-24T12:12:45+01:00 Add CVE-2018-25100/libmojolicious-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 84a52fea by Salvatore Bonaccorso at 2024-03-24T12:11:23+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c348e186 by security tracker role at 2024-03-24T08:11:41+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add new anope issue

2024-03-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 62e2b8c8 by Salvatore Bonaccorso at 2024-03-24T08:48:10+01:00 Add new anope issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list