[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-31778 as ignored for buster

2022-10-31 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: 19db2921 by Abhijith PA at 2022-11-01T11:19:16+05:30 Mark CVE-2022-31778 as ignored for buster - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Fix dla-needed after git conflicts

2022-10-31 Thread Anton Gladky (@gladk)
-needed.txt = @@ -100,11 +100,13 @@ ini4j jackson-databind NOTE: 20221030: Programming language: Java. -- +jhead NOTE: 20221031: Programming language: C. NOTE: 20221031: Note that multiple options are vulnerable. The attacker have to trick someone

[Git][security-tracker-team/security-tracker][master] Mark pysha3 as removed from unstable

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a9ec9555 by Salvatore Bonaccorso at 2022-11-01T06:17:51+01:00 Mark pysha3 as removed from unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Add ntfs-3g to dsa-needed list

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e30faf70 by Salvatore Bonaccorso at 2022-10-31T22:29:41+01:00 Add ntfs-3g to dsa-needed list - - - - - 23c08961 by Salvatore Bonaccorso at 2022-10-31T22:30:14+01:00 Take ntfs-3g from

[Git][security-tracker-team/security-tracker][master] CVE-2022-31008/rabbitmq-server: references patches reducing the affected versions range

2022-10-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0076ed8e by Sylvain Beucler at 2022-10-31T22:23:20+01:00 CVE-2022-31008/rabbitmq-server: references patches reducing the affected versions range not triaging, letting LTS front-desk and/or

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 45d0f666 by Salvatore Bonaccorso at 2022-10-31T21:29:40+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process several NFUs

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b75a1cff by Salvatore Bonaccorso at 2022-10-31T21:20:06+01:00 Process several NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Added ceph to dla-needed. Do not have good enough experience with ceph to...

2022-10-31 Thread Ola Lundqvist (@opal)
: 20221018: https://lists.debian.org/debian-lts/2022/10/msg00037.html -- +ceph + NOTE: 20221031: Programming language: C++. + NOTE: 20221031: To be checked further. Not clear whether the vulnerability can be exploited in a Debian system. + NOTE: 20221031: What should be checked is whether any user

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 12a48cc6 by security tracker role at 2022-10-31T20:10:17+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Marked CVE-2022-42920 for node-minimatch as no-dsa for buster following decision for bullseye.

2022-10-31 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c6923bf by Ola Lundqvist at 2022-10-31T20:49:44+01:00 Marked CVE-2022-42920 for node-minimatch as no-dsa for buster following decision for bullseye. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Added ntfs-3g to dla-needed.

2022-10-31 Thread Ola Lundqvist (@opal)
-needed.txt = @@ -153,6 +153,10 @@ node-css-what node-tar NOTE: 20220907: Programming language: JavaScript. -- +ntfs-3g + NOTE: 20221031: Programming language: C. + NOTE: 20221031: VCS: https://salsa.debian.org/lts-team/packages/ntfs-3g.git +-- openexr NOTE

[Git][security-tracker-team/security-tracker][master] Track fixed version for libxml2 issues via unstable

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e852f8e0 by Salvatore Bonaccorso at 2022-10-31T19:29:49+01:00 Track fixed version for libxml2 issues via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-40284/ntfs-3g via unstable

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ab74f9d7 by Salvatore Bonaccorso at 2022-10-31T19:28:21+01:00 Track fixed version for CVE-2022-40284/ntfs-3g via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track upstream commits for CVE-2022-40284/ntfs-3g

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 47b9536d by Salvatore Bonaccorso at 2022-10-31T19:25:40+01:00 Track upstream commits for CVE-2022-40284/ntfs-3g - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity

2022-10-31 Thread Anton Gladky (@gladk)
-needed.txt Changes: = data/dla-needed.txt = @@ -83,7 +83,7 @@ hsqldb NOTE: 20221031: To be investigated further. A possible outcome is to ignore it. NOTE: 20221031: https://lists.debian.org/debian-lts/2022/10/msg00060.html

[Git][security-tracker-team/security-tracker][master] Remove two check items for CVE-2022-3168 and CVE-2022-20128

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fd693cb3 by Salvatore Bonaccorso at 2022-10-31T19:21:26+01:00 Remove two check items for CVE-2022-3168 and CVE-2022-20128 Entries looks correct with temporary tracking of fixed version in

[Git][security-tracker-team/security-tracker][master] CVE-2022-3276/puppet-module-puppetlabs-mysql: reference commits following upstream confirmation

2022-10-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9fd20b1f by Sylvain Beucler at 2022-10-31T16:36:30+01:00 CVE-2022-3276/puppet-module-puppetlabs-mysql: reference commits following upstream confirmation - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Added php7.3 to dla-needed.

2022-10-31 Thread Ola Lundqvist (@opal)
+ NOTE: 20221031: Programming language: C. + NOTE: 20221031: CVE-2022-37454 is what is of most concern. +-- phpseclib NOTE: 20220909: Programming language: PHP. NOTE: 20220909: Note the discussion whether 2.0 is in fact affected by the CVE or not. It looks like it is affected by a small

[Git][security-tracker-team/security-tracker][master] Triaged python-cmarkgfm for LTS (buster) and concluded CVE-2022-24724 and...

2022-10-31 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: b8c1e028 by Ola Lundqvist at 2022-10-31T15:51:43+01:00 Triaged python-cmarkgfm for LTS (buster) and concluded CVE-2022-24724 and CVE-2022-39209 to be minor issues. Same conclusion as cmark-gfm. - -

[Git][security-tracker-team/security-tracker][master] CVE-2022-20128,CVE-2022-3168/android-platform-tools (adb): reference public disclosure

2022-10-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 35eb7223 by Sylvain Beucler at 2022-10-31T15:29:27+01:00 CVE-2022-20128,CVE-2022-3168/android-platform-tools (adb): reference public disclosure - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-40284/ntfs-3g

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ec4db72 by Salvatore Bonaccorso at 2022-10-31T15:12:33+01:00 Add CVE-2022-40284/ntfs-3g - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added libapreq2 to dla-needed. Webserver crash is not a good thing so it should be solved.

2022-10-31 Thread Ola Lundqvist (@opal)
Changes: = data/dla-needed.txt = @@ -110,6 +110,9 @@ kopanocore lava NOTE: 20221031: Programming language: Python. -- +libapreq2 + NOTE: 20221031: Programming language: C. +-- libcommons-jxpath-java NOTE: 20221027

[Git][security-tracker-team/security-tracker][master] Added rabbitmq-server to dla-needed. It should be checked further since the...

2022-10-31 Thread Ola Lundqvist (@opal)
+ NOTE: 20221031: Programming language: Erlang. + NOTE: 20221031: New configuration option. Should be studied further.. + NOTE: 20221031: Potentially the outcome is to ignore the issue.. +-- rails (Abhijith PA) NOTE: 20220909: Regression on 2:5.2.2.1+dfsg-1+deb10u4 (abhijith) NOTE: 20220909

[Git][security-tracker-team/security-tracker][master] 2 commits: Added hsqldb to dla-needed for further investigation. It is possibly a...

2022-10-31 Thread Ola Lundqvist (@opal)
: = data/dla-needed.txt = @@ -78,6 +78,11 @@ golang-websocket graphicsmagick NOTE: 20221027: Programming language: C. -- +hsqldb + NOTE: 20221031: Programming language: Java. + NOTE: 20221031: To be investigated further. A possible outcome

[Git][security-tracker-team/security-tracker][master] CVE-2022-37454/php*: introduced in 7.2

2022-10-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 38f016b3 by Sylvain Beucler at 2022-10-31T14:18:51+01:00 CVE-2022-37454/php*: introduced in 7.2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2022-41853,hsqldb: Link to possible fixing commit

2022-10-31 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: fabc7c5a by Markus Koschany at 2022-10-31T13:36:30+01:00 CVE-2022-41853,hsqldb: Link to possible fixing commit - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 3 commits: Triaged cmark-gfm for LTS (buster) and concluded CVE-2022-24724 and...

2022-10-31 Thread Ola Lundqvist (@opal)
: Please evaluate, whether it can be applied. -- +consul + NOTE: 20221031: Programming language: Go. + NOTE: 20221031: Concluded that the package should be fixed by the CVE description. Source code not analyzed in detail. +-- curl (Emilio) NOTE: 20220901: Programming language: C. NOTE

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3174-1 for pysha3

2022-10-31 Thread Stefano Rivera (@stefanor)
+154,6 @@ pluxml NOTE: 20220913: Programming language: PHP. NOTE: 20220913: Special attention: orphaned package. -- -pysha3 (Stefano Rivera) - NOTE: 20221031: Programming language: Python. - NOTE: 20221031: Special attention: urgent. --- python3.7 (Stefano Rivera) NOTE: 20221031

[Git][security-tracker-team/security-tracker][master] CVE-2022-37454/python3*: introduced in 3.6

2022-10-31 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 380c2080 by Sylvain Beucler at 2022-10-31T11:10:29+01:00 CVE-2022-37454/python3*: introduced in 3.6 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Clarify pypy3.6 in history

2022-10-31 Thread Stefano Rivera (@stefanor)
Stefano Rivera pushed to branch master at Debian Security Tracker / security-tracker Commits: 08647d86 by Stefano Rivera at 2022-10-31T11:30:16+02:00 Clarify pypy3.6 in history - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: Claim pysha3

2022-10-31 Thread Stefano Rivera (@stefanor)
(Stefano Rivera) NOTE: 20221031: Programming language: Python. NOTE: 20221031: Special attention: urgent. -- +python3.7 (Stefano Rivera) + NOTE: 20221031: Programming language: C. + NOTE: 20221031: Special attention: urgent. +-- python-django NOTE: 20221031: Programming language: Python

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ee0cb88 by Salvatore Bonaccorso at 2022-10-31T10:17:22+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b0513b34 by security tracker role at 2022-10-31T08:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3707/linux

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7da36de5 by Salvatore Bonaccorso at 2022-10-31T08:38:53+01:00 Add CVE-2022-3707/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3500 as NFU

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dc139021 by Salvatore Bonaccorso at 2022-10-31T08:29:23+01:00 Add CVE-2022-3500 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1415 as NFU

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d8f21266 by Salvatore Bonaccorso at 2022-10-31T08:28:30+01:00 Add CVE-2022-1415 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-3705/vim

2022-10-31 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a078ad85 by Salvatore Bonaccorso at 2022-10-31T08:06:51+01:00 Track fixed version for CVE-2022-3705/vim - - - - - 1 changed file: - data/CVE/list Changes: