[Git][security-tracker-team/security-tracker][master] dla: claim nodejs

2022-08-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e7fc22a by Sylvain Beucler at 2022-08-29T17:48:25+02:00 dla: claim nodejs - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[SECURITY] [DLA 3082-1] exim4 security update

2022-08-27 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3082-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler August 27, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3082-1 for exim4

2022-08-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bf2b35fc by Sylvain Beucler at 2022-08-27T18:22:26+02:00 Reserve DLA-3082-1 for exim4 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] dla: claim exim4

2022-08-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f9fbc44 by Sylvain Beucler at 2022-08-22T18:26:08+02:00 dla: claim exim4 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-12 Thread Sylvain Beucler
ate future, and the discussion seems to have reached consensus, so I think it's good for upload :) Cheers! Sylvain Beucler Debian LTS Team

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-10 Thread Sylvain Beucler
Hi, On 10/08/2022 11:47, Emilio Pozuelo Monfort wrote: On 09/08/2022 19:04, Sylvain Beucler wrote: Here's a little recap for security-support-ended.deb9 -> deb10 evaluation, following our discussion, also including dropped entries for completeness/transparency: Supported again in bus

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-09 Thread Sylvain Beucler
s-mozilla - reel - tomcat6 https://salsa.debian.org/debian/debian-security-support/-/blob/master/security-support-ended.deb9 https://salsa.debian.org/debian/debian-security-support/-/blob/master/security-support-ended.deb10 Cheers! Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3069-1] gst-plugins-good1.0 security update

2022-08-09 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3069-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sebastian Dro"ge August 09, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3069-1 for gst-plugins-good1.0

2022-08-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5813033a by Sylvain Beucler at 2022-08-09T14:39:59+02:00 Reserve DLA-3069-1 for gst-plugins-good1.0 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

Re: gst-plugins-good1.0/1.14.4-1+deb10u2 for DLA

2022-08-09 Thread Sylvain Beucler
Hi, Thanks for the heads-up. I'll make the announcement. Cheers! Sylvain Beucler Debian LTS Team On 09/08/2022 14:07, Salvatore Bonaccorso wrote: Hi LTS team members! The maintainer for gst-plugins-good1.0 uploaded for buster-security an update to address current CVEs. I have thus added

Re: EOL candidates for security-support-ended.deb10 (libspring-java support)

2022-08-08 Thread Sylvain Beucler
Hello Moritz, On 05/08/2022 11:59, Moritz Mühlenhoff wrote: Am Wed, Aug 03, 2022 at 11:54:28AM +0200 schrieb Sylvain Beucler: I think the following stretch EOL entries also apply to buster, because the rationale still applies to the buster versions: - libspring-java https://lists.debian.org

Re: EOL candidates for security-support-ended.deb10 (OpenStack support)

2022-08-08 Thread Sylvain Beucler
Hi, On Wed, Aug 03, 2022 at 11:54:28AM +0200, Sylvain Beucler wrote: > OpenStack: we tend not to support openstack beyond upstream's support My statement was influenced by the OpenStack 2020 EOL in jessie: https://salsa.debian.org/debian/debian-security-support/-/merge_requests/3 "Jes

[Git][security-tracker-team/security-tracker][master] dla: update qemu status following abhijith contact

2022-08-08 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 44cd31ff by Sylvain Beucler at 2022-08-08T11:08:00+02:00 dla: update qemu status following abhijith contact - - - - - 1 changed file: - data/dla-needed.txt Changes

Bug#1010349: closed by Sylvain Beucler (Re: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib)

2022-08-03 Thread Sylvain Beucler
Hi, On 03/08/2022 19:31, Moritz Mühlenhoff wrote: > Am Sat, May 28, 2022 at 06:36:29PM +0200 schrieb Sylvain Beucler: >> - the package uses system dxflib, cf. debian/patches/debian_build.patch > > But is that functional/working as expected? librecad does not > have and depend

Bug#1010349: closed by Sylvain Beucler (Re: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib)

2022-08-03 Thread Sylvain Beucler
Hi, On 03/08/2022 19:31, Moritz Mühlenhoff wrote: > Am Sat, May 28, 2022 at 06:36:29PM +0200 schrieb Sylvain Beucler: >> - the package uses system dxflib, cf. debian/patches/debian_build.patch > > But is that functional/working as expected? librecad does not > have and depend

[Git][security-tracker-team/security-tracker][master] CVE-2021-21897/librecad: leave unfixed but mark unimportant

2022-08-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4bc77255 by Sylvain Beucler at 2022-08-03T20:48:10+02:00 CVE-2021-21897/librecad: leave unfixed but mark unimportant following input from jmm and carnil in #1010349 - - - - - 1 changed file

[Git][security-tracker-team/security-tracker][master] CVE-2021-21897/librecad not-affected

2022-08-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 7aed0753 by Sylvain Beucler at 2022-08-03T17:37:20+02:00 CVE-2021-21897/librecad not-affected cf. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1010349 for rationale, no feedback/rebutal after 2

[Git][security-tracker-team/security-tracker][master] dla: claim qemu

2022-08-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b4b33215 by Sylvain Beucler at 2022-08-03T16:55:06+02:00 dla: claim qemu - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

EOL candidates for security-support-ended.deb10

2022-08-03 Thread Sylvain Beucler
Hi, I think the following stretch EOL entries also apply to buster, because the rationale still applies to the buster versions: - ckeditor3 https://lists.debian.org/debian-lts/2022/05/msg00060.html - gpac https://lists.debian.org/debian-lts/2022/04/msg8.html - libspring-java

[Git][security-tracker-team/security-tracker][master] dla: drop slurm-llnl (EOL'd)

2022-08-02 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d120185c by Sylvain Beucler at 2022-08-02T08:42:34+02:00 dla: drop slurm-llnl (EOLd) - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

Debian LTS and ELTS - July 2022

2022-08-01 Thread Sylvain Beucler
the CVEs: contribute opinion https://salsa.debian.org/lts-team/lts-extra-tasks/-/issues/38 - LTS documentation: fix a couple migration issues - IRC meeting -- Sylvain Beucler Debian LTS Team

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: drop LTS inactivity note

2022-08-01 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 925d179f by Sylvain Beucler at 2022-08-01T16:23:29+02:00 dla: drop LTS inactivity note - - - - - 73672b19 by Sylvain Beucler at 2022-08-01T16:25:03+02:00 dla: claim slurm-llnl (for EOL

[Git][security-tracker-team/security-tracker][master] dla: reminder not to conflict with opu

2022-07-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 7454be62 by Sylvain Beucler at 2022-07-28T16:56:45+02:00 dla: reminder not to conflict with opu - - - - - 1 changed file: - data/dla-needed.txt Changes

Re: What do do with bullseye minor issues?

2022-07-25 Thread Sylvain Beucler
Hi, On 14/07/2022 23:49, Ola Lundqvist wrote: During my front desk work I have now got down to the CVEs for buster that are "postponed". The triage script suggests me to "ignore" or "fix". You mean this particular section: "Issues postponed for , but already fixed in via DSA or point

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-19603/sqlite3: document affected versions

2022-07-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: eece83d1 by Sylvain Beucler at 2022-07-23T10:53:03+02:00 CVE-2019-19603/sqlite3: document affected versions - - - - - 8b553135 by Sylvain Beucler at 2022-07-23T10:53:04+02:00 CVE-2019-19645,CVE

[Git][security-tracker-team/security-tracker][master] CVE-2021-46828/libtirpc: reference introductory commit

2022-07-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: cba4d476 by Sylvain Beucler at 2022-07-22T21:35:06+02:00 CVE-2021-46828/libtirpc: reference introductory commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2022-31625,CVE-2022-31626/php: reference patches

2022-07-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 45472114 by Sylvain Beucler at 2022-07-22T18:51:40+02:00 CVE-2022-31625,CVE-2022-31626/php: reference patches - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2022-2255/mod-wsgi: reference introductory commit

2022-07-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 80dddce6 by Sylvain Beucler at 2022-07-19T20:58:51+02:00 CVE-2022-2255/mod-wsgi: reference introductory commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] DSA-5126-1/ffmpeg: reference fixed CVEs

2022-07-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6bbce2f2 by Sylvain Beucler at 2022-07-19T12:41:20+02:00 DSA-5126-1/ffmpeg: reference fixed CVEs - - - - - 2 changed files: - data/CVE/list - data/DSA/list Changes

[Git][security-tracker-team/security-tracker][master] DLA-3062-1/ublock-origin: reference additional CVE

2022-07-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 53fa30d8 by Sylvain Beucler at 2022-07-18T19:19:57+02:00 DLA-3062-1/ublock-origin: reference additional CVE - - - - - 1 changed file: - data/DLA/list Changes

[Git][security-tracker-team/security-tracker][master] Reference workflow during buster transition

2022-07-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c4616112 by Sylvain Beucler at 2022-07-18T09:31:19+02:00 Reference workflow during buster transition - - - - - 1 changed file: - data/dla-needed.txt Changes

Debian LTS - June 2022

2022-07-01 Thread Sylvain Beucler
- Running tests: document direct run with newer/stretch syntax, some logging tips https://wiki.debian.org/LTS/TestSuites/autopkgtest?action=diff=3=2 -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3063-1] systemd security update

2022-06-30 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3063-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 30, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3063-1 for systemd

2022-06-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 572102ec by Sylvain Beucler at 2022-06-30T16:35:21+02:00 Reserve DLA-3063-1 for systemd - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes

[SECURITY] [DLA 3061-1] firejail security update

2022-06-29 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3061-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 29, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3061-1 for firejail

2022-06-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d803cb9c by Sylvain Beucler at 2022-06-29T21:54:49+02:00 Reserve DLA-3061-1 for firejail - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] dla: claim systemd

2022-06-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 51105efd by Sylvain Beucler at 2022-06-29T14:44:13+02:00 dla: claim systemd - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: track missing CVE from DLA-3055-1

2022-06-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a7ef5eba by Sylvain Beucler at 2022-06-23T08:49:45+02:00 dla: track missing CVE from DLA-3055-1 thanks Chris Lamb for the report - - - - - 1 changed file: - data/DLA/list Changes

[Pkg-javascript-devel] ckeditor4 security update

2022-06-22 Thread Sylvain Beucler
that sound doable and safe enough, or do you think there's too much of a risk of breakage? Cheers! Sylvain Beucler Debian LTS Team -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

[Git][security-tracker-team/security-tracker][master] CVE-2022-31214/firejail: reference upstream backports

2022-06-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 7492d950 by Sylvain Beucler at 2022-06-21T18:14:37+02:00 CVE-2022-31214/firejail: reference upstream backports - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: claim firejail

2022-06-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 620a by Sylvain Beucler at 2022-06-21T17:04:15+02:00 dla: claim firejail - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[SECURITY] [DLA 3055-1] ntfs-3g security update

2022-06-21 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3055-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 21, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3055-1 for ntfs-3g

2022-06-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9da6b34f by Sylvain Beucler at 2022-06-21T13:21:40+02:00 Reserve DLA-3055-1 for ntfs-3g - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] dla: update ckeditor status

2022-06-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c846b261 by Sylvain Beucler at 2022-06-18T15:44:21+02:00 dla: update ckeditor status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] dla: claim ntfs-3g

2022-06-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c6c8d8d5 by Sylvain Beucler at 2022-06-18T15:19:09+02:00 dla: claim ntfs-3g - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

ckeditor4 security update

2022-06-17 Thread Sylvain Beucler
that sound doable and safe enough, or do you think there's too much of a risk of breakage? Cheers! Sylvain Beucler Debian LTS Team

[Git][security-tracker-team/security-tracker][master] dla: drop dpdk (all 5 CVEs not-affected)

2022-06-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f6745520 by Sylvain Beucler at 2022-06-17T14:27:56+02:00 dla: drop dpdk (all 5 CVEs not-affected) - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2020-14374, CVE-2020-14375, CVE-2020-14376, CVE-2020-14377, CVE-2020-14378/dpd...

2022-06-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 05d8add6 by Sylvain Beucler at 2022-06-17T14:26:30+02:00 CVE-2020-14374,CVE-2020-14375,CVE-2020-14376,CVE-2020-14377,CVE-2020-14378/dpdk: stretch not-affected - - - - - 1 changed file: - data

[Git][security-tracker-team/security-tracker][master] CVE-2020-14374, CVE-2020-14375, CVE-2020-14376, CVE-2020-14377, CVE-2020-14378/dpd...

2022-06-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ac6b3779 by Sylvain Beucler at 2022-06-13T18:33:18+02:00 CVE-2020-14374,CVE-2020-14375,CVE-2020-14376,CVE-2020-14377,CVE-2020-14378/dpdk: reference upstream patches - - - - - 1 changed file

[Git][security-tracker-team/security-tracker][master] dla: claim dpdk

2022-06-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0957a2cb by Sylvain Beucler at 2022-06-10T19:26:36+02:00 dla: claim dpdk - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[SECURITY] [DLA 3050-1] vlc security update

2022-06-10 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3050-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 10, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3050-1 for vlc

2022-06-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: db6b9344 by Sylvain Beucler at 2022-06-10T18:45:21+02:00 Reserve DLA-3050-1 for vlc - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes

Re: buster & ntpd leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 19 days

2022-06-09 Thread Sylvain Beucler
Hello Marc, The exact switch dates aren't set yet. I'd recommend opening a bug against buster's ntpd, and add debian-lts@lists.debian.org in Cc. Cheers! Sylvain Beucler Debian LTS Team On 09/06/2022 11:04, Marc SCHAEFER wrote: buster is not yet handled by LTS, but it will be soon AFAIK

[Git][security-tracker-team/security-tracker][master] dla: claim vlc

2022-06-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 46ff7619 by Sylvain Beucler at 2022-06-09T12:32:32+02:00 dla: claim vlc - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[SECURITY] [DLA 3049-1] mailman security update

2022-06-09 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3049-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 09, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3049-1 for mailman

2022-06-09 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ce13f64 by Sylvain Beucler at 2022-06-09T12:04:59+02:00 Reserve DLA-3049-1 for mailman - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2021-44227/mailman: vcs patch refs

2022-06-08 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fb2281ee by Sylvain Beucler at 2022-06-08T21:11:51+02:00 CVE-2021-44227/mailman: vcs patch refs - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2021-43331,CVE-2021-43332/mailman: vcs patch refs

2022-06-08 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f66d8f80 by Sylvain Beucler at 2022-06-08T20:36:17+02:00 CVE-2021-43331,CVE-2021-43332/mailman: vcs patch refs - - - - - 1 changed file: - data/CVE/list Changes

Debian LTS and ELTS - May 2022

2022-06-01 Thread Sylvain Beucler
/2022/05/msg00038.html - Clarify report label and document expected front-desk action - Internal discussions - Recommend keeping documentation in the wiki and ad-hoc READMEs - Recommend leaving git-based workflow optional - Help LTS newcomers on IRC -- Sylvain Beucler Debian LTS Team

[Git][security-tracker-team/security-tracker][master] dla: claim mailman

2022-05-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 69c22bdc by Sylvain Beucler at 2022-05-31T11:26:19+02:00 dla: claim mailman - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[SECURITY] [DLA 3035-1] libdbi-perl security update

2022-05-30 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3035-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler May 30, 2022

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3035-1 for libdbi-perl

2022-05-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a1802074 by Sylvain Beucler at 2022-05-30T21:50:12+02:00 Reserve DLA-3035-1 for libdbi-perl - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2014-10402/libdbi-perl: add patch reference

2022-05-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d279cbd3 by Sylvain Beucler at 2022-05-30T20:31:01+02:00 CVE-2014-10402/libdbi-perl: add patch reference - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: claim libdbi-perl

2022-05-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6986202b by Sylvain Beucler at 2022-05-30T10:33:12+02:00 dla: claim libdbi-perl - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-05-28 Thread Sylvain Beucler
for 'groupCode==42'), this particular file is not used in the build process AFAICT Can you confirm and update the security tracker accordingly? Cheers! Sylvain Beucler Debian LTS Team On Fri, 29 Apr 2022 11:09:43 +0100 Neil Williams wrote: Source: librecad Version: 2.1.3-3 Severity: important

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-05-28 Thread Sylvain Beucler
for 'groupCode==42'), this particular file is not used in the build process AFAICT Can you confirm and update the security tracker accordingly? Cheers! Sylvain Beucler Debian LTS Team On Fri, 29 Apr 2022 11:09:43 +0100 Neil Williams wrote: Source: librecad Version: 2.1.3-3 Severity: important

[Git][security-tracker-team/security-tracker][master] dla: add libmatio

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ebe2ab09 by Sylvain Beucler at 2022-05-28T18:13:45+02:00 dla: add libmatio - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2022-1215/libinput: reference introductory commit + stretch not-affected

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4f6ea281 by Sylvain Beucler at 2022-05-28T17:44:29+02:00 CVE-2022-1215/libinput: reference introductory commit + stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: add jupyter-notebook

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ed3ef108 by Sylvain Beucler at 2022-05-28T17:09:52+02:00 dla: add jupyter-notebook - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2022-25844/angular.js: stretch ignored

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4476dd6f by Sylvain Beucler at 2022-05-28T16:59:23+02:00 CVE-2022-25844/angular.js: stretch ignored - - - - - 4b59151d by Sylvain Beucler at 2022-05-28T16:59:23+02:00 dla: add grunt

[Git][security-tracker-team/security-tracker][master] dla: add halibut

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 69ac6bfc by Sylvain Beucler at 2022-05-28T11:46:15+02:00 dla: add halibut - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add pypdf2

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 429a3b74 by Sylvain Beucler at 2022-05-28T11:36:35+02:00 dla: add pypdf2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: Fix typo

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b5981190 by Sylvain Beucler at 2022-05-28T11:24:24+02:00 Fix typo - - - - - 75260e87 by Sylvain Beucler at 2022-05-28T11:24:24+02:00 dla: add pyjwt - - - - - 2 changed files: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: add pidgin

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0afa0860 by Sylvain Beucler at 2022-05-28T11:01:33+02:00 dla: add pidgin - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] lts-cve-triage.py: clarify report header

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ef438048 by Sylvain Beucler at 2022-05-28T10:44:26+02:00 lts-cve-triage.py: clarify report header - - - - - 1 changed file: - bin/lts-cve-triage.py Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-12827,CVE-2019-15297/asterisk: precise stretch triage

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 50a0c977 by Sylvain Beucler at 2022-05-28T10:41:37+02:00 CVE-2019-12827,CVE-2019-15297/asterisk: precise stretch triage - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2021-42700,CVE-2021-42702,CVE-2021-42704/inkscape: add reference

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f134d659 by Sylvain Beucler at 2022-05-28T10:26:21+02:00 CVE-2021-42700,CVE-2021-42702,CVE-2021-42704/inkscape: add reference - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2022-1897,CVE-2022-1898/vim: stretch postponed

2022-05-28 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 11747c06 by Sylvain Beucler at 2022-05-28T10:04:53+02:00 CVE-2022-1897,CVE-2022-1898/vim: stretch postponed - - - - - c39411f3 by Sylvain Beucler at 2022-05-28T10:04:54+02:00 CVE-2022-0544,CVE-2022

[Git][security-tracker-team/security-tracker][master] CVE-2021-32627,CVE-2021-32628/redis: precise triage

2022-05-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c352801c by Sylvain Beucler at 2022-05-27T10:26:20+02:00 CVE-2021-32627,CVE-2021-32628/redis: precise triage - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 4 commits: dla: add thunderbird

2022-05-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 08e3e4cc by Sylvain Beucler at 2022-05-27T10:02:22+02:00 dla: add thunderbird - - - - - e7f136de by Sylvain Beucler at 2022-05-27T10:02:22+02:00 dla: add smarty3 - - - - - a4d0aac5 by Sylvain

Re: Support for ckeditor3 in Debian

2022-05-25 Thread Sylvain Beucler
Hi, On 21/05/2022 12:06, Sylvain Beucler wrote: On 21/05/2022 10:45, Mike Gabriel wrote: as I have a company interest in Horde and thus in ckeditor3, I'd be happy to co-fund work hours on ckeditor3. Esp. because ckeditor3 in unstable needs the same love as in LTS. And we are currently working

Re: What is going on with debian-security-support in stretch?

2022-05-25 Thread Sylvain Beucler
Hi, For the record: https://salsa.debian.org/security-tracker-team/security-tracker/-/blob/03a7d97fa8090d6f48808b08265b970606cb1569/data/dla-needed.txt#L50 Cheers! Sylvain Beucler Debian LTS Team On 20/05/2022 22:00, Roberto C. Sánchez wrote: I've not looked at the debian-security-support

[Git][security-tracker-team/security-tracker][master] dla: add freerdp

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 26a2bf6d by Sylvain Beucler at 2022-05-25T12:01:05+02:00 dla: add freerdp - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add pjproject

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0debcbf2 by Sylvain Beucler at 2022-05-25T11:54:00+02:00 dla: add pjproject - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2021-42218/ompl: stretch not-affected

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6048a85e by Sylvain Beucler at 2022-05-25T11:30:52+02:00 CVE-2021-42218/ompl: stretch not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-21698/golang-github-prometheus-client-golang: stretch postponed

2022-05-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 10ef6d47 by Sylvain Beucler at 2022-05-25T09:34:15+02:00 CVE-2022-21698/golang-github-prometheus-client-golang: stretch postponed - - - - - 20db17ba by Sylvain Beucler at 2022-05-25T09:44:10+02:00

Re: Tracking buster/stable updates suitable for LTS

2022-05-24 Thread Sylvain Beucler
Anton Am Di., 17. Mai 2022 um 14:43 Uhr schrieb Sylvain Beucler mailto:b...@beuc.net>>: > > Hi, > > On 17/05/2022 08:44, Ola Lundqvist wrote: > > When doing triaging this week as part of the front desk assignment I > > reali

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: add vlc

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: de18cdc6 by Sylvain Beucler at 2022-05-24T17:28:40+02:00 dla: add vlc - - - - - 07a81f3a by Sylvain Beucler at 2022-05-24T17:28:40+02:00 dla: add zipios++ - - - - - 1 changed file: - data/dla

[Git][security-tracker-team/security-tracker][master] dla: add ublock-origin

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: cf6d6886 by Sylvain Beucler at 2022-05-24T17:16:36+02:00 dla: add ublock-origin - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] dla: add systemd

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0bc5d771 by Sylvain Beucler at 2022-05-24T17:11:44+02:00 dla: add systemd - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: add sleuthkit

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 889df7da by Sylvain Beucler at 2022-05-24T16:48:51+02:00 dla: add sleuthkit - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2020-13124,CVE-2021-29488/sabnzbdplus: precise stretch status

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8526f6eb by Sylvain Beucler at 2022-05-24T16:43:45+02:00 CVE-2020-13124,CVE-2021-29488/sabnzbdplus: precise stretch status - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: add ros-ros-comm

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e40b8f70 by Sylvain Beucler at 2022-05-24T16:38:28+02:00 dla: add ros-ros-comm - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] dla: add request-tracker4

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bbc8557e by Sylvain Beucler at 2022-05-24T16:30:45+02:00 dla: add request-tracker4 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-3866/mistral,python-oslo.utils: clarify/update stretch status

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 821ddda7 by Sylvain Beucler at 2022-05-24T16:13:23+02:00 CVE-2019-3866/mistral,python-oslo.utils: clarify/update stretch status - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2018-16848/mistral: OpenStack EOL'd in jessie but not in stretch

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 88525be7 by Sylvain Beucler at 2022-05-24T15:23:35+02:00 CVE-2018-16848/mistral: OpenStack EOLd in jessie but not in stretch - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: add pngcheck

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3893ed2b by Sylvain Beucler at 2022-05-24T11:55:12+02:00 dla: add pngcheck - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add plinth

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5537158f by Sylvain Beucler at 2022-05-24T11:43:19+02:00 dla: add plinth - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: add pam-u2f

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: dd7ec8bc by Sylvain Beucler at 2022-05-24T11:30:51+02:00 dla: add pam-u2f - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: add openscad

2022-05-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 16ac647a by Sylvain Beucler at 2022-05-24T11:27:03+02:00 dla: add openscad - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

<    2   3   4   5   6   7   8   9   10   11   >