[Git][security-tracker-team/security-tracker][master] 2 commits: node-ejs: follow stable triage, buster postponed

2024-05-04 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f3180c9 by Sylvain Beucler at 2024-05-04T18:05:59+02:00 node-ejs: follow stable triage, buster postponed - - - - - b1dd32d8 by Sylvain Beucler at 2024-05-04T18:10:48+02:00 CVE-2024-3572/python

[Git][security-tracker-team/security-tracker][master] 4 commits: CVE-2017-7938,CVE-2020-14931,CVE-2024-31837/dmitry: buster postponed

2024-05-04 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c8c8eeed by Sylvain Beucler at 2024-05-04T18:03:21+02:00 CVE-2017-7938,CVE-2020-14931,CVE-2024-31837/dmitry: buster postponed - - - - - 5aa5566a by Sylvain Beucler at 2024-05-04T18:03:23+02:00

[Git][security-tracker-team/security-tracker][master] dla: add ruby2.5

2024-05-04 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 76371c0c by Sylvain Beucler at 2024-05-04T12:56:15+02:00 dla: add ruby2.5 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2023-46566/tftpy: buster postponed

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f36a742d by Sylvain Beucler at 2024-05-03T18:26:24+02:00 CVE-2023-46566/tftpy: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2024-1892/python-scrapy: link GHSA to help disambiguate CVE-2024-3572

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 274e77ed by Sylvain Beucler at 2024-05-03T18:19:48+02:00 CVE-2024-1892/python-scrapy: link GHSA to help disambiguate CVE-2024-3572 - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] RUSTSEC-2024-0332: buster postponed

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 1dfb2671 by Sylvain Beucler at 2024-05-03T18:17:01+02:00 RUSTSEC-2024-0332: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: add pypy3

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 838a46e8 by Sylvain Beucler at 2024-05-03T18:14:03+02:00 dla: add pypy3 - - - - - 9cd54b9d by Sylvain Beucler at 2024-05-03T18:14:05+02:00 CVE-2024-3572/python-scrapy: un-triage buster, theres

[Git][security-tracker-team/security-tracker][master] CVE-2024-3572,CVE-2024-3574/python-scrapy: buster postponed

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6ba50baa by Sylvain Beucler at 2024-05-03T17:43:06+02:00 CVE-2024-3572,CVE-2024-3574/python-scrapy: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-32039, CVE-2024-32040, CVE-2024-32041, CVE-2024-32458, CVE-2024-32459, CVE...

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 058e502a by Sylvain Beucler at 2024-05-03T15:09:09+02:00 CVE-2024-32039,CVE-2024-32040,CVE-2024-32041,CVE-2024-32458,CVE-2024-32459,CVE-2024-32460/freerdp*: reference patches - - - - - 32ef1278

[Git][security-tracker-team/security-tracker][master] CVE-2023-26793/libmodbus: buster postponed

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 569f7b20 by Sylvain Beucler at 2024-05-03T12:00:52+02:00 CVE-2023-26793/libmodbus: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-4140/libemail-mime-perl: buster postponed

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 00651f20 by Sylvain Beucler at 2024-05-03T11:06:51+02:00 CVE-2024-4140/libemail-mime-perl: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-34088/frr: buster not-affected + introductory commit

2024-05-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d9c936a4 by Sylvain Beucler at 2024-05-03T10:42:12+02:00 CVE-2024-34088/frr: buster not-affected + introductory commit - - - - - 1 changed file: - data/CVE/list Changes

Debian LTS and ELTS - April 2024

2024-05-02 Thread Sylvain Beucler
- Help with handling package / understand triage: https://lists.debian.org/debian-lts/2024/04/msg00014.html https://lists.debian.org/debian-lts/2024/04/msg00015.html - Jitsi meeting Also took notes: https://lists.debian.org/debian-lts/2024/04/msg00113.html -- Sylvain Beucler Debian LTS

[Git][security-tracker-team/security-tracker][master] dla: claim firmware-nonfree for tobi who claimed elts uploads

2024-05-02 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f9f34c9 by Sylvain Beucler at 2024-05-02T15:56:33+02:00 dla: claim firmware-nonfree for tobi who claimed elts uploads - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] dla: add firmware-nonfree + fix triage

2024-05-02 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 127467c1 by Sylvain Beucler at 2024-05-02T15:54:27+02:00 dla: add firmware-nonfree + fix triage - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] dla: add intel-microcode and attribute to tobi who claimed elts uploads

2024-05-02 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 07b3d895 by Sylvain Beucler at 2024-05-02T15:47:14+02:00 dla: add intel-microcode and attribute to tobi who claimed elts uploads - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-XXXX/ngircd: buster postponed

2024-04-30 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ea3b4831 by Sylvain Beucler at 2024-04-30T16:11:19+02:00 CVE-2024-/ngircd: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2023-6597/python: reference introductory commit

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8267dca4 by Sylvain Beucler at 2024-04-29T23:10:41+02:00 CVE-2023-6597/python: reference introductory commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-31031/libcoap: buster not-affected + UB-related commits

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9f4efcf2 by Sylvain Beucler at 2024-04-29T22:40:40+02:00 CVE-2024-31031/libcoap: buster not-affected + UB-related commits - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] samba/buster: tidy remaining CVEs

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c9168180 by Sylvain Beucler at 2024-04-29T12:29:15+02:00 samba/buster: tidy remaining CVEs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] CVE-2023-45288/golang-1.11: buster postponed

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f3c929e by Sylvain Beucler at 2024-04-29T11:59:52+02:00 CVE-2023-45288/golang-1.11: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-30202,CVE-2024-30203/emacs,org-mode: precise commit versions

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: ac058e87 by Sylvain Beucler at 2024-04-29T11:30:17+02:00 CVE-2024-30202,CVE-2024-30203/emacs,org-mode: precise commit versions - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-30202/emacs,org-mode: precise commit versions

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d28a91c3 by Sylvain Beucler at 2024-04-29T11:26:53+02:00 CVE-2024-30202/emacs,org-mode: precise commit versions - - - - - 14f3d07e by Sylvain Beucler at 2024-04-29T11:26:53+02:00 CVE-2024-30205

[Git][security-tracker-team/security-tracker][master] CVE-2023-51794/qemu: buster postponed

2024-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bde8f63a by Sylvain Beucler at 2024-04-29T10:24:33+02:00 CVE-2023-51794/qemu: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: clarify nss status a little

2024-04-17 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a39bd63c by Sylvain Beucler at 2024-04-17T18:46:24+02:00 dla: clarify nss status a little - - - - - 1 changed file: - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: reference freeimage discussion

2024-04-10 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 93fc6fbe by Sylvain Beucler at 2024-04-10T19:33:00+02:00 dla: reference freeimage discussion - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Drop obsolete LTS package info from packages/

2024-04-08 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 856a542b by Sylvain Beucler at 2024-04-08T17:15:58+02:00 Drop obsolete LTS package info from packages/ Cf. https://lts-team.pages.debian.net/wiki/TestSuites.html for updated info. - - - - - 2

Re: How to handle freeimage package

2024-04-08 Thread Sylvain Beucler
Hi, I think this requires a bit of coordination: - the package is basically dead upstream, there hasn't been a fix in the official repos, neither Debian or other distros attempted to fix them - we do have a sponsor for LTS and ELTS/stretch, so we're paid to take care of this package - secteam

Re: Remove runc from dla-needed

2024-04-08 Thread Sylvain Beucler
Hi, Please read the dla-needed.txt entry. It says we should sync *bullseye*. Cheers! Sylvain On 07/04/2024 23:47, Ola Lundqvist wrote: Hi fellow LTS contributors I was about to assign runc to myself but realized that it should not be in dla-needed. There is just one CVE to be fixed and that

Debian LTS and ELTS - March 2024

2024-04-02 Thread Sylvain Beucler
com - Update upcoming ELA documentation rdeps status updated ~every hour Fix missing dcut suite (internal) - IRC meeting -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3765-1] cacti security update

2024-03-18 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3765-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler March 18, 2024

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3765-1 for cacti

2024-03-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d8aeddc1 by Sylvain Beucler at 2024-03-18T18:46:31+01:00 Reserve DLA-3765-1 for cacti - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-18 Thread Sylvain Beucler
Hi, On 17/03/2024 06:54, Sean Whitton wrote: On Thu 14 Mar 2024 at 04:47pm -04, Roberto C. Sánchez wrote: - it is important update the notes on packages in dla-needed.txt to indicate what work has been done and what remains I think that we should be also reviewing old notes and deleting

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-16 Thread Sylvain Beucler
a/freexian/services/deblts/lts/git' is not a git working directory => fix this first in your ~/.config/freexian.ini :) Cheers! Sylvain Beucler Debian LTS Team

[Git][security-tracker-team/security-tracker][master] CVE-2023-27043/python*: sync with stable triage

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8d1975f9 by Sylvain Beucler at 2024-03-16T19:28:53+01:00 CVE-2023-27043/python*: sync with stable triage - - - - - 1 changed file: - data/CVE/list Changes

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-16 Thread Sylvain Beucler
Hi, On 14/03/2024 21:47, Roberto C. Sánchez wrote: - FD should be confirming that package removals from dla-needed.txt are valid (i.e., that the package does not require any work towards an upload to (old)stable) Phrased that way, I don't really like the idea of FD checking on his

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-26540/cimg: buster postponed, reference patch

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8cea774f by Sylvain Beucler at 2024-03-16T13:36:03+01:00 CVE-2024-26540/cimg: buster postponed, reference patch - - - - - 246888dc by Sylvain Beucler at 2024-03-16T13:44:52+01:00 CVE-2024-28849

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-2496/libvirt: buster postponed

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 15535e20 by Sylvain Beucler at 2024-03-16T13:00:23+01:00 CVE-2024-2496/libvirt: buster postponed - - - - - 5c76fbe6 by Sylvain Beucler at 2024-03-16T13:09:36+01:00 dla: add libvirt - - - - - 2

[Git][security-tracker-team/security-tracker][master] CVE-2024-2467/libcrypt-openssl-rsa-perl: buster postponed

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 72788521 by Sylvain Beucler at 2024-03-16T12:52:06+01:00 CVE-2024-2467/libcrypt-openssl-rsa-perl: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-28318,CVE-2024-28319/gpac: buster end-of-life

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c12 by Sylvain Beucler at 2024-03-16T12:42:12+01:00 CVE-2024-28318,CVE-2024-28319/gpac: buster end-of-life - - - - - de17954c by Sylvain Beucler at 2024-03-16T12:42:14+01:00 intel-microcode

[Git][security-tracker-team/security-tracker][master] dla: reference DSA 5632-1/composer

2024-03-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: dc8d397b by Sylvain Beucler at 2024-03-15T13:41:42+01:00 dla: reference DSA 5632-1/composer - - - - - 1 changed file: - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2024-28054/amavisd-new: buster postponed

2024-03-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: bb96c54f by Sylvain Beucler at 2024-03-15T12:53:53+01:00 CVE-2024-28054/amavisd-new: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-15 Thread Sylvain Beucler
Hi, I add here a reminder to use './find-work' (as documented, including at the top of dla-needed.txt) to look for work _sorted by priority_. I triaged a few low, non-sponsored, harmonize-with-point-updates packages this week, and I'm a bit surprised that some were claimed and even uploaded

[Git][security-tracker-team/security-tracker][master] dla: cacti status update

2024-03-15 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8841ff3b by Sylvain Beucler at 2024-03-15T12:02:46+01:00 dla: cacti status update - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] cacti update in progress

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 178ab9e7 by Sylvain Beucler at 2024-03-14T17:55:37+01:00 cacti update in progress - - - - - 1 changed file: - data/dsa-needed.txt Changes: = data/dsa

[Git][security-tracker-team/security-tracker][master] dla: tidy notes

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8cbf87fb by Sylvain Beucler at 2024-03-14T17:51:03+01:00 dla: tidy notes - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: tidy notes

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8c4e6aba by Sylvain Beucler at 2024-03-14T17:45:04+01:00 dla: tidy notes - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2023-39513/cacti: clarify fixes

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: d55ea526 by Sylvain Beucler at 2024-03-14T16:37:43+01:00 CVE-2023-39513/cacti: clarify fixes - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] dla: confirm drop cinder and python-os-brick

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a278aa25 by Sylvain Beucler at 2024-03-14T12:55:27+01:00 dla: confirm drop cinder and python-os-brick Rationale: - Issue is marked Minor - No particular effort was made to fix CVE-2023-2088

[Git][security-tracker-team/security-tracker][master] Tidy golang* buster triage

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e32da8c by Sylvain Beucler at 2024-03-14T12:34:47+01:00 Tidy golang* buster triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2024-21626/runc: clarify and source buster triage

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 03cc0b97 by Sylvain Beucler at 2024-03-14T12:27:28+01:00 CVE-2024-21626/runc: clarify and source buster triage - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Typo

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e1648a73 by Sylvain Beucler at 2024-03-14T11:02:31+01:00 Typo - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: add unadf

2024-03-14 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 50212642 by Sylvain Beucler at 2024-03-14T10:38:55+01:00 dla: add unadf - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

Re: Removal of sendmail from dla-needed?

2024-03-13 Thread Sylvain Beucler
Hi, For reference, re-added through https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a2a182dc53f0632ecd32108c91c071bdad76289 Cheers! Sylvain Beucler Debian LTS Team On 10/03/2024 23:18, Ola Lundqvist wrote: Hi all Since I'm not 100% sure about this one I'm sending

Re: Question about tinymce dsa/no-dsa decisions

2024-03-13 Thread Sylvain Beucler
Hi Ola, On 12/03/2024 20:52, Ola Lundqvist wrote: I have claimed the package myself now. I think the conclusion will be that all are minor issues and the package do not need an update. But we will see when I have gone through all the CVEs. tinymce is only available up to buster, so we don't

[Git][security-tracker-team/security-tracker][master] CVE-2023-46586/weborf: buster no-dsa -> not-affected

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b670457 by Sylvain Beucler at 2024-03-13T19:31:37+01:00 CVE-2023-46586/weborf: buster no-dsa - not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] dla: add node-xml2js

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 20855786 by Sylvain Beucler at 2024-03-13T19:26:21+01:00 dla: add node-xml2js - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] dla: add spip

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e4597ae by Sylvain Beucler at 2024-03-13T19:05:38+01:00 dla: add spip - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-2314/bpfcc: buster not-affected

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c29b571 by Sylvain Beucler at 2024-03-13T18:43:37+01:00 CVE-2024-2314/bpfcc: buster not-affected - - - - - e2f4acec by Sylvain Beucler at 2024-03-13T18:50:56+01:00 CVE-2024-2313/bpftrace: buster

[Git][security-tracker-team/security-tracker][master] CVE-2021-42343/dask.distributed: precise buster triage

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a80cc6f0 by Sylvain Beucler at 2024-03-13T18:26:26+01:00 CVE-2021-42343/dask.distributed: precise buster triage ignored since guilhem reviewed and explicitly dropped the entry

[Git][security-tracker-team/security-tracker][master] CVE-2024-1441/libvirt: buster postponed

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 70d498bd by Sylvain Beucler at 2024-03-13T17:54:27+01:00 CVE-2024-1441/libvirt: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: fix syntax

2024-03-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fa253efd by Sylvain Beucler at 2024-03-13T16:11:06+01:00 dla: fix syntax - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] dla: update edk2 status

2024-03-12 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 010b3dfb by Sylvain Beucler at 2024-03-12T09:04:44+01:00 dla: update edk2 status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Revert "Removed sendmail from dla-needed since there is no CVE marked as need...

2024-03-11 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9a2a182d by Sylvain Beucler at 2024-03-11T12:07:53+01:00 Revert Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster. This reverts commit

[Git][security-tracker-team/security-tracker][master] CVE-2023-6110/python-openstackclient: buster no-dsa -> not-affected

2024-03-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2dd2e31c by Sylvain Beucler at 2024-03-07T10:59:39+01:00 CVE-2023-6110/python-openstackclient: buster no-dsa - not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-25126/ruby-rack: reference upstream patch

2024-03-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 039bf355 by Sylvain Beucler at 2024-03-07T10:24:23+01:00 CVE-2024-25126/ruby-rack: reference upstream patch - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-22201/jetty9: precision

2024-03-07 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: cfbf8d9d by Sylvain Beucler at 2024-03-07T09:44:05+01:00 CVE-2024-22201/jetty9: precision - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] Fix tab

2024-03-02 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f752d354 by Sylvain Beucler at 2024-03-02T11:35:19+01:00 Fix tab - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

Debian LTS and ELTS - February 2024

2024-03-01 Thread Sylvain Beucler
with freexian administrative tooling and help test - Documentation - (internal) improves notes on reproducing ELTS autopkgtest setup locally - TestSuites: improves python3 notes https://lts-team.pages.debian.net/wiki/TestSuites/python3.html - Jitsi meeting -- Sylvain Beucler Debian LTS

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-02-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f1d7559b by Sylvain Beucler at 2024-02-27T13:04:30+01:00 dla: update cacti status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-49084/cacti: follow-up patch + mitigation note

2024-02-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a8640782 by Sylvain Beucler at 2024-02-27T11:42:15+01:00 CVE-2023-49084/cacti: follow-up patch + mitigation note - - - - - 8d95dc5b by Sylvain Beucler at 2024-02-27T11:43:48+01:00 CVE-2023-49085

[Git][security-tracker-team/security-tracker][master] CVE-2023-39362/cacti: note limitations

2024-02-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 37ae384b by Sylvain Beucler at 2024-02-26T20:59:28+01:00 CVE-2023-39362/cacti: note limitations - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: eda6d880 by Sylvain Beucler at 2024-02-22T23:23:58+01:00 dla: update cacti status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2023-39360/cacti: precise note again

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 79e1fa5a by Sylvain Beucler at 2024-02-22T18:26:28+01:00 CVE-2023-39360/cacti: precise note again - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2023-49088,CVE-2023-50250/cacti: another follow-up commit

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0470d1be by Sylvain Beucler at 2024-02-22T18:00:36+01:00 CVE-2023-49088,CVE-2023-50250/cacti: another follow-up commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2023-49088/cacti: reference additional patches

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 296cb887 by Sylvain Beucler at 2024-02-22T17:39:49+01:00 CVE-2023-49088/cacti: reference additional patches Despite the reference to CVE-2023-49088 in 56f9d99e6e5ab434ea18fa344236f41e78f99c59

[Git][security-tracker-team/security-tracker][master] CVE-2023-39360/cacti: precise note

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 56b966d9 by Sylvain Beucler at 2024-02-22T12:36:19+01:00 CVE-2023-39360/cacti: precise note - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] CVE-2023-39361/cacti: reference complementary fix

2024-02-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0293e780 by Sylvain Beucler at 2024-02-21T19:14:50+01:00 CVE-2023-39361/cacti: reference complementary fix - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2023-39361/cacti: reference introductory commit

2024-02-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e56496d by Sylvain Beucler at 2024-02-21T19:09:14+01:00 CVE-2023-39361/cacti: reference introductory commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2023-39360/cacti: wrong patch, bookworm still vulnerable

2024-02-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 902dd979 by Sylvain Beucler at 2024-02-21T18:26:16+01:00 CVE-2023-39360/cacti: wrong patch, bookworm still vulnerable Follow-up to c3cae9377156c963d7b475fda3a82413188d8446 - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] CVE-2023-39359/cacti: buster actually not-affected

2024-02-21 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 3cad43f5 by Sylvain Beucler at 2024-02-21T17:02:59+01:00 CVE-2023-39359/cacti: buster actually not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 6 commits: CVE-2023-49085/cacti: reference patch

2024-02-20 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 40e4289c by Sylvain Beucler at 2024-02-20T13:18:40+01:00 CVE-2023-49085/cacti: reference patch - - - - - 76b9bb2f by Sylvain Beucler at 2024-02-20T13:18:42+01:00 CVE-2023-49084/cacti: fix patch

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-02-19 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 23fa34c5 by Sylvain Beucler at 2024-02-19T11:22:35+01:00 dla: update cacti status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2023-49086/cacti: fix patch

2024-02-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 02a813f5 by Sylvain Beucler at 2024-02-03T12:51:45+01:00 CVE-2023-49086/cacti: fix patch - - - - - d4bc509a by Sylvain Beucler at 2024-02-03T12:51:47+01:00 CVE-2023-49088/cacti: reference patch

Debian LTS and ELTS - January 2024

2024-02-01 Thread Sylvain Beucler
freerdp tests https://lts-team.pages.debian.net/wiki/TestSuites/freerdp.html - Ping lts-coordinator about issues with Front-Desk reminder template -- Sylvain Beucler Debian LTS Team

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-01-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f8b9b7f8 by Sylvain Beucler at 2024-01-31T22:10:37+01:00 dla: update cacti status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 2 commits: mathtex: follow bullseye triage for buster

2024-01-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 4f29a01e by Sylvain Beucler at 2024-01-27T16:14:19+01:00 mathtex: follow bullseye triage for buster - - - - - cc3aee24 by Sylvain Beucler at 2024-01-27T16:27:31+01:00 mbedtls: follow bullseye

[Git][security-tracker-team/security-tracker][master] CVE-2023-52355,CVE-2023-52356/tiff: buster postponed

2024-01-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0bccd6ab by Sylvain Beucler at 2024-01-27T16:04:25+01:00 CVE-2023-52355,CVE-2023-52356/tiff: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-0444/gst-plugins-bad1.0: buster not-affected

2024-01-27 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a804687d by Sylvain Beucler at 2024-01-27T15:35:17+01:00 CVE-2024-0444/gst-plugins-bad1.0: buster not-affected - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-22725/orthanc: buster postponed

2024-01-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a0ebe7d7 by Sylvain Beucler at 2024-01-26T21:03:47+01:00 CVE-2024-22725/orthanc: buster postponed - - - - - 34dafc5c by Sylvain Beucler at 2024-01-26T21:03:47+01:00 ela: update salt status

[Git][security-tracker-team/security-tracker][master] CVE-2024-0914/opencryptoki: buster postponed

2024-01-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9599d1bd by Sylvain Beucler at 2024-01-26T20:47:57+01:00 CVE-2024-0914/opencryptoki: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2024-22636/pluxml: buster end-of-life

2024-01-26 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: dd3564ae by Sylvain Beucler at 2024-01-26T13:31:37+01:00 CVE-2024-22636/pluxml: buster end-of-life - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2024-22749/gpac: buster end-of-life

2024-01-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: eca6e58b by Sylvain Beucler at 2024-01-25T22:55:18+01:00 CVE-2024-22749/gpac: buster end-of-life - - - - - 3b1c9bfe by Sylvain Beucler at 2024-01-25T22:55:19+01:00 CVE-2023-52354/chasquid: buster

[Git][security-tracker-team/security-tracker][master] dla: tidy golang triage

2024-01-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e6e7c86 by Sylvain Beucler at 2024-01-25T22:20:28+01:00 dla: tidy golang triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2024-0727/openssl: buster postponed

2024-01-25 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e12e02b1 by Sylvain Beucler at 2024-01-25T21:38:28+01:00 CVE-2024-0727/openssl: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2023-4969/firmware-nonfree: buster postponed

2024-01-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 006a456c by Sylvain Beucler at 2024-01-24T13:33:46+01:00 CVE-2023-4969/firmware-nonfree: buster postponed - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2023-6693/qemu: buster not-affected

2024-01-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 67c1cf09 by Sylvain Beucler at 2024-01-24T12:40:17+01:00 CVE-2023-6693/qemu: buster not-affected - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-01-23 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: cafee77e by Sylvain Beucler at 2024-01-23T12:02:00+01:00 dla: update cacti status - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] dla: add gnutls28

2024-01-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f0c93d91 by Sylvain Beucler at 2024-01-22T14:26:01+01:00 dla: add gnutls28 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2023-51448/cacti: harmonize buster triage

2024-01-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: afb820f5 by Sylvain Beucler at 2024-01-18T20:07:11+01:00 CVE-2023-51448/cacti: harmonize buster triage - - - - - 1 changed file: - data/CVE/list Changes

  1   2   3   4   5   6   7   8   9   10   >