[Git][security-tracker-team/security-tracker][master] dla: claim jetty9

2021-06-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b7635f80 by Sylvain Beucler at 2021-06-11T18:43:27+02:00 dla: claim jetty9 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: xmlbeans: report IRC discussion + ELTS status

2021-06-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c2ea11b0 by Sylvain Beucler at 2021-06-09T19:04:16+02:00 dla: xmlbeans: report IRC discussion + ELTS status - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: squid3: reference ELTS same-version upload

2021-06-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 65b9d151 by Sylvain Beucler at 2021-06-09T19:07:46+02:00 dla: squid3: reference ELTS same-version upload - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-10241/jetty: fix comment

2021-06-12 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 89c1207a by Sylvain Beucler at 2021-06-12T18:58:58+02:00 CVE-2019-10241/jetty: fix comment - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-28834/ruby-kramdown: stretch not-affected

2021-06-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 91e89727 by Sylvain Beucler at 2021-06-10T18:10:30+02:00 CVE-2021-28834/ruby-kramdown: stretch not-affected - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: claim ruby-doorkeeper

2021-06-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 303b251d by Sylvain Beucler at 2021-06-10T18:32:30+02:00 dla: claim ruby-doorkeeper - - - - - 19ac6194 by Sylvain Beucler at 2021-06-10T18:33:03+02:00 dla: ruby-doorkeeper: drop notes on

[Git][security-tracker-team/security-tracker][master] dla: claim ruby-kramdown

2021-06-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 24a4686b by Sylvain Beucler at 2021-06-10T17:06:10+02:00 dla: claim ruby-kramdown - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2018-1000211/ruby-doorkeeper: stretch ignored

2021-06-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c44f06a by Sylvain Beucler at 2021-06-17T22:15:19+02:00 CVE-2018-1000211/ruby-doorkeeper: stretch ignored - - - - - 7e0d8190 by Sylvain Beucler at 2021-06-17T22:15:20+02:00

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2688-1 for jetty9

2021-06-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8890d64b by Sylvain Beucler at 2021-06-17T20:22:44+02:00 Reserve DLA-2688-1 for jetty9 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim openexr

2021-06-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f823459f by Sylvain Beucler at 2021-06-19T18:57:28+02:00 dla: claim openexr - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2017-12596/openexr: reference common 2017-911x patch

2021-06-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f6e9cc77 by Sylvain Beucler at 2021-06-22T23:04:10+02:00 CVE-2017-12596/openexr: reference common 2017-911x patch - - - - - d2433469 by Sylvain Beucler at 2021-06-22T23:04:11+02:00

[Git][security-tracker-team/security-tracker][master] CVE-2020-11763/openexr: reference merged patch

2021-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 21e537f7 by Sylvain Beucler at 2021-06-23T19:37:24+02:00 CVE-2020-11763/openexr: reference merged patch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2017-9114/openexr: clarify fixed versions

2021-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: eab805e1 by Sylvain Beucler at 2021-06-23T18:07:37+02:00 CVE-2017-9114/openexr: clarify fixed versions Follow-up to d2433469e14f4e07b77e28e5b20085391450260d - - - - - 10c9155e by Sylvain Beucler at

[Git][security-tracker-team/security-tracker][master] CVE-2020-11758, CVE-2020-11759, CVE-2020-11761, CVE-2020-11762, CVE-2020-11765/ope...

2021-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d91efac4 by Sylvain Beucler at 2021-06-23T19:24:04+02:00 CVE-2020-11758,CVE-2020-11759,CVE-2020-11761,CVE-2020-11762,CVE-2020-11765/openexr: precise affected versions - - - - - 1 changed file:

[Git][security-tracker-team/security-tracker][master] CVE-2020-11761/openexr: reference additional patches

2021-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8310cfd4 by Sylvain Beucler at 2021-06-23T20:14:54+02:00 CVE-2020-11761/openexr: reference additional patches - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-11761/openexr: revert not-affected

2021-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 1583b340 by Sylvain Beucler at 2021-06-23T21:51:50+02:00 CVE-2020-11761/openexr: revert not-affected PoC has 3 vectors, 2 of which directly related to additional patches from

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2017-9110,CVE-2017-9112,CVE-2017-9116/openexr: reference upstream patch

2021-06-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ce36a2a by Sylvain Beucler at 2021-06-22T00:04:05+02:00 CVE-2017-9110,CVE-2017-9112,CVE-2017-9116/openexr: reference upstream patch - - - - - 26012d62 by Sylvain Beucler at

[Git][security-tracker-team/security-tracker][master] CVE-2020-11764/openexr: reference patch that fixes the reproducer

2021-06-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ef414c96 by Sylvain Beucler at 2021-06-24T19:05:42+02:00 CVE-2020-11764/openexr: reference patch that fixes the reproducer - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-15305,CVE-2020-15306/openexr: precise affected versions

2021-06-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c905c8ef by Sylvain Beucler at 2021-06-24T22:38:05+02:00 CVE-2020-15305,CVE-2020-15306/openexr: precise affected versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Revert "Triage CVE-2020-16587 in openexr for stretch LTS."

2021-06-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ee5bdd73 by Sylvain Beucler at 2021-06-24T22:56:44+02:00 Revert Triage CVE-2020-16587 in openexr for stretch LTS. This reverts commit e152b7e42940e7a2fea74e98cb50c047b9940e4b. Given that the

[Git][security-tracker-team/security-tracker][master] CVE-2021-3474/openexr: precise affected versions

2021-06-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b9347f4e by Sylvain Beucler at 2021-06-24T23:21:19+02:00 CVE-2021-3474/openexr: precise affected versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim libxstream-java

2021-06-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 1840866e by Sylvain Beucler at 2021-06-18T18:34:46+02:00 dla: claim libxstream-java - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-29505/libxstream-java: reference patch

2021-06-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bf1273c4 by Sylvain Beucler at 2021-06-18T18:19:27+02:00 CVE-2021-29505/libxstream-java: reference patch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-28169/jetty: reference patch

2021-06-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e5a5580b by Sylvain Beucler at 2021-06-11T15:47:11+02:00 CVE-2021-28169/jetty: reference patch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2020-27223/jetty: stretch not-affected

2021-05-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6efb962b by Sylvain Beucler at 2021-05-11T12:32:57+02:00 CVE-2020-27223/jetty: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-28165/jetty9: stretch ignored

2021-05-12 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fbdcc650 by Sylvain Beucler at 2021-05-12T11:16:25+02:00 CVE-2021-28165/jetty9: stretch ignored - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2560-1 for jetty9

2021-05-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d5b791b9 by Sylvain Beucler at 2021-05-14T15:16:10+02:00 Reserve DLA-2560-1 for jetty9 - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2664-1 for curl

2021-05-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 57bf5a8f by Sylvain Beucler at 2021-05-17T16:32:01+02:00 Reserve DLA-2664-1 for curl - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-30130/phpseclib: precise affected versions

2021-05-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d33a4d2b by Sylvain Beucler at 2021-05-17T21:09:45+02:00 CVE-2021-30130/phpseclib: precise affected versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-28163/jetty9: stretch not-affected

2021-05-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e8ca1d9 by Sylvain Beucler at 2021-05-11T16:25:41+02:00 CVE-2021-28163/jetty9: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-28164/jetty9: stretch not-affected

2021-05-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5df94d08 by Sylvain Beucler at 2021-05-11T16:56:10+02:00 CVE-2021-28164/jetty9: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-10241/jetty: jessie not-affected

2021-05-12 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ac4780d1 by Sylvain Beucler at 2021-05-12T21:22:04+02:00 CVE-2019-10241/jetty: jessie not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: claim curl

2021-05-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 557abac5 by Sylvain Beucler at 2021-05-14T19:08:45+02:00 dla: claim curl - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2667-1 for djvulibre

2021-05-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a03ea860 by Sylvain Beucler at 2021-05-26T17:15:49+02:00 Reserve DLA-2667-1 for djvulibre - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim djvulibre

2021-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e5ac234a by Sylvain Beucler at 2021-05-25T17:18:04+02:00 dla: claim djvulibre - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] djvulibre: reference upstream patches

2021-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 12af51f2 by Sylvain Beucler at 2021-05-25T17:54:33+02:00 djvulibre: reference upstream patches CVE-2021-3500 CVE-2021-32490 CVE-2021-32491 CVE-2021-32492 CVE-2021-32493 - - - - - 1 changed file:

[Git][security-tracker-team/security-tracker][master] dla: squid3: reference elts work

2021-06-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b308cf2 by Sylvain Beucler at 2021-06-03T22:46:15+02:00 dla: squid3: reference elts work - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] squid3/CVE-2021-28116: add upstream status

2021-06-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 528df0ea by Sylvain Beucler at 2021-06-03T23:28:13+02:00 squid3/CVE-2021-28116: add upstream status - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2019-18218: reference embedded copy in php7.0

2021-07-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5ded8e10 by Sylvain Beucler at 2021-07-07T18:51:44+02:00 CVE-2019-18218: reference embedded copy in php7.0 - - - - - 1ce82024 by Sylvain Beucler at 2021-07-07T18:51:45+02:00 CVE-2019-6977/php:

[Git][security-tracker-team/security-tracker][master] dla: claim php7.0

2021-07-06 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5359c802 by Sylvain Beucler at 2021-07-06T14:31:45+02:00 dla: claim php7.0 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-3605/openexr: stretch triage

2021-07-06 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e023bce by Sylvain Beucler at 2021-07-06T16:09:28+02:00 CVE-2021-3605/openexr: stretch triage - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-3605/openexr: stretch postponed

2021-07-06 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b95d0bde by Sylvain Beucler at 2021-07-06T14:03:44+02:00 CVE-2021-3605/openexr: stretch postponed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-23215/openexr: reference 2.x patches

2021-07-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bd7f1962 by Sylvain Beucler at 2021-07-03T13:10:15+02:00 CVE-2021-23215/openexr: reference 2.x patches - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-23215/openexr: clarify patches some more

2021-07-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fbe3854d by Sylvain Beucler at 2021-07-03T15:49:33+02:00 CVE-2021-23215/openexr: clarify patches some more (Following prompt by carnil) de27156 is a pre-requisite for the 2.x branches (especially

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2701-1 for openexr

2021-07-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f7ee7c32 by Sylvain Beucler at 2021-07-03T20:03:25+02:00 Reserve DLA-2701-1 for openexr - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-3477/openexr: precise affected versions

2021-06-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9398fe7b by Sylvain Beucler at 2021-06-26T20:14:35+02:00 CVE-2021-3477/openexr: precise affected versions - - - - - b9d6f206 by Sylvain Beucler at 2021-06-26T20:58:19+02:00 CVE-2021-3478/openexr:

[Git][security-tracker-team/security-tracker][master] CVE-2021-3598/openexr: precise affected versions

2021-06-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3bafc582 by Sylvain Beucler at 2021-06-26T21:21:08+02:00 CVE-2021-3598/openexr: precise affected versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: status update

2021-06-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 300ece7e by Sylvain Beucler at 2021-06-26T22:08:17+02:00 dla: status update - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-3605/openexr: duplicate of CVE-2020-11760

2021-06-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8341bd0e by Sylvain Beucler at 2021-06-26T21:47:50+02:00 CVE-2021-3605/openexr: duplicate of CVE-2020-11760 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] embedded-code-copies: freeimage repacked without openexr

2021-07-06 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d7c1fc1f by Sylvain Beucler at 2021-07-06T18:53:52+02:00 embedded-code-copies: freeimage repacked without openexr - - - - - 1 changed file: - data/embedded-code-copies Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2704-1 for libxstream-java

2021-07-05 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f0b08488 by Sylvain Beucler at 2021-07-05T17:38:01+02:00 Reserve DLA-2704-1 for libxstream-java - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2019-13224/php7.0: fixed in previous upload

2021-07-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6bb2062f by Sylvain Beucler at 2021-07-09T17:43:04+02:00 CVE-2019-13224/php7.0: fixed in previous upload - - - - - 1 changed file: - data/DSA/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-38593/qt: precise versions

2021-08-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2685bffa by Sylvain Beucler at 2021-08-18T22:13:29+02:00 CVE-2021-38593/qt: precise versions The advisory mentions Qt5 but the crash appears to be only a few months old. Prior that (and prior the

[Git][security-tracker-team/security-tracker][master] CVE-2021-35368/modsecurity-crs: reference commits

2021-08-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fecc4ea by Sylvain Beucler at 2021-08-17T18:23:38+02:00 CVE-2021-35368/modsecurity-crs: reference commits - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-3621/sssd: reference patch and affected versions

2021-08-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bfa41ca6 by Sylvain Beucler at 2021-08-17T19:30:19+02:00 CVE-2021-3621/sssd: reference patch and affected versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-24742: add version tags

2021-08-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 944d7bd5 by Sylvain Beucler at 2021-08-17T19:14:23+02:00 CVE-2020-24742: add version tags - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-22222/wireshark: don't clutter with unsupported releases

2021-08-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e276d573 by Sylvain Beucler at 2021-08-31T16:39:11+02:00 CVE-2021-2/wireshark: dont clutter with unsupported releases - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: re-add amd64-microcode as update did not build

2021-08-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 64616099 by Sylvain Beucler at 2021-08-31T16:30:20+02:00 dla: re-add amd64-microcode as update did not build - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-23215/openexr: no stretch regression

2021-09-01 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bd9323a1 by Sylvain Beucler at 2021-09-01T17:48:44+02:00 CVE-2021-23215/openexr: no stretch regression (following discussion with secteam ~1 month ago) - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-32808/ckeditor: precise versions

2021-08-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 29e929ad by Sylvain Beucler at 2021-08-16T19:46:44+02:00 CVE-2021-32808/ckeditor: precise versions - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-21391/ckeditor: stretch not-affected

2021-08-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5cc601c8 by Sylvain Beucler at 2021-08-16T20:03:51+02:00 CVE-2021-21391/ckeditor: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-32809/ckeditor: precise versions

2021-08-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4c726671 by Sylvain Beucler at 2021-08-16T19:29:05+02:00 CVE-2021-32809/ckeditor: precise versions - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2021-38185/cpio: reference new regression

2021-08-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f3f6ee3e by Sylvain Beucler at 2021-08-21T18:56:01+02:00 CVE-2021-38185/cpio: reference new regression - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2020-21676/fig2dev: precise versions

2021-08-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5bf6b1ed by Sylvain Beucler at 2021-08-19T18:57:54+02:00 CVE-2020-21676/fig2dev: precise versions - - - - - 8a7c6d00 by Sylvain Beucler at 2021-08-19T18:57:55+02:00 CVE-2021-3561/fig2dev: patch

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2020-25695/postgresql: reference patch

2021-09-04 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4f3fcb22 by Sylvain Beucler at 2021-09-04T10:43:31+02:00 CVE-2020-25695/postgresql: reference patch - - - - - 1d5a651d by Sylvain Beucler at 2021-09-04T10:44:38+02:00 CVE-2020-25696/postgresql:

[Git][security-tracker-team/security-tracker][master] dla: add and claim gnutls28

2021-09-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 86143064 by Sylvain Beucler at 2021-09-10T20:41:50+02:00 dla: add and claim gnutls28 - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2018-1058/postgresql-9.4: reference fixed version

2021-09-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 59cd6ce1 by Sylvain Beucler at 2021-09-07T19:42:35+02:00 CVE-2018-1058/postgresql-9.4: reference fixed version - - - - - 86806d9e by Sylvain Beucler at 2021-09-07T19:42:36+02:00

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2761-1 for openssl

2021-09-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: feccd706 by Sylvain Beucler at 2021-09-18T22:08:23+02:00 Reserve DLA-2761-1 for openssl - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2759-1 for gnutls28

2021-09-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c799c63a by Sylvain Beucler at 2021-09-17T21:44:57+02:00 Reserve DLA-2759-1 for gnutls28 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2708-1 for php7.0

2021-07-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 72b2fa1b by Sylvain Beucler at 2021-07-15T10:33:51+02:00 Reserve DLA-2708-1 for php7.0 - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim golang-1.7

2021-07-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: da9634ce by Sylvain Beucler at 2021-07-15T15:10:11+02:00 dla: claim golang-1.7 - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] embedded-code-copies: dereference tiff3

2021-08-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8aa50a8d by Sylvain Beucler at 2021-08-09T19:24:44+02:00 embedded-code-copies: dereference tiff3 tiff3 was removed in 2014, last published in wheezy - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] dla: clarify who's tracking mosquitto

2021-08-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ac4a1099 by Sylvain Beucler at 2021-08-07T10:21:10+02:00 dla: clarify whos tracking mosquitto - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: clarify python-babel notes

2021-08-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 36273179 by Sylvain Beucler at 2021-08-11T16:12:00+02:00 dla: clarify python-babel notes - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: claim openexr

2021-07-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c048ea1a by Sylvain Beucler at 2021-07-28T19:59:54+02:00 dla: claim openexr - - - - - 2 changed files: - bin/lts-needs-forward-port.py - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-20298/openexr: fix is partial

2021-07-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a2342e79 by Sylvain Beucler at 2021-07-30T17:38:43+02:00 CVE-2021-20298/openexr: fix is partial - CVE-2021-20298 is a OOM, but the current fix only divides the memory usage by 2, hence below

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-20298/openexr: stretch postponed

2021-08-04 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bfa06328 by Sylvain Beucler at 2021-08-04T21:32:19+02:00 CVE-2021-20298/openexr: stretch postponed - - - - - 4676904f by Sylvain Beucler at 2021-08-04T21:39:11+02:00 Reserve DLA-2732-1 for openexr

[Git][security-tracker-team/security-tracker][master] CVE-2021-33196/golang: reference complementary CVE

2021-09-20 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a66c106 by Sylvain Beucler at 2021-09-20T16:31:35+02:00 CVE-2021-33196/golang: reference complementary CVE - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim apache2

2021-09-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d191a6c by Sylvain Beucler at 2021-09-23T14:49:42+02:00 dla: claim apache2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-36160: affects uwsgi

2021-09-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e06f7133 by Sylvain Beucler at 2021-09-24T19:59:44+02:00 CVE-2021-36160: affects uwsgi (prior merging mod_proxy_uwsgi into Apache 2.4.30) only binary:libapache2-mod-proxy-uwsgi/stretch should be

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-36160/apache2: stretch not-affected

2021-09-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ad18ab52 by Sylvain Beucler at 2021-09-24T20:02:08+02:00 CVE-2021-36160/apache2: stretch not-affected - - - - - 9350b535 by Sylvain Beucler at 2021-09-24T20:33:58+02:00 CVE-2021-39275/apache2:

[Git][security-tracker-team/security-tracker][master] CVE-2021-40438/apache2: reference first part of the fix

2021-09-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d8e90491 by Sylvain Beucler at 2021-09-25T19:47:05+02:00 CVE-2021-40438/apache2: reference first part of the fix - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-25635/libreoffice: windows-specific

2021-10-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d893be7 by Sylvain Beucler at 2021-10-13T20:02:26+02:00 CVE-2021-25635/libreoffice: windows-specific - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add my hours

2021-10-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 995d287d by Sylvain Beucler at 2021-10-11T16:41:58+02:00 Add my hours - - - - - 1 changed file: - org/lts-frontdesk.2022.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: claim libreoffice

2021-10-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 096de990 by Sylvain Beucler at 2021-10-11T20:19:28+02:00 dla: claim libreoffice - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: amd64-microcode: update status

2021-10-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 79c87b10 by Sylvain Beucler at 2021-10-11T16:55:16+02:00 dla: amd64-microcode: update status + make it clearer Im not involved in the update - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2768-2 for uwsgi

2021-10-20 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fc3f2a88 by Sylvain Beucler at 2021-10-20T18:56:05+02:00 Reserve DLA-2768-2 for uwsgi - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] DLA-2768-2: drop CVE reference

2021-10-20 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b5d65d17 by Sylvain Beucler at 2021-10-20T19:57:04+02:00 DLA-2768-2: drop CVE reference (following note from Salvatore) This fixes a functional regression, i.e. CVE was fully fixed in previous

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2790-1 for python-babel

2021-10-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e4fb9be by Sylvain Beucler at 2021-10-21T09:51:50+02:00 Reserve DLA-2790-1 for python-babel - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: python-babel status

2021-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e5788a70 by Sylvain Beucler at 2021-10-18T18:05:14+02:00 dla: python-babel status - - - - - 60c07c13 by Sylvain Beucler at 2021-10-18T18:09:03+02:00 dla: uwsgi status - - - - - 1 changed file:

[Git][security-tracker-team/security-tracker][master] dla: copy/paste jsoup status from extended-lts-t...@freexian.com exchange

2021-10-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c598977 by Sylvain Beucler at 2021-10-19T17:06:00+02:00 dla: copy/paste jsoup status from extended-lts-t...@freexian.com exchange - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-25634/libreoffice: stretch not-affected (yet)

2021-10-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4c45d9ec by Sylvain Beucler at 2021-10-15T20:57:11+02:00 CVE-2021-25634/libreoffice: stretch not-affected (yet) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim redmine

2021-10-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5f502b24 by Sylvain Beucler at 2021-10-16T18:44:06+02:00 dla: claim redmine - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-42326/redmine: reference patch

2021-10-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e4a7e423 by Sylvain Beucler at 2021-10-16T18:59:21+02:00 CVE-2021-42326/redmine: reference patch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: claim python-babel

2021-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 634274a2 by Sylvain Beucler at 2021-10-18T16:57:43+02:00 dla: claim python-babel - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: drop libreoffice

2021-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 18f62d22 by Sylvain Beucler at 2021-10-18T15:17:57+02:00 dla: drop libreoffice - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2787-1 for redmine

2021-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ccfe09db by Sylvain Beucler at 2021-10-18T17:55:53+02:00 Reserve DLA-2787-1 for redmine - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-40438/apache2: reference regression fix

2021-09-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d3f1e269 by Sylvain Beucler at 2021-09-28T18:02:38+02:00 CVE-2021-40438/apache2: reference regression fix (not shipped with 2.4.49) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2768-1 for uwsgi

2021-09-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 265c91bb by Sylvain Beucler at 2021-09-29T21:20:14+02:00 Reserve DLA-2768-1 for uwsgi - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-40438/apache2: clarify patches + re-order regression fixes

2021-09-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bffb81a1 by Sylvain Beucler at 2021-09-30T17:20:26+02:00 CVE-2021-40438/apache2: clarify patches + re-order regression fixes Cf. https://bugzilla.suse.com/show_bug.cgi?id=1190703#c1 - - - - - 1

  1   2   3   4   5   6   7   8   9   >