[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-28625

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e17ffc9e by Salvatore Bonaccorso at 2023-04-03T22:51:23+02:00 Add Debian bug reference for CVE-2023-28625 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-28625/libapache2-mod-auth-openidc

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bf5d5561 by Salvatore Bonaccorso at 2023-04-03T22:35:48+02:00 Add CVE-2023-28625/libapache2-mod-auth-openidc - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-28834/nextcloud-server, itp'ed

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 11cfbd99 by Salvatore Bonaccorso at 2023-04-03T22:34:42+02:00 Add CVE-2023-28834/nextcloud-server, itped - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a9fb734 by Salvatore Bonaccorso at 2023-04-03T22:30:40+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 780ed588 by Salvatore Bonaccorso at 2023-04-03T22:23:32+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3f84fd6f by security tracker role at 2023-04-03T20:10:34+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-4899/libzstd

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 68e5a186 by Salvatore Bonaccorso at 2023-04-03T21:53:07+02:00 Add CVE-2022-4899/libzstd - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process several NFUs

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e01db48d by Salvatore Bonaccorso at 2023-04-03T21:41:50+02:00 Process several NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-1436/libjettison-java: reference introductory commit

2023-04-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: b921f844 by Sylvain Beucler at 2023-04-03T19:53:38+02:00 CVE-2023-1436/libjettison-java: reference introductory commit - - - - - 705ca49b by Sylvain Beucler at 2023-04-03T20:14:08+02:00

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-1996/golang-github-emicklei-go-restful

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fff04cb5 by Salvatore Bonaccorso at 2023-04-03T19:20:27+02:00 Track fixed version for CVE-2022-1996/golang-github-emicklei-go-restful - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2022-1996

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f3a2f25e by Salvatore Bonaccorso at 2023-04-03T19:19:30+02:00 Add upstream tag information for CVE-2022-1996 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for xen issues fixed via unstable

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d3f3e9f7 by Salvatore Bonaccorso at 2023-04-03T19:17:23+02:00 Track fixed version for xen issues fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Re-claim

2023-04-03 Thread Daniel Leidert (@dleidert)
-- -ruby-loofah +ruby-loofah (dleidert) NOTE: 20221231: Programming language: Ruby. NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/ruby-loofah.git NOTE: 20230313: Pinged Daniel re. patches in repo ^. (lamby) NOTE: 20230403: See "RFC: ruby-loofah 2.2.3-1+deb10u2&qu

[Git][security-tracker-team/security-tracker][master] CVE-2023-1436/libjettison-java: buster postponed

2023-04-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: cf39b23b by Sylvain Beucler at 2023-04-03T17:33:43+02:00 CVE-2023-1436/libjettison-java: buster postponed - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2023-0836/haproxy: buster not-affected

2023-04-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a4d78dd by Sylvain Beucler at 2023-04-03T17:15:32+02:00 CVE-2023-0836/haproxy: buster not-affected - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Clarify that the additional hardening for CVE-2023-28879 should not be applied to older versions

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 01521ba5 by Salvatore Bonaccorso at 2023-04-03T16:42:18+02:00 Clarify that the additional hardening for CVE-2023-28879 should not be applied to older versions - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] dla: add jruby

2023-04-03 Thread Sylvain Beucler (@beuc)
= @@ -111,6 +111,11 @@ hdf5 NOTE: 20230318: Enrico did some work around hdf5* packaging in the past, probably NOTE: 20230318: sync w/ him. (utkarsh) -- +jruby + NOTE: 20230403: Programming language: Ruby, Java, C. + NOTE: 20230403: Special attention

[Git][security-tracker-team/security-tracker][master] CVE-2023-*/nvidia-graphics-drivers-legacy-340xx: buster ignored

2023-04-03 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 285112bc by Sylvain Beucler at 2023-04-03T14:54:11+02:00 CVE-2023-*/nvidia-graphics-drivers-legacy-340xx: buster ignored - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: Updated note for ruby-loofah.

2023-04-03 Thread Chris Lamb (@lamby)
/dla-needed.txt = @@ -245,6 +245,7 @@ ruby-loofah NOTE: 20221231: Programming language: Ruby. NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/ruby-loofah.git NOTE: 20230313: Pinged Daniel re. patches in repo ^. (lamby) + NOTE: 20230403

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f7ec6111 by Salvatore Bonaccorso at 2023-04-03T11:04:49+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aca8833b by security tracker role at 2023-04-03T08:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-04-03 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 86127df1 by Salvatore Bonaccorso at 2023-04-03T08:50:05+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list