[Git][security-tracker-team/security-tracker][master] Reserve DLA-2680-1 for nginx

2021-06-07 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 32fb61b5 by Markus Koschany at 2021-06-07T20:53:34+02:00 Reserve DLA-2680-1 for nginx - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] 3 commits: Claim ruby-actionpack-page-caching and ruby-kaminari

2021-06-06 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 16d3eca9 by Markus Koschany at 2021-06-01T00:56:43+02:00 Claim ruby-actionpack-page-caching and ruby-kaminari - - - - - d38970ed by Markus Koschany at 2021-06-06T17:56:31+02:00 Merge branch master

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2021-28169,CVE-2021-34428,jetty9: Fixed in unstable

2021-07-03 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bd70f65b by Markus Koschany at 2021-07-03T19:19:55+02:00 CVE-2021-28169,CVE-2021-34428,jetty9: Fixed in unstable - - - - - 6bbfa6bd by Markus Koschany at 2021-07-03T19:20:42+02:00 Remove jetty9

[Git][security-tracker-team/security-tracker][master] Reclaim the ruby packages and jetty9 in dla-needed.txt.

2021-07-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c03bd728 by Markus Koschany at 2021-07-01T10:37:58+02:00 Reclaim the ruby packages and jetty9 in dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: Document I am looking into ceph and condor.

2021-07-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 64c6375a by Markus Koschany at 2021-07-09T12:42:01+02:00 dla-needed.txt: Document I am looking into ceph and condor. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Order the entries correctly

2021-07-05 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e270b33a by Markus Koschany at 2021-07-05T14:56:59+02:00 Order the entries correctly - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-28163 and CVE-2021-28164,jetty9 as not affected for Buster.

2021-07-05 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f199805 by Markus Koschany at 2021-07-05T14:48:37+02:00 Mark CVE-2021-28163 and CVE-2021-28164,jetty9 as not affected for Buster. The vulnerable code was introduced later. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2693-1 for xmlbeans

2021-06-27 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e51a46c9 by Markus Koschany at 2021-06-28T00:05:10+02:00 Reserve DLA-2693-1 for xmlbeans - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-36773,ublock-origin: Fixed in unstable

2021-08-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 00ad5198 by Markus Koschany at 2021-08-18T22:20:06+02:00 CVE-2021-36773,ublock-origin: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Claim qemu in dla-needed.txt

2021-08-27 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b2f730f by Markus Koschany at 2021-08-25T22:21:27+02:00 Claim qemu in dla-needed.txt - - - - - 62d86128 by Markus Koschany at 2021-08-27T16:43:44+02:00 Merge branch master of

[Git][security-tracker-team/security-tracker][master] Claim nettle in dla-needed.txt

2021-08-31 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c9245904 by Markus Koschany at 2021-08-31T22:47:09+02:00 Claim nettle in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-3544,CVE-2021-3545,CVE-2021-3546 in Qemu/Stretch as not-affected

2021-08-31 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: db95e31b by Markus Koschany at 2021-09-01T00:09:22+02:00 Mark CVE-2021-3544,CVE-2021-3545,CVE-2021-3546 in Qemu/Stretch as not-affected The vulnerable code was introduced later in 2019. - - - - -

[Git][security-tracker-team/security-tracker][master] CVE-2021-31811,CVE-2021-31812,libpdfbox2-java: Fixed in unstable

2021-08-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 977b4a6a by Markus Koschany at 2021-08-30T00:32:59+02:00 CVE-2021-31811,CVE-2021-31812,libpdfbox2-java: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2021-3748 and CVE-2021-3735 as postponed in Stretch

2021-09-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: cd87b6ae by Markus Koschany at 2021-09-01T23:54:56+02:00 Mark CVE-2021-3748 and CVE-2021-3735 as postponed in Stretch - - - - - c45b2cca by Markus Koschany at 2021-09-01T23:56:09+02:00 Reserve

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-3750,qemu in Stretch as postponed.

2021-09-02 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 54b124c2 by Markus Koschany at 2021-09-02T20:42:19+02:00 Mark CVE-2021-3750,qemu in Stretch as postponed. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-37714,jsoup as fixed in unstable.

2021-09-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 94d1b021 by Markus Koschany at 2021-09-09T13:34:17+02:00 Mark CVE-2021-37714,jsoup as fixed in unstable. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update status for nettle in dla-needed.txt

2021-09-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a837cef1 by Markus Koschany at 2021-09-13T01:52:11+02:00 Update status for nettle in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim jsoup in dla-needed.txt

2021-09-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dca98c21 by Markus Koschany at 2021-09-18T15:51:51+02:00 Claim jsoup in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-20305,nettle: Remove postponed tag

2021-09-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b9fe0d98 by Markus Koschany at 2021-09-18T15:50:06+02:00 CVE-2021-20305,nettle: Remove postponed tag - - - - - b218d63f by Markus Koschany at 2021-09-18T15:50:57+02:00 Reserve DLA-2760-1 for nettle

[Git][security-tracker-team/security-tracker][master] 2 commits: Ignore CVE-2021-3592,qemu for now because of a regression.

2021-09-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 95baca24 by Markus Koschany at 2021-09-11T22:51:09+02:00 Ignore CVE-2021-3592,qemu for now because of a regression. - - - - - 5f977316 by Markus Koschany at 2021-09-11T22:58:40+02:00 Reserve

[Git][security-tracker-team/security-tracker][master] Update notes for CVE-2021-3592

2021-09-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: eea83f8e by Markus Koschany at 2021-09-11T23:07:30+02:00 Update notes for CVE-2021-3592 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2735-1 for ceph

2021-08-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a52bf959 by Markus Koschany at 2021-08-09T11:11:33+02:00 Reserve DLA-2735-1 for ceph - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-30639,tomcat9: Buster and Bullseye are not affected

2021-08-05 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e340e4c by Markus Koschany at 2021-08-05T23:24:55+02:00 CVE-2021-30639,tomcat9: Buster and Bullseye are not affected The vulnerable code was introduced in version 9.0.44 - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2733-1 for tomcat8

2021-08-05 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c695147 by Markus Koschany at 2021-08-05T20:21:11+02:00 Reserve DLA-2733-1 for tomcat8 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-30639,tomcat8: Stretch is not affected

2021-08-05 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fba1 by Markus Koschany at 2021-08-05T20:22:42+02:00 CVE-2021-30639,tomcat8: Stretch is not affected The vulnerable code was introduced in version 8.5.64 - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] CVE-2021-33037,CVE-2021-30640,tomcat9: Fixed in unstable

2021-08-07 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e8cf6597 by Markus Koschany at 2021-08-07T17:05:09+02:00 CVE-2021-33037,CVE-2021-30640,tomcat9: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-25678, CVE-2021-20288, ceph as no-dsa for Stretch

2021-08-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: da6b1dfb by Markus Koschany at 2021-08-11T15:24:11+02:00 Mark CVE-2020-25678, CVE-2021-20288, ceph as no-dsa for Stretch and postpone CVE-2020-27781 CVE-2021-20288 The fix is to implement a new

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2739-1 for libspf2

2021-08-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fc57a94f by Markus Koschany at 2021-08-11T17:20:27+02:00 Reserve DLA-2739-1 for libspf2 - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2741-1 for commons-io

2021-08-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dc2eee5f by Markus Koschany at 2021-08-12T21:38:19+02:00 Reserve DLA-2741-1 for commons-io - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-29425,commons-io: Remove no-dsa tag for upcoming security update

2021-08-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: edb444f4 by Markus Koschany at 2021-08-12T21:43:43+02:00 CVE-2021-29425,commons-io: Remove no-dsa tag for upcoming security update - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tags for upcoming lrzip security update

2021-08-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c9be145 by Markus Koschany at 2021-08-01T23:01:24+02:00 Remove no-dsa tags for upcoming lrzip security update - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2725-1 for lrzip

2021-08-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f889a58 by Markus Koschany at 2021-08-01T22:58:49+02:00 Reserve DLA-2725-1 for lrzip - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Claim tomcat8 and apache-directory-server in dla-needed.txt

2021-08-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c1d77938 by Markus Koschany at 2021-08-01T16:57:28+02:00 Claim tomcat8 and apache-directory-server in dla-needed.txt Avoid possible double work with Java packages which have to be fixed in

[Git][security-tracker-team/security-tracker][master] 2 commits: Remove apache-directory-server from dla-needed.txt

2021-08-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 220251a5 by Markus Koschany at 2021-08-01T17:49:34+02:00 Remove apache-directory-server from dla-needed.txt Apparently the vulnerability is in apache-directory-studio which has not been packaged

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2724-1 for condor

2021-08-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ba587f8a by Markus Koschany at 2021-08-01T16:49:49+02:00 Reserve DLA-2724-1 for condor - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-11988,xmlgraphics-commons: Fixed in unstable

2021-08-02 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: df148746 by Markus Koschany at 2021-08-02T08:17:07+02:00 CVE-2020-11988,xmlgraphics-commons: Fixed in unstable Mark Stretch as not-affected because the vulnerable XMPParser code is not present. -

[Git][security-tracker-team/security-tracker][master] CVE-2021-41079,tomcat9: Fixed in unstable

2021-09-24 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b8ec4627 by Markus Koschany at 2021-09-24T19:07:18+02:00 CVE-2021-41079,tomcat9: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Claim fig2dev in dla-needed.txt

2021-09-23 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0cff7c47 by Markus Koschany at 2021-09-23T19:40:36+02:00 Claim fig2dev in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Fix typo in data/CVE/list

2021-10-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e9291301 by Markus Koschany at 2021-10-09T18:07:06+02:00 Fix typo in data/CVE/list - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2021-41800,CVE-2021-41801,mediawiki as not-affected for Stretch

2021-10-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a57854a by Markus Koschany at 2021-10-09T17:33:14+02:00 Mark CVE-2021-41800,CVE-2021-41801,mediawiki as not-affected for Stretch The vulnerable code was introduced later - - - - - 232ea563 by

[Git][security-tracker-team/security-tracker][master] Claim smarty3 in dla-needed.txt

2021-10-09 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 742e9381 by Markus Koschany at 2021-10-09T17:39:48+02:00 Claim smarty3 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2618-3 for smarty3

2021-10-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e24955b9 by Markus Koschany at 2021-10-20T11:28:34+02:00 Reserve DLA-2618-3 for smarty3 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2021-37714,jsoup as no-dsa in Stretch

2021-10-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bfa8c0d4 by Markus Koschany at 2021-10-20T14:51:20+02:00 Mark CVE-2021-37714,jsoup as no-dsa in Stretch As privately discussed with the security team I am going to mark CVE-2021-37714 as no-dsa

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2767-1 for libxml-security-java

2021-09-27 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d875339 by Markus Koschany at 2021-09-27T13:50:07+02:00 Reserve DLA-2767-1 for libxml-security-java - - - - - 1 changed file: - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2769-1 for libxstream-java

2021-09-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 695f8cd3 by Markus Koschany at 2021-09-29T21:36:18+02:00 Reserve DLA-2769-1 for libxstream-java - - - - - 1 changed file: - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Remove libxstream-java from dla-needed.txt

2021-09-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 993de458 by Markus Koschany at 2021-09-29T21:36:32+02:00 Remove libxstream-java from dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark open CVE for libcommons-compress-java as fixed in unstable

2021-09-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: be7728c1 by Markus Koschany at 2021-09-20T21:42:04+02:00 Mark open CVE for libcommons-compress-java as fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Claim tomcat8 in dla-needed.txt

2021-09-22 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 554dc7d7 by Markus Koschany at 2021-09-22T17:49:22+02:00 Claim tomcat8 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2763-1 for ruby-kaminari

2021-09-22 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b6ccfd4 by Markus Koschany at 2021-09-22T15:41:36+02:00 Reserve DLA-2763-1 for ruby-kaminari - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2764-1 for tomcat8

2021-09-22 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a7a9369e by Markus Koschany at 2021-09-22T21:49:48+02:00 Reserve DLA-2764-1 for tomcat8 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090, libcommons-compress-java

2021-10-02 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a7b197cf by Markus Koschany at 2021-10-02T20:24:14+02:00 CVE-2021-35515,CVE-2021-35516,CVE-2021-35517,CVE-2021-36090,libcommons-compress-java Add fixing commits. I have tried to contact the Apache

[Git][security-tracker-team/security-tracker][master] 2 commits: Remove no-dsa tags for upcoming fig2dev update

2021-10-04 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 235551db by Markus Koschany at 2021-10-04T09:54:31+02:00 Remove no-dsa tags for upcoming fig2dev update - - - - - 265fe795 by Markus Koschany at 2021-10-04T09:56:55+02:00 Reserve DLA-2778-1 for

[Git][security-tracker-team/security-tracker][master] Claim mediawiki in dla-needed.txt

2021-10-04 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0fff3598 by Markus Koschany at 2021-10-04T10:02:35+02:00 Claim mediawiki in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-40690,CVE-2019-12400,libxml-security-java: Fixed in unstable

2021-09-23 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5f8c7a11 by Markus Koschany at 2021-09-23T23:58:36+02:00 CVE-2021-40690,CVE-2019-12400,libxml-security-java: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-18670,CVE-2020-18671 in roundcube as ignore instead of postponed

2021-12-06 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b8e325e5 by Markus Koschany at 2021-12-06T17:34:28+01:00 Mark CVE-2020-18670,CVE-2020-18671 in roundcube as ignore instead of postponed Those issues are borderline unimportant and can be safely

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2840-1 for roundcube

2021-12-06 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2bef4ee8 by Markus Koschany at 2021-12-06T17:33:43+01:00 Reserve DLA-2840-1 for roundcube - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim firmware-nonfree in dla-needed.txt again.

2021-12-06 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 82ff9064 by Markus Koschany at 2021-12-07T01:34:26+01:00 Claim firmware-nonfree in dla-needed.txt again. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2020-9488,apache-log4j2: Remove no-dsa tag

2021-12-26 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 240c08e9 by Markus Koschany at 2021-12-26T21:25:55+01:00 CVE-2020-9488,apache-log4j2: Remove no-dsa tag - - - - - b7ec1f90 by Markus Koschany at 2021-12-26T21:27:09+01:00 Reserve DLA-2852-1 for

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2870-1 for apache-log4j2

2021-12-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8b87e211 by Markus Koschany at 2021-12-29T23:20:52+01:00 Reserve DLA-2870-1 for apache-log4j2 - - - - - 1 changed file: - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reclaim firmware-nonfree and nvidia-graphics-drivers in dla-needed.txt

2021-12-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 68ef9638 by Markus Koschany at 2021-12-29T23:29:32+01:00 Reclaim firmware-nonfree and nvidia-graphics-drivers in dla-needed.txt Update notes for nvidia-graphics-drivers. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] CVE-2021-44832,apache-log4j2: Fixed in unstable

2021-12-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d1100b3 by Markus Koschany at 2021-12-29T12:20:54+01:00 CVE-2021-44832,apache-log4j2: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Claim ghostscript in dla-needed.txt

2022-01-03 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 82e63bef by Markus Koschany at 2022-01-03T22:51:23+01:00 Claim ghostscript in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-45105,apache-log4j2 as fixed in unstable.

2021-12-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fdd090b3 by Markus Koschany at 2021-12-18T18:55:00+01:00 Mark CVE-2021-45105,apache-log4j2 as fixed in unstable. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5024-1 for apache-log4j2

2021-12-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 489712d9 by Markus Koschany at 2021-12-18T21:32:25+01:00 Reserve DSA-5024-1 for apache-log4j2 - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim apache-log4j2 in dla-needed.txt

2021-12-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f332a5d by Markus Koschany at 2021-12-18T22:10:57+01:00 Claim apache-log4j2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] node-http-proxy is now in Debian.

2021-11-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: eb522819 by Markus Koschany at 2021-11-21T00:35:32+01:00 node-http-proxy is now in Debian. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2823-2 for salt

2021-11-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 82160e66 by Markus Koschany at 2021-11-21T00:17:03+01:00 Reserve DLA-2823-2 for salt - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Claim roundcube in dla-needed.txt

2021-11-20 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a1a80c83 by Markus Koschany at 2021-11-20T20:25:14+01:00 Claim roundcube in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark Buster issues in Salt as fixed in version 2018.3.4+dfsg1-6+deb10u3

2021-11-19 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 27a14d6b by Markus Koschany at 2021-11-19T12:09:17+01:00 Mark Buster issues in Salt as fixed in version 2018.3.4+dfsg1-6+deb10u3 - - - - - 55045117 by Markus Koschany at 2021-11-19T12:10:36+01:00

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2823-1 for salt

2021-11-19 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f0b58ba by Markus Koschany at 2021-11-19T23:46:11+01:00 Reserve DLA-2823-1 for salt - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2815-1 for salt

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3db8d207 by Markus Koschany at 2021-11-10T17:55:04+01:00 Reserve DLA-2815-1 for salt - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5004-1 for libxstream-java

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d974cd4 by Markus Koschany at 2021-11-10T20:44:00+01:00 Reserve DSA-5004-1 for libxstream-java - - - - - 1 changed file: - data/DSA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark Buster CVE of libxstream-java as fixed in version 1.4.11.1-1+deb10u3

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1aa24f85 by Markus Koschany at 2021-11-10T20:47:31+01:00 Mark Buster CVE of libxstream-java as fixed in version 1.4.11.1-1+deb10u3 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5005-1 for ruby-kaminari

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 233c5f66 by Markus Koschany at 2021-11-10T22:36:17+01:00 Reserve DSA-5005-1 for ruby-kaminari - - - - - 1 changed file: - data/DSA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Claim libxml-security-java, salt and tomcat9 in dsa-needed.txt

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e2980a25 by Markus Koschany at 2021-11-10T23:52:48+01:00 Claim libxml-security-java, salt and tomcat9 in dsa-needed.txt - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-22004,salt as unimportant because only Windows systems are

2021-11-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fb450bf6 by Markus Koschany at 2021-11-10T22:56:33+01:00 Mark CVE-2021-22004,salt as unimportant because only Windows systems are affected. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2021-42340,tomcat9 in buster as not-affected

2021-11-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3d3c740e by Markus Koschany at 2021-11-12T11:07:24+01:00 Mark CVE-2021-42340,tomcat9 in buster as not-affected The vulnerable code was introduced later in version 9.0.40 - - - - - 4d938f0c by

[Git][security-tracker-team/security-tracker][master] Claim ntfs-3g in dla-needed.txt

2021-11-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 125488d7 by Markus Koschany at 2021-11-12T11:22:08+01:00 Claim ntfs-3g in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5010-1 for libxml-security-java

2021-11-15 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2282a1dc by Markus Koschany at 2021-11-15T11:08:05+01:00 Reserve DSA-5010-1 for libxml-security-java - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Claim firmware-nonfree in dla-needed.txt

2021-11-16 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 851a329f by Markus Koschany at 2021-11-16T23:20:07+01:00 Claim firmware-nonfree in dla-needed.txt - - - - - 83a5b72a by Markus Koschany at 2021-11-16T23:23:10+01:00 Reserve DLA-2819-1 for ntfs-3g

[Git][security-tracker-team/security-tracker][master] CVE-2021-41653, Readd the whitespace character

2021-11-16 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 31f16620 by Markus Koschany at 2021-11-17T00:12:18+01:00 CVE-2021-41653, Readd the whitespace character This is the only unrelated change which might cause the processing errors. The whitespace was

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-21996,salt: Link to fixing commit

2021-11-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ca949bfc by Markus Koschany at 2021-11-11T13:38:10+01:00 CVE-2021-21996,salt: Link to fixing commit - - - - - 73d7bd8f by Markus Koschany at 2021-11-11T13:38:50+01:00 Claim salt in dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2806-1 for glusterfs

2021-11-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 627ef39a by Markus Koschany at 2021-11-01T22:55:02+01:00 Reserve DLA-2806-1 for glusterfs - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2807-1 for bind9

2021-11-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c9a407c by Markus Koschany at 2021-11-01T22:57:22+01:00 Reserve DLA-2807-1 for bind9 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tag for CVE-2018-5740,bind9 in Stretch.

2021-11-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f1948010 by Markus Koschany at 2021-11-02T00:09:45+01:00 Remove no-dsa tag for CVE-2018-5740,bind9 in Stretch. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Claim opencv in dla-needed.txt

2021-10-26 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 271be626 by Markus Koschany at 2021-10-26T16:52:52+02:00 Claim opencv in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2799-1 for opencv

2021-10-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ec140577 by Markus Koschany at 2021-10-29T23:10:09+02:00 Reserve DLA-2799-1 for opencv - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim glusterfs in dla-needed.txt

2021-10-29 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f33ba4ae by Markus Koschany at 2021-10-29T23:13:10+02:00 Claim glusterfs in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-42340,tomcat9 as fixed in unstable

2021-10-22 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d5223fd by Markus Koschany at 2021-10-22T22:07:58+02:00 Mark CVE-2021-42340,tomcat9 as fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2811-1 for sqlalchemy

2021-11-06 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f975e141 by Markus Koschany at 2021-11-06T21:51:30+01:00 Reserve DLA-2811-1 for sqlalchemy - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reclaim salt in dla-needed.txt and update NOTES.

2021-11-08 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e9a8a80 by Markus Koschany at 2021-11-08T21:57:09+01:00 Reclaim salt in dla-needed.txt and update NOTES. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim sqlalchemy in dla-needed.txt

2021-11-03 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f82bd90 by Markus Koschany at 2021-11-03T16:59:25+01:00 Claim sqlalchemy in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Claim nvidia-graphics-drivers in dla-needed.txt

2021-12-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 78411da6 by Markus Koschany at 2021-12-01T22:59:36+01:00 Claim nvidia-graphics-drivers in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2842-1 for apache-log4j2

2021-12-12 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fe344981 by Markus Koschany at 2021-12-12T15:16:13+01:00 Reserve DLA-2842-1 for apache-log4j2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-44228,apache-log4j2: Fixed in unstable

2021-12-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1b5f92ad by Markus Koschany at 2021-12-11T16:09:43+01:00 CVE-2021-44228,apache-log4j2: Fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5022-1 for apache-log4j2

2021-12-16 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0440a6aa by Markus Koschany at 2021-12-16T11:09:52+01:00 Reserve DSA-5022-1 for apache-log4j2 - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Triage CVE-2021-45046,apache-log4j2 as not-affected.

2021-12-14 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3891c020 by Markus Koschany at 2021-12-14T23:52:38+01:00 Triage CVE-2021-45046,apache-log4j2 as not-affected. The JndiLookup class has been removed already. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Claim apache-log4j2 in dla-needed.txt

2021-12-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 81d8bded by Markus Koschany at 2021-12-10T22:44:12+01:00 Claim apache-log4j2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Update notes for nvidia-graphics-drivers in dla-needed.txt

2021-12-10 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a92991a7 by Markus Koschany at 2021-12-10T22:45:52+01:00 Update notes for nvidia-graphics-drivers in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim apache-log4j2 in dsa-needed.txt

2021-12-11 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f7ef9cfc by Markus Koschany at 2021-12-11T17:20:20+01:00 Claim apache-log4j2 in dsa-needed.txt - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

  1   2   3   4   5   6   7   >