[Git][security-tracker-team/security-tracker][master] Reserve DLA-3337-1 for mariadb-10.3

2023-02-22 Thread Emilio Pozuelo Monfort (@pochu)
can be marked as . NOTE: 20230213: VCS: https://salsa.debian.org/debian/man2html.git -- -mariadb-10.3 (Emilio) - NOTE: 20220222: coordinating DLA with maintainer (pochu) --- mono NOTE: 20230222: Programming language: C. NOTE: 20230222: Needs further investigation. How can a desktop

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-38779/kibana

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 99eb83cd by Salvatore Bonaccorso at 2023-02-23T08:13:33+01:00 Add CVE-2022-38779/kibana - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Correct CVE association for qemu issue

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 11d28ee7 by Salvatore Bonaccorso at 2023-02-23T08:12:25+01:00 Correct CVE association for qemu issue Did typoed yesterday apparently the CVE for qemu. Move entry from CVE-2023-0644 to

[Git][security-tracker-team/security-tracker][master] 2 commits: Mark axtls as removed from stable

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b779704 by Salvatore Bonaccorso at 2023-02-23T07:30:53+01:00 Mark axtls as removed from stable - - - - - 01862523 by Salvatore Bonaccorso at 2023-02-23T07:31:20+01:00 axtls is removed from

[Git][security-tracker-team/security-tracker][master] Add php7.4 to dsa-needed list

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3514c62d by Salvatore Bonaccorso at 2023-02-23T07:32:48+01:00 Add php7.4 to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add chromium to dsa-needed list

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 35d95ba2 by Salvatore Bonaccorso at 2023-02-23T07:31:56+01:00 Add chromium to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add new chromium issues

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 689e5571 by Salvatore Bonaccorso at 2023-02-23T07:28:26+01:00 Add new chromium issues - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-24998/libcommons-fileupload-java via unstable

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 621f78aa by Salvatore Bonaccorso at 2023-02-23T07:26:56+01:00 Track fixed version for CVE-2023-24998/libcommons-fileupload-java via unstable - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5357-1 for git

2023-02-22 Thread Aron Xu (@aron)
Aron Xu pushed to branch master at Debian Security Tracker / security-tracker Commits: 0de6743b by Aron Xu at 2023-02-23T14:26:37+08:00 Reserve DSA-5357-1 for git - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: claim nodejs in dla-needed.txt

2023-02-22 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 7bc142d1 by Guilhem Moulin at 2023-02-23T02:36:40+01:00 LTS: claim nodejs in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3336-1 for node-url-parse

2023-02-22 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: ec09bb29 by Guilhem Moulin at 2023-02-23T01:33:53+01:00 Reserve DLA-3336-1 for node-url-parse - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim openimageio in dla-needed.txt

2023-02-22 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 23e287e6 by Markus Koschany at 2023-02-22T23:38:48+01:00 Claim openimageio in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2021-32142 as no-dsa in buster following bullseye decision.

2023-02-22 Thread Ola Lundqvist (@opal)
/bc3aaf4223fdb70d52d470dae65c5a7923ea2a49 (0.21-Beta1) CVE-2021-32141 = data/dla-needed.txt = @@ -151,6 +151,11 @@ man2html (gladk) mariadb-10.3 (Emilio) NOTE: 20220222: coordinating DLA with maintainer (pochu) -- +mono + NOTE: 20230222: Programming

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-39244,CVE-2022-39269, Asterisk: Bullseye is affected

2023-02-22 Thread Markus Koschany (@apo)
+20110422.1-2.1+deb10u3 = data/dla-needed.txt = @@ -24,10 +24,6 @@ apache2 (Lee Garrett) NOTE: 20221227: Special attention: Double check an update! Package is used by many customers and users!. NOTE: 20230222: CVE-2019-17567

[Git][security-tracker-team/security-tracker][master] lts: take binwalk

2023-02-22 Thread Adrian Bunk (@bunk)
= @@ -28,7 +28,7 @@ asterisk (Markus Koschany) NOTE: 20221211: Programming language: C. NOTE: 20230111: VCS: https://salsa.debian.org/lts-team/packages/asterisk.git -- -binwalk +binwalk (Adrian Bunk) NOTE: 20230222: Programming language: Python. -- ceph View

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3334-1 for sofia-sip

2023-02-22 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f3e4722 by Adrian Bunk at 2023-02-22T23:35:04+02:00 Reserve DLA-3334-1 for sofia-sip - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-23009/libreswan via unstable

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a47f6d77 by Salvatore Bonaccorso at 2023-02-22T22:04:51+01:00 Track fixed version for CVE-2023-23009/libreswan via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-4833{7,8,9}/emacs via unstable

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5bb7a83e by Salvatore Bonaccorso at 2023-02-22T22:02:04+01:00 Track fixed version for CVE-2022-4833{7,8,9}/emacs via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-48340/glustefs

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5a5de58b by Salvatore Bonaccorso at 2023-02-22T22:00:30+01:00 Add Debian bug reference for CVE-2022-48340/glustefs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-23627/ruby-sanitize via unstable

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 776be473 by Salvatore Bonaccorso at 2023-02-22T21:45:51+01:00 Track fixed version for CVE-2023-23627/ruby-sanitize via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2022-47516/sofia-sip

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c5f10566 by Salvatore Bonaccorso at 2023-02-22T21:32:07+01:00 Add Debian bug reference for CVE-2022-47516/sofia-sip - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: add binwalk to dla-needed.txt

2023-02-22 Thread Ola Lundqvist (@opal)
-needed.txt = @@ -28,6 +28,9 @@ asterisk (Markus Koschany) NOTE: 20221211: Programming language: C. NOTE: 20230111: VCS: https://salsa.debian.org/lts-team/packages/asterisk.git -- +binwalk + NOTE: 20230222: Programming language: Python. +-- ceph NOTE

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2022-47516

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f8f4c356 by Salvatore Bonaccorso at 2023-02-22T21:23:29+01:00 Update information for CVE-2022-47516 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2021-32142/libraw

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f2284ae4 by Salvatore Bonaccorso at 2023-02-22T21:17:28+01:00 Update information for CVE-2021-32142/libraw Add Debian bug reference for issue and mark as no-dsa for bullseye. - - - - - 1

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2021-32850/jquery-minicolors

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 887c4e79 by Salvatore Bonaccorso at 2023-02-22T21:15:36+01:00 Add Debian bug reference for CVE-2021-32850/jquery-minicolors - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove notes for CVE-2020-36643

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 532f311d by Salvatore Bonaccorso at 2023-02-22T21:14:32+01:00 Remove notes for CVE-2020-36643 CVE got withrawn by the assigning CNA as further investigation showed that there is no security

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-47517 as NFU

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d9802189 by Salvatore Bonaccorso at 2023-02-22T21:12:37+01:00 Mark CVE-2022-47517 as NFU The CVE assignment is specific to the libsofia-sip fork in drachtio-server. The changes applied

[Git][security-tracker-team/security-tracker][master] CVE-2022-45939 as no-dsa in buster even though emacs package has been fixed....

2023-02-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: db183443 by Ola Lundqvist at 2023-02-22T21:10:16+01:00 CVE-2022-45939 as no-dsa in buster even though emacs package has been fixed. Still consider it as minor but if someone want to fix it it is ok.

[Git][security-tracker-team/security-tracker][master] Update status for multipath-tools

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 52b01bb1 by Salvatore Bonaccorso at 2023-02-22T20:41:56+01:00 Update status for multipath-tools - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] bookworm triage

2023-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 06788701 by Moritz Muehlenhoff at 2023-02-22T20:33:10+01:00 bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-24998 as no-dsa in buster.

2023-02-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2638d81f by Ola Lundqvist at 2023-02-22T20:07:14+01:00 CVE-2023-24998 as no-dsa in buster. - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] disassociate CVE-2021-43172 from two source packages.

2023-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 08f3f48e by Moritz Muehlenhoff at 2023-02-22T17:38:54+01:00 disassociate CVE-2021-43172 from two source packages. Theres no concrete information whether they are actually affected (and all other

[Git][security-tracker-team/security-tracker][master] Reference additional followup for CVE-2022-37704/amanda

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e016864 by Salvatore Bonaccorso at 2023-02-22T17:12:58+01:00 Reference additional followup for CVE-2022-37704/amanda - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Claim samba in dla-needed.txt

2023-02-22 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: c31a1ca4 by Lee Garrett at 2023-02-22T16:04:54+01:00 Claim samba in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] epiphany fixed in sid

2023-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f0e022ba by Moritz Muehlenhoff at 2023-02-22T15:34:28+01:00 epiphany fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add comment on CVE-2019-17567 (apache2)

2023-02-22 Thread Lee Garrett (@lgarrett)
customers and users!. + NOTE: 20230222: CVE-2019-17567 requires 1000+ LoC patch, too intrusive (lee) -- asterisk (Markus Koschany) NOTE: 20221211: Programming language: C. View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] add PHP commit references

2023-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 49fed8a1 by Moritz Muehlenhoff at 2023-02-22T11:51:46+01:00 add PHP commit references - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reference upstream commit for CVE-2023-0662/php

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1fef44a3 by Salvatore Bonaccorso at 2023-02-22T10:21:17+01:00 Reference upstream commit for CVE-2023-0662/php - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] lts: take mariadb-10.3

2023-02-22 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 8f0a26b3 by Emilio Pozuelo Monfort at 2023-02-22T10:18:06+01:00 lts: take mariadb-10.3 Im coordinating the DLA with Otto. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 72a84504 by Salvatore Bonaccorso at 2023-02-22T09:27:32+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process one Wordpress plugin as NFU

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 43e74aa2 by Salvatore Bonaccorso at 2023-02-22T09:19:23+01:00 Process one Wordpress plugin as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f452d45 by security tracker role at 2023-02-22T08:10:31+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list