[Git][security-tracker-team/security-tracker][master] lts: add openssl

2023-02-07 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 809b484b by Emilio Pozuelo Monfort at 2023-02-08T08:53:51+01:00 lts: add openssl - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Track more fixes for ring via unstable upload

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0107bea1 by Salvatore Bonaccorso at 2023-02-08T08:37:32+01:00 Track more fixes for ring via unstable upload Thanks: Amin Bandali - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for chromium issue with unstable upload

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 749eeefb by Salvatore Bonaccorso at 2023-02-08T08:35:46+01:00 Track fixed version for chromium issue with unstable upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-25194/kafka

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7188547c by Salvatore Bonaccorso at 2023-02-08T08:15:50+01:00 Add CVE-2023-25194/kafka - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add oss-security reference for heimdal issue

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6da3c634 by Salvatore Bonaccorso at 2023-02-08T07:54:57+01:00 Add oss-security reference for heimdal issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-45142 /heimdal

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b5c2c414 by Salvatore Bonaccorso at 2023-02-08T07:17:03+01:00 Add CVE-2022-45142 /heimdal - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add chromium to dsa-needed list

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 068f02ba by Salvatore Bonaccorso at 2023-02-08T06:39:15+01:00 Add chromium to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add new chromium issues

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0db0ede3 by Salvatore Bonaccorso at 2023-02-08T06:38:01+01:00 Add new chromium issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: Add VCS to apr-util

2023-02-07 Thread Anton Gladky (@gladk)
= @@ -25,6 +25,7 @@ apache2 (Lee Garrett) -- apr-util (Adrian Bunk) NOTE: 20230207: Programming language: C. + NOTE: 20230208: VCS: https://salsa.debian.org/lts-team/packages/apr-util.git -- asterisk (Lee Garrett) NOTE: 20221211: Programming language: C

[no subject]

2023-02-07 Thread KAMPANAT THUMWONG
___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2012-6655/accountsservice via unstable

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 01ac376e by Salvatore Bonaccorso at 2023-02-07T22:44:45+01:00 Track fixed version for CVE-2012-6655/accountsservice via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for several ring issues via unstable

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c8639746 by Salvatore Bonaccorso at 2023-02-07T22:34:15+01:00 Track fixed version for several ring issues via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update fixed version information for CVE-2023-0430/thunderbird

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2fac8605 by Salvatore Bonaccorso at 2023-02-07T22:25:49+01:00 Update fixed version information for CVE-2023-0430/thunderbird As the maintainer explains: Note: The previous version

[Git][security-tracker-team/security-tracker][master] Track fixed version for three mplayer issues

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3dc42e6a by Salvatore Bonaccorso at 2023-02-07T22:23:33+01:00 Track fixed version for three mplayer issues Note for reviewers: Suspect more CVEs are actually adressed by rebasing to the

[Git][security-tracker-team/security-tracker][master] Track fixed version for openssl issue via unstable

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
] RESERVED - - openssl + - openssl 3.0.8-1 [bullseye] - openssl (Only affects 3.x) [buster] - openssl (Only affects 3.x) NOTE: https://www.openssl.org/news/secadv/20230207.txt @@ -5455,7 +5455,7 @@ CVE-2023-0287 (A vulnerability was found in ityouknow

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-45442/ruby-sinatra

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c1d153d by Salvatore Bonaccorso at 2023-02-07T22:12:19+01:00 Track fixed version for CVE-2022-45442/ruby-sinatra - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for openssl update

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a67896e6 by Salvatore Bonaccorso at 2023-02-07T21:59:11+01:00 Reserve DSA number for openssl update - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c34bb48f by Salvatore Bonaccorso at 2023-02-07T21:46:34+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e391ba1 by security tracker role at 2023-02-07T20:10:22+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-46663/less

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4a862425 by Salvatore Bonaccorso at 2023-02-07T21:08:10+01:00 Add Debian bug reference for CVE-2022-46663/less - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-46663/less

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ccb423ea by Salvatore Bonaccorso at 2023-02-07T20:57:49+01:00 Add CVE-2022-46663/less - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add some commit references for openssl issues

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
/secadv/20230207.txt + NOTE: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=d3b6dfd70db844c4499bec6ad6601623a565e674 (openssl-3.0.8) CVE-2023-0400 (The protection bypass vulnerability in DLP for Windows 11.9.x is addre ...) NOT-FOR-US: DLP for Windows CVE-2023-0399

[Git][security-tracker-team/security-tracker][master] lts: add haproxy

2023-02-07 Thread Emilio Pozuelo Monfort (@pochu)
updates didn't). -- +haproxy + NOTE: 20230207: Programming language: C. + NOTE: 20230207: VCS: https://salsa.debian.org/haproxy-team/haproxy.git + NOTE: 20230207: method was called h2_frt_decode_headers in buster (pochu) +-- heimdal (Helmut Grohne) NOTE: 20230206: Programming language: C

[Git][security-tracker-team/security-tracker][master] new openssl issues

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
: https://www.openssl.org/news/secadv/20230207.txt CVE-2023-0400 (The protection bypass vulnerability in DLP for Windows 11.9.x is addre ...) NOT-FOR-US: DLP for Windows CVE-2023-0399 @@ -5291,8 +5295,10 @@ CVE-2023-0288 (Heap-based Buffer Overflow in GitHub repository vim/vim prior

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for xorg-server update

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 87be81a9 by Salvatore Bonaccorso at 2023-02-07T16:41:45+01:00 Reserve DSA number for xorg-server update - - - - - 1 changed file: - data/DSA/list Changes:

[Git][security-tracker-team/security-tracker][master] DLA: take apr-util

2023-02-07 Thread Adrian Bunk (@bunk)
) NOTE: 20230207: Programming language: C. -- asterisk (Lee Garrett) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/abf18fbb34293e2502adc8833f0b15e51a3ed246 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker

[Git][security-tracker-team/security-tracker][master] also track CVE-2023-0494 for xwayland

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cf0e2236 by Moritz Muehlenhoff at 2023-02-07T15:05:54+01:00 also track CVE-2023-0494 for xwayland - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] xorg-server fixed in sid

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: eaa8cb67 by Moritz Muehlenhoff at 2023-02-07T14:57:22+01:00 xorg-server fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] linux n/a

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 524520bf by Moritz Muehlenhoff at 2023-02-07T14:16:34+01:00 linux n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-24813/php-dompdf

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6eceeeff by Salvatore Bonaccorso at 2023-02-07T14:10:00+01:00 Add CVE-2023-24813/php-dompdf - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-0494/xorg-server

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c19c2cc by Salvatore Bonaccorso at 2023-02-07T14:07:30+01:00 Add Debian bug reference for CVE-2023-0494/xorg-server - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 04f141e6 by Moritz Muehlenhoff at 2023-02-07T13:57:56+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] bullseye triage

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5790e7d1 by Moritz Muehlenhoff at 2023-02-07T13:54:27+01:00 bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: lts: CVE-2022-24963/apr n/a on buster

2023-02-07 Thread Emilio Pozuelo Monfort (@pochu)
: 20230207: Programming language: C. +-- asterisk (Lee Garrett) NOTE: 20221211: Programming language: C. NOTE: 20230111: VCS: https://salsa.debian.org/lts-team/packages/asterisk.git View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-4426{7,8}/imagemagick

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e971252 by Salvatore Bonaccorso at 2023-02-07T13:03:09+01:00 Add CVE-2022-4426{7,8}/imagemagick - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] new issues in rust crates

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b1682292 by Moritz Muehlenhoff at 2023-02-07T11:42:59+01:00 new issues in rust crates - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-02-07 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 7e4fc302 by Moritz Muehlenhoff at 2023-02-07T10:19:54+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 3 commits: Add embedded code copies for tryton-sao.

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 80bdf80b by Mathias Behrle at 2023-02-07T09:23:18+01:00 Add embedded code copies for tryton-sao. - - - - - 3c69b247 by Salvatore Bonaccorso at 2023-02-07T09:43:22+01:00 Move NOTE below

[Git][security-tracker-team/security-tracker][master] Process several NFUs

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1eef5a30 by Salvatore Bonaccorso at 2023-02-07T09:34:27+01:00 Process several NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker] Deleted branch tryton-sao

2023-02-07 Thread Mathias Behrle (@mbehrle)
Mathias Behrle deleted branch tryton-sao at Debian Security Tracker / security-tracker -- You're receiving this email because of your account on salsa.debian.org. ___ debian-security-tracker-commits mailing list

[Git][security-tracker-team/security-tracker] Pushed new branch tryton-sao

2023-02-07 Thread Mathias Behrle (@mbehrle)
Mathias Behrle pushed new branch tryton-sao at Debian Security Tracker / security-tracker -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/tree/tryton-sao You're receiving this email because of your account on salsa.debian.org.

[Git][security-tracker-team/security-tracker][master] automatic update

2023-02-07 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 11d16059 by security tracker role at 2023-02-07T08:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list