[Git][security-tracker-team/security-tracker][master] 2 commits: Added trafficserver to dla-needed with a note about low prio due to few users.

2023-06-18 Thread Ola Lundqvist (@opal)
/fb13af36286b9d898e332e8762a286eb83bd1770 (v2.0.0) = data/dla-needed.txt = @@ -221,6 +221,10 @@ samba (Lee Garrett) syncthing NOTE: 20230616: Added by Front-Desk (opal) -- +trafficserver + NOTE: 20230618: Added by Front-Desk (opal) + NOTE

[Git][security-tracker-team/security-tracker][master] update notes

2023-06-18 Thread Thorsten Alteholz (@alteholz)
package, not all tests pass yet -- ruby-doorkeeper NOTE: 20230618: Added by Front-Desk (opal) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d0ae311f69c76f1ed243b5eaf0215490af46108c -- View it on GitLab: https://salsa.debian.org/security-tracker

[Git][security-tracker-team/security-tracker][master] Added php-dompdf to dla-needed with a note about low prio.

2023-06-18 Thread Ola Lundqvist (@opal)
: 20230618: Added by Front-Desk (opal) + NOTE: 20230618: Low priority but higher than to not fix it. +-- python-glance-store NOTE: 20230525: Added by Front-Desk (lamby) NOTE: 20230525: NB. CVE-2023-2088 filed against python-glance-store, python-os-brick, nova and cinder. View

[Git][security-tracker-team/security-tracker][master] 3 commits: Added sabnzbdplus to dla-needed.

2023-06-18 Thread Ola Lundqvist (@opal)
timing could be improved here -- +ruby-doorkeeper + NOTE: 20230618: Added by Front-Desk (opal) +-- ruby-loofah NOTE: 20221231: Added by Front-Desk (ola) NOTE: 20230313: Pinged Daniel re. patches in repo ^. (lamby) @@ -198,6 +201,9 @@ ruby-rails-html-sanitizer ruby-redcloth NOTE: 20230612

[Git][security-tracker-team/security-tracker][master] 4 commits: Marked golang-1.11 CVEs as no-dsa for buster following bullseye.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2bc45273 by Ola Lundqvist at 2023-06-18T21:46:34+02:00 Marked golang-1.11 CVEs as no-dsa for buster following bullseye. - - - - - 22287c80 by Ola Lundqvist at 2023-06-18T21:49:11+02:00 Marked

[Git][security-tracker-team/security-tracker][master] Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 00d9ac0a by Ola Lundqvist at 2023-06-18T21:41:44+02:00 Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed. Following the decision for golang-1.11 package. - - - - - 1

[Git][security-tracker-team/security-tracker][master] 5 commits: Marked gpac CVE-2023-3291 end-of-life.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 08297450 by Ola Lundqvist at 2023-06-18T21:34:53+02:00 Marked gpac CVE-2023-3291 end-of-life. - - - - - f19d2d30 by Ola Lundqvist at 2023-06-18T21:34:54+02:00 Marked librabbitmq CVE-2023-35789 no-dsa

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-06-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 76306029 by Moritz Muehlenhoff at 2023-06-18T21:22:39+02:00 bullseye/bookworm triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for several odoo issues

2023-06-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f71ad868 by Salvatore Bonaccorso at 2023-06-18T20:57:18+02:00 Track fixed version for several odoo issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-35005 for airflow, itp'ed

2023-06-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f2996354 by Salvatore Bonaccorso at 2023-06-18T20:52:31+02:00 Add CVE-2023-35005 for airflow, itped - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Fix CVE-2023-28709,tomcat10. (hopefully)

2023-06-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 71a893a0 by Markus Koschany at 2023-06-18T17:59:20+02:00 Fix CVE-2023-28709,tomcat10. (hopefully) - - - - - 1 changed file: - data/CVE/list Changes: =

Processing 4b9551028d80b5e9abc4920f54d2906af60f186d failed

2023-06-18 Thread security tracker role
The error message was: data/CVE/list:12083: expected package entry, got: '-[bookworm] - tomcat10 (Fix when more important issues arise)' make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list

[Git][security-tracker-team/security-tracker][master] 3 commits: Claim wordpress in dla-needed.txt

2023-06-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dd54db9e by Markus Koschany at 2023-06-18T17:50:08+02:00 Claim wordpress in dla-needed.txt - - - - - f43d96eb by Markus Koschany at 2023-06-18T17:52:42+02:00 CVE-2023-28709,tomcat10:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3456-1 for requests

2023-06-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5cbb107a by Markus Koschany at 2023-06-18T17:38:26+02:00 Reserve DLA-3456-1 for requests - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2022-30256: Add upstream patches for maradns

2023-06-18 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 407411d3 by Bastien Roucariès at 2023-06-18T14:48:07+00:00 CVE-2022-30256: Add upstream patches for maradns - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] xmltooling DSA

2023-06-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 163e43b8 by Moritz Mühlenhoff at 2023-06-18T16:44:54+02:00 xmltooling DSA - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Claim maradns

2023-06-18 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: a759932f by Bastien Roucariès at 2023-06-18T14:20:11+00:00 Claim maradns - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] libusrsctp: waiting for comments

2023-06-18 Thread @rouca
: = data/dla-needed.txt = @@ -85,6 +85,8 @@ libreoffice (Abhijith PA) -- libusrsctp (rouca) NOTE: 20230612: Added by Front-Desk (opal) + NOTE: 20230618: May need a backport see https://lists.debian.org/debian-lts/2023/06/msg00050.html (rouca) + NOTE: 20230618

[Git][security-tracker-team/security-tracker][master] new nuget issue (whether that very old is affected remains to be seen)

2023-06-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a6706697 by Moritz Muehlenhoff at 2023-06-18T14:27:01+02:00 new nuget issue (whether that very old is affected remains to be seen) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2014-125106/nanopb

2023-06-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cc5c358f by Salvatore Bonaccorso at 2023-06-18T13:38:33+02:00 Add CVE-2014-125106/nanopb - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-06-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: de3c825e by Salvatore Bonaccorso at 2023-06-18T13:36:44+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f871edfc by Ola Lundqvist at 2023-06-18T10:30:15+02:00 Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 1497f27f by Ola Lundqvist at 2023-06-18T10:26:21+02:00 Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm. CVE-2023-34410 CVE-2023-33285 and CVE-2023-32763 - -

[Git][security-tracker-team/security-tracker][master] automatic update

2023-06-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5627e3f6 by security tracker role at 2023-06-18T08:12:09+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list