[Git][security-tracker-team/security-tracker][master] CVE-2021-46877 does not affect buster

2023-04-29 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: abafe136 by Adrian Bunk at 2023-04-30T03:08:14+03:00 CVE-2021-46877 does not affect buster - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: take jackson-databind

2023-04-29 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: ab84e45a by Adrian Bunk at 2023-04-30T02:02:44+03:00 dla: take jackson-databind - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3403-1 and DLA-3404-1 for linux and linux-5.10

2023-04-29 Thread Ben Hutchings (@benh)
Ben Hutchings pushed to branch master at Debian Security Tracker / security-tracker Commits: 41eb9f95 by Ben Hutchings at 2023-04-29T22:41:54+02:00 Reserve DLA-3403-1 and DLA-3404-1 for linux and linux-5.10 - - - - - 1 changed file: - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Process one NFU

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 493de603 by Salvatore Bonaccorso at 2023-04-29T22:31:04+02:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-31484/perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dfa74652 by Salvatore Bonaccorso at 2023-04-29T22:26:11+02:00 Add Debian bug reference for CVE-2023-31484/perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Move #954089 association to correct CVE

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 532e5515 by Salvatore Bonaccorso at 2023-04-29T22:14:42+02:00 Move #954089 association to correct CVE - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f52e1fd0 by security tracker role at 2023-04-29T20:12:22+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: take jruby

2023-04-29 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: ab4fe165 by Adrian Bunk at 2023-04-29T22:23:57+03:00 dla: take jruby - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-29950/swftools

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b166b09 by Salvatore Bonaccorso at 2023-04-29T21:15:24+02:00 Add CVE-2023-29950/swftools - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: da701d71 by Salvatore Bonaccorso at 2023-04-29T21:14:56+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-1161: Note that it only partially affects <= bullseye

2023-04-29 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: 92d458ca by Adrian Bunk at 2023-04-29T21:49:50+03:00 CVE-2023-1161: Note that it only partially affects = bullseye - - - - - e18158d9 by Adrian Bunk at 2023-04-29T21:51:33+03:00 Reserve DLA-3402-1 for

[Git][security-tracker-team/security-tracker][master] ffmpeg updates, some n/a, remove one postponed entry for issue fixed in 4.3.6

2023-04-29 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 08610bfb by Moritz Muehlenhoff at 2023-04-29T19:30:25+02:00 ffmpeg updates, some n/a, remove one postponed entry for issue fixed in 4.3.6 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] sqlite: associate past sqlite3 CVEs to sqlite + buster triage (open + 2020-2022)

2023-04-29 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: afc2c368 by Sylvain Beucler at 2023-04-29T18:45:13+02:00 sqlite: associate past sqlite3 CVEs to sqlite + buster triage (open + 2020-2022) See

[Git][security-tracker-team/security-tracker][master] Remove two manual overrides in ancient entry and note

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 75c06504 by Salvatore Bonaccorso at 2023-04-29T17:17:39+02:00 Remove two manual overrides in ancient entry and note The reason was maybe that back then there was not automatic

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2023-31484/perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5b6ea307 by Salvatore Bonaccorso at 2023-04-29T15:53:01+02:00 Update information for CVE-2023-31484/perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2023-31485/libgitlab-api-v4-perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ef6eeb6e by Salvatore Bonaccorso at 2023-04-29T15:50:07+02:00 Update information for CVE-2023-31485/libgitlab-api-v4-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] DSA-2044-1: Make version without epoch

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4bd92754 by Salvatore Bonaccorso at 2023-04-29T15:34:45+02:00 DSA-2044-1: Make version without epoch The fix was before the epoch bump. - - - - - 1 changed file: - data/DSA/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark libsignal-protocol-c as no-dsa for bullseye

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a813710a by Salvatore Bonaccorso at 2023-04-29T15:21:43+02:00 Mark libsignal-protocol-c as no-dsa for bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream commit reference for CVE-2023-2002

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a6b3043b by Salvatore Bonaccorso at 2023-04-29T14:43:41+02:00 Add upstream commit reference for CVE-2023-2002 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-30847/h2o

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c96b5bf by Salvatore Bonaccorso at 2023-04-29T14:36:45+02:00 Add CVE-2023-30847/h2o - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 89f642d7 by Salvatore Bonaccorso at 2023-04-29T14:29:37+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Correct tracking for mariadb-10.5 issues in bullseye

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a48b9387 by Salvatore Bonaccorso at 2023-04-29T13:53:01+02:00 Correct tracking for mariadb-10.5 issues in bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-47015 in bullseye

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 914683d9 by Salvatore Bonaccorso at 2023-04-29T13:47:37+02:00 Track fixed version for CVE-2022-47015 in bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-1227/libpod addressed as well in bullseye

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 21de68d9 by Salvatore Bonaccorso at 2023-04-29T13:44:40+02:00 Mark CVE-2022-1227/libpod addressed as well in bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove three no-dsa tagged entries which got an update

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 73c6f529 by Salvatore Bonaccorso at 2023-04-29T13:41:36+02:00 Remove three no-dsa tagged entries which got an update - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] bookworm triage

2023-04-29 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 20fade1e by Moritz Muehlenhoff at 2023-04-29T12:55:45+02:00 bookworm triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 297f349e by Salvatore Bonaccorso at 2023-04-29T10:42:15+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-31484/perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0cbd728e by Salvatore Bonaccorso at 2023-04-29T10:37:48+02:00 Add CVE-2023-31484/perl - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-31485/libgitlab-api-v4-perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 22a61e7b by Salvatore Bonaccorso at 2023-04-29T10:30:04+02:00 Add CVE-2023-31485/libgitlab-api-v4-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track as well perl for CVE-2023-31486

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0c22b01a by Salvatore Bonaccorso at 2023-04-29T10:28:30+02:00 Track as well perl for CVE-2023-31486 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9565c55e by Salvatore Bonaccorso at 2023-04-29T10:25:12+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-28882/modsecurity

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6cbfd60e by Salvatore Bonaccorso at 2023-04-29T10:20:52+02:00 Add Debian bug reference for CVE-2023-28882/modsecurity - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 034b5e4b by security tracker role at 2023-04-29T08:12:12+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add two additional references for CVE-2023-31486

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 73985306 by Salvatore Bonaccorso at 2023-04-29T09:44:10+02:00 Add two additional references for CVE-2023-31486 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-31486/libhttp-tiny-perl

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9fd3c340 by Salvatore Bonaccorso at 2023-04-29T08:39:43+02:00 Add CVE-2023-31486/libhttp-tiny-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-28882/modsecurity

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ca9cae7e by Salvatore Bonaccorso at 2023-04-29T08:29:32+02:00 Add CVE-2023-28882/modsecurity - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-1999/libwebp

2023-04-29 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cbb533e4 by Salvatore Bonaccorso at 2023-04-29T08:22:33+02:00 Add CVE-2023-1999/libwebp - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/DSA/list Changes: