[Git][security-tracker-team/security-tracker][master] Track proposed update for postsrsd via buster-pu

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cb103b5a by Salvatore Bonaccorso at 2020-12-21T08:26:22+01:00 Track proposed update for postsrsd via buster-pu - - - - - 1 changed file: - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] Several chromium bugs fixed in unstable

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 441a09e4 by Salvatore Bonaccorso at 2020-12-21T06:48:56+01:00 Several chromium bugs fixed in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2502-1 for postsrsd

2020-12-20 Thread Adrian Bunk
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 597b570a by Adrian Bunk at 2020-12-20T23:11:53+02:00 Reserve DLA-2502-1 for postsrsd - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla: update status

2020-12-20 Thread Adrian Bunk
= @@ -89,6 +89,7 @@ linux-4.19 (Ben Hutchings) -- mariadb-10.1 (Adrian Bunk) NOTE: 20201207: still ongoing (bunk) + NOTE: 20201220: debugging test failure in local build (bunk) -- mediawiki (Roberto C. Sánchez) -- View it on GitLab: https://salsa.debian.org

[Git][security-tracker-team/security-tracker][master] automatic update

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b1ce1c3d by security tracker role at 2020-12-20T20:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: claim postsrsd

2020-12-20 Thread Adrian Bunk
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: c7829741 by Adrian Bunk at 2020-12-20T20:27:17+02:00 dla: claim postsrsd - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] LTS: stretch triage

2020-12-20 Thread Roberto C . Sánchez
. (sunweaver) -- +postsrsd +-- reel NOTE: 20200909: it is now unmaintained. last commit was in Aug 2018. (utkarsh) -- @@ -181,6 +183,11 @@ spip (Abhijith PA) NOTE: Low priority for us. sec team did DSA-4798-1 (abhijith) NOTE: 20201220: package in stretch in unusable. Contacted maintainer

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2020-16093/lemonldap as no-dsa for stretch

2020-12-20 Thread Utkarsh Gupta
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 759da913 by Utkarsh Gupta at 2020-12-20T23:27:51+05:30 Mark CVE-2020-16093/lemonldap as no-dsa for stretch - - - - - 592c0fe2 by Utkarsh Gupta at 2020-12-20T23:28:11+05:30 Drop lemonldap-ng from

[Git][security-tracker-team/security-tracker][master] LTS: reclaim shiro, update notes

2020-12-20 Thread Roberto C . Sánchez
) -- -shiro +shiro (Roberto C. Sánchez) NOTE: 20200920: WIP NOTE: 20200928: Still awaiting reponse to request for assistance sent to upstream dev list. (roberto) NOTE: 20201004: Sent additional request to upstream dev list; stil no response. (roberto) + NOTE: 20201220: Upstream has responded

[Git][security-tracker-team/security-tracker][master] 2 commits: update note for slirp

2020-12-20 Thread Thorsten Alteholz
changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt = @@ -119,6 +119,7 @@ openjdk-8 (Emilio) NOTE: 20201215: regression update (Emilio) -- openjpeg2 (Thorsten Alteholz) + NOTE: 20201220: more CVEs appeared

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2016-7151/capstone

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 56cccb38 by Salvatore Bonaccorso at 2020-12-20T17:40:21+01:00 Track fixed version via unstable for CVE-2016-7151/capstone - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2020-14330/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d682fec6 by Salvatore Bonaccorso at 2020-12-20T17:24:03+01:00 Track fixed version via unstable for CVE-2020-14330/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference to 2.9.y fix for CVE-2020-14330/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1b843282 by Salvatore Bonaccorso at 2020-12-20T17:23:06+01:00 Add reference to 2.9.y fix for CVE-2020-14330/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-14332/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 07195292 by Salvatore Bonaccorso at 2020-12-20T17:18:35+01:00 Track fixed version for CVE-2020-14332/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream commit reference for CVE-2020-14332/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f9059d8 by Salvatore Bonaccorso at 2020-12-20T17:17:09+01:00 Add upstream commit reference for CVE-2020-14332/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-14365/ansible via unstable

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 23827866 by Salvatore Bonaccorso at 2020-12-20T17:14:09+01:00 Track fixed version for CVE-2020-14365/ansible via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track upstream commit for CVE-2020-14365/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0acf3a1f by Salvatore Bonaccorso at 2020-12-20T17:13:16+01:00 Track upstream commit for CVE-2020-14365/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-1736/ansible as unimportant

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 73b003f6 by Salvatore Bonaccorso at 2020-12-20T17:10:26+01:00 Mark CVE-2020-1736/ansible as unimportant Although the isuse valid, it wont be fixed source wise (it was attempted but reverted),

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-1753/ansible via unstable

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 09c00a21 by Salvatore Bonaccorso at 2020-12-20T17:04:45+01:00 Track fixed version for CVE-2020-1753/ansible via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2020-1753/ansible

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 49257f41 by Salvatore Bonaccorso at 2020-12-20T17:04:11+01:00 Update information for CVE-2020-1753/ansible - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2013-7488 as no-dsa

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 549b210a by Salvatore Bonaccorso at 2020-12-20T16:57:17+01:00 Mark CVE-2013-7488 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2013-1841 as no-dsa

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 21b25d5b by Salvatore Bonaccorso at 2020-12-20T16:55:15+01:00 Mark CVE-2013-1841 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reference upstream commit CVE-2020-24344

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 236800bd by Salvatore Bonaccorso at 2020-12-20T16:47:22+01:00 Reference upstream commit CVE-2020-24344 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Two more iotjs issues fixed in unstable with 1.0+715-1 upload

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c627442b by Salvatore Bonaccorso at 2020-12-20T16:42:57+01:00 Two more iotjs issues fixed in unstable with 1.0+715-1 upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream commit for CVE-2020-35545/spotweb

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 176cdba7 by Salvatore Bonaccorso at 2020-12-20T16:38:09+01:00 Reference upstream commit for CVE-2020-35545/spotweb - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2018-1000636/iotjs

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7749ee30 by Salvatore Bonaccorso at 2020-12-20T14:42:52+01:00 Update information for CVE-2018-1000636/iotjs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2018-1141{8,9}/iotjs

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 11bac888 by Salvatore Bonaccorso at 2020-12-20T14:39:00+01:00 Update information for CVE-2018-1141{8,9}/iotjs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2019-1010176/iotjs

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ded8993 by Salvatore Bonaccorso at 2020-12-20T14:34:22+01:00 Track fixed version via unstable for CVE-2019-1010176/iotjs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream commit for CVE-2019-1010176

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: efb85518 by Salvatore Bonaccorso at 2020-12-20T14:33:55+01:00 Reference upstream commit for CVE-2019-1010176 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-0499/flac

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0e2fb985 by Salvatore Bonaccorso at 2020-12-20T14:21:56+01:00 Add Debian bug reference for CVE-2020-0499/flac - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12272

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c1f6a23 by Salvatore Bonaccorso at 2020-12-20T14:21:10+01:00 Add Debian bug reference for CVE-2020-12272 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-20790

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e65481d by Salvatore Bonaccorso at 2020-12-20T14:20:34+01:00 Add Debian bug reference for CVE-2019-20790 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2019-20019/libmatio as no-dsa

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 274edf10 by Salvatore Bonaccorso at 2020-12-20T14:19:05+01:00 Mark CVE-2019-20019/libmatio as no-dsa - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for http-parser via unstable

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 80065d9e by Salvatore Bonaccorso at 2020-12-20T13:37:52+01:00 Track fixed version for http-parser via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add note for spip

2020-12-20 Thread Abhijith PA
= @@ -181,6 +181,7 @@ spice-vdagent (Abhijith PA) -- spip (Abhijith PA) NOTE: Low priority for us. sec team did DSA-4798-1 (abhijith) + NOTE: 20201220: package in stretch in unusable. Contacted maintainer (abhijith) -- wireshark NOTE: 20201007: during last

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim opendmarc

2020-12-20 Thread Abhijith PA
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 44018335 by Abhijith PA at 2020-12-20T15:12:06+05:30 data/dla-needed.txt: claim opendmarc - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2501-1 for influxdb

2020-12-20 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 98238868 by Thorsten Alteholz at 2020-12-20T09:25:39+01:00 Reserve DLA-2501-1 for influxdb - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Correctly associate tag to commit actually

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b1347865 by Salvatore Bonaccorso at 2020-12-20T09:13:45+01:00 Correctly associate tag to commit actually Fixes: 094415fec5f4 (Add CVE-2020-35573/postsrsd) - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] automatic update

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d16fa2fb by security tracker role at 2020-12-20T08:10:14+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-35573/postsrsd

2020-12-20 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 094415fe by Salvatore Bonaccorso at 2020-12-20T09:08:13+01:00 Add CVE-2020-35573/postsrsd - - - - - 1 changed file: - data/CVE/list Changes: =