[Git][security-tracker-team/security-tracker][master] freecad DSA

2022-09-13 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 291553f3 by Moritz Mühlenhoff at 2022-09-13T22:51:22+02:00 freecad DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3029/routinator

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ec7bf776 by Salvatore Bonaccorso at 2022-09-13T22:48:56+02:00 Add CVE-2022-3029/routinator - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add new rdiffweb issues, itp'ed

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 65608374 by Salvatore Bonaccorso at 2022-09-13T22:34:40+02:00 Add new rdiffweb issues, itped - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3190/wireshark

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bcbde15f by Salvatore Bonaccorso at 2022-09-13T22:34:04+02:00 Add CVE-2022-3190/wireshark - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process several NFUs

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 76408d33 by Salvatore Bonaccorso at 2022-09-13T22:32:49+02:00 Process several NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-36087

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2cb6fa5c by Salvatore Bonaccorso at 2022-09-13T22:25:47+02:00 Add Debian bug reference for CVE-2022-36087 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-4064{7,8}/man2html

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a1d2c75 by Salvatore Bonaccorso at 2022-09-13T22:24:41+02:00 Add CVE-2021-4064{7,8}/man2html - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dda70817 by Salvatore Bonaccorso at 2022-09-13T22:16:57+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 019fee87 by security tracker role at 2022-09-13T20:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process two more NFUs

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c3de84fe by Salvatore Bonaccorso at 2022-09-13T21:29:21+02:00 Process two more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-37300 as NFU

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3435fee2 by Salvatore Bonaccorso at 2022-09-13T21:26:22+02:00 Mark CVE-2022-37300 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-37734 as NFU

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 19105702 by Salvatore Bonaccorso at 2022-09-13T21:23:59+02:00 Mark CVE-2022-37734 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-39200 as NFU

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d8532d3 by Salvatore Bonaccorso at 2022-09-13T21:20:29+02:00 Mark CVE-2022-39200 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream tag reference for CVE-2022-38266

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9136d6c0 by Salvatore Bonaccorso at 2022-09-13T20:54:43+02:00 Add upstream tag reference for CVE-2022-38266 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Record upstream commit for CVE-2020-14394/qemu

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fadb3f00 by Salvatore Bonaccorso at 2022-09-13T20:45:48+02:00 Record upstream commit for CVE-2020-14394/qemu - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2020-14394/qemu

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d53db595 by Salvatore Bonaccorso at 2022-09-13T20:44:52+02:00 Track fixed version via unstable for CVE-2020-14394/qemu - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for two qemu issues in 1:7.1+dfsg-2

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ff5ec504 by Salvatore Bonaccorso at 2022-09-13T20:43:27+02:00 Track fixed version for two qemu issues in 1:7.1+dfsg-2 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: add notes for rainloop

2022-09-13 Thread Sylvain Beucler (@beuc)
-needed.txt = @@ -149,6 +149,10 @@ rails (Abhijith PA) rainloop NOTE: 20220913: Programming language: PHP, JavaScript. NOTE: 20220913: Special attention: orphaned as of 2022-09. + NOTE: 20220913: Upstream appeared dead but there was activity 2 weeks ago

[Git][security-tracker-team/security-tracker][master] dla: add rainloop

2022-09-13 Thread Sylvain Beucler (@beuc)
= @@ -146,6 +146,10 @@ rails (Abhijith PA) NOTE: 20220909: https://lists.debian.org/debian-lts/2022/09/msg4.html (abhijith) NOTE: 20220909: upstream report https://github.com/rails/rails/issues/45590 (abhijith) -- +rainloop + NOTE: 20220913

[Git][security-tracker-team/security-tracker][master] dla: add dovecot

2022-09-13 Thread Sylvain Beucler (@beuc)
= @@ -27,6 +27,11 @@ curl NOTE: 20220904: VCS: https://salsa.debian.org/lts-team/packages/curl.git NOTE: 20220904: Special attention: high popcon!. -- +dovecot + NOTE: 20220913: Programming language: C. + NOTE: 20220913: VCS: https://salsa.debian.org/lts

[Git][security-tracker-team/security-tracker][master] CVE-2021-33193/apache2: link patches from distros with close versions

2022-09-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: e0e1200b by Sylvain Beucler at 2022-09-13T17:56:32+02:00 CVE-2021-33193/apache2: link patches from distros with close versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3107-1 for sqlite3

2022-09-13 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: bc7b3c1c by Chris Lamb at 2022-09-13T15:19:13+01:00 Reserve DLA-3107-1 for sqlite3 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3106-1 for python-oslo.utils

2022-09-13 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 93b84abf by Chris Lamb at 2022-09-13T14:13:36+01:00 Reserve DLA-3106-1 for python-oslo.utils - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2022-09-13 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 8fb35876 by Moritz Muehlenhoff at 2022-09-13T13:31:01+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new leptonlib issue

2022-09-13 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 96ad99b3 by Moritz Muehlenhoff at 2022-09-13T13:17:59+02:00 new leptonlib issue NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] lts: take glib2.0

2022-09-13 Thread Emilio Pozuelo Monfort (@pochu)
/dla-needed.txt = @@ -39,7 +39,7 @@ gdal (Utkarsh) NOTE: 20220913: Upcoming DSA (Beuc/front-desk) NOTE: 20220913: 2 CVEs already fixed in stretch (Beuc/front-desk) -- -glib2.0 +glib2.0 (Emilio) NOTE: 20220901: Programming language: C. NOTE: 20220901

[Git][security-tracker-team/security-tracker][master] dla: add glibc

2022-09-13 Thread Sylvain Beucler (@beuc)
= @@ -43,6 +43,10 @@ glib2.0 NOTE: 20220901: Programming language: C. NOTE: 20220901: Special attention: High Popcon!. -- +glibc + NOTE: 20220913: Programming language: C, Assembly. + NOTE: 20220913: Harmonize with bullseye: 4 CVEs fixed in Debian 11.3

[Git][security-tracker-team/security-tracker][master] 2 commits: dla: add pluxml

2022-09-13 Thread Sylvain Beucler (@beuc)
= @@ -119,6 +119,10 @@ phpseclib NOTE: 20220909: Programming language: PHP. NOTE: 20220909: Note the discussion whether 2.0 is in fact affected by the CVE or not. It looks like it is affected by a small part of it that is best to fix.. -- +pluxml + NOTE: 20220913: Programming

[Git][security-tracker-team/security-tracker][master] ruby-mechanize fixed in sid

2022-09-13 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c1b25054 by Moritz Muehlenhoff at 2022-09-13T10:51:57+02:00 ruby-mechanize fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Take packages

2022-09-13 Thread Utkarsh Gupta (@utkarsh)
= @@ -34,7 +34,7 @@ exiv2 firmware-nonfree NOTE: 20220906: Consider to check the severity of the issues again and judge whether a correction is worth it. -- -gdal +gdal (Utkarsh) NOTE: 20220913: Programming language: C/C++, Python. NOTE: 20220913: Upcoming DSA

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bdee6244 by Salvatore Bonaccorso at 2022-09-13T10:32:30+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: add gdal

2022-09-13 Thread Sylvain Beucler (@beuc)
= @@ -34,6 +34,11 @@ exiv2 firmware-nonfree NOTE: 20220906: Consider to check the severity of the issues again and judge whether a correction is worth it. -- +gdal + NOTE: 20220913: Programming language: C/C++, Python. + NOTE: 20220913: Upcoming DSA (Beuc/front

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3105-1 for connman

2022-09-13 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d8b843c by Chris Lamb at 2022-09-13T09:20:02+01:00 Reserve DLA-3105-1 for connman - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2022-09-13 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 48b5b24a by security tracker role at 2022-09-13T08:10:17+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2022-1705/golang: buster not-affected

2022-09-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: fdaedd28 by Sylvain Beucler at 2022-09-13T09:57:42+02:00 CVE-2022-1705/golang: buster not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] lts: take nova

2022-09-13 Thread Emilio Pozuelo Monfort (@pochu)
: Current branch to package: https://salsa.debian.org/openstack-team/services/nova/-/tree/debian/rocky/nova + NOTE: 20220913: will coordinate with maintainer (pochu) -- openexr NOTE: 20220904: Programming language: C++. View it on GitLab: https://salsa.debian.org/security-tracker-team/security

[Git][security-tracker-team/security-tracker][master] lts: take mariadb-10.3

2022-09-13 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: c3b20911 by Emilio Pozuelo Monfort at 2022-09-13T09:53:21+02:00 lts: take mariadb-10.3 - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2020-10735/python3.7: buster postponed

2022-09-13 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b60bef9d by Sylvain Beucler at 2022-09-13T08:48:32+02:00 CVE-2020-10735/python3.7: buster postponed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reclaim sox

2022-09-13 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c05ffa8 by Abhijith PA at 2022-09-13T11:47:29+05:30 Reclaim sox - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt