[Git][security-tracker-team/security-tracker][master] fill in details for openssl

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
] - openssl (Minor issue, fix along with future DSA) + [bullseye] - openssl (Vulnerable code not present, only affects 3.x) + [buster] - openssl (Vulnerable code not present, only affects 3.x) NOTE: https://www.openssl.org/news/secadv/20230714.txt NOTE: Fixed

[Git][security-tracker-team/security-tracker][master] "new" freetype isue

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 208d31c4 by Moritz Muehlenhoff at 2023-07-15T00:04:47+02:00 new freetype isue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: fd524306 by Moritz Muehlenhoff at 2023-07-14T23:56:26+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] bugnums

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 433b2294 by Moritz Muehlenhoff at 2023-07-14T23:51:27+02:00 bugnums - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2012-66{98,99} and CVE-2012-6700

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 72944f84 by Salvatore Bonaccorso at 2023-07-14T23:48:19+02:00 Track fixed version for CVE-2012-66{98,99} and CVE-2012-6700 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-38325/python-cryptography

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9f82e1a7 by Salvatore Bonaccorso at 2023-07-14T23:29:27+02:00 Update status for CVE-2023-38325/python-cryptography - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-38325/python-cryptography

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4253d969 by Salvatore Bonaccorso at 2023-07-14T23:18:52+02:00 Add CVE-2023-38325/python-cryptography - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-38199/modsecurity-crs

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 85dde5d5 by Salvatore Bonaccorso at 2023-07-14T23:14:12+02:00 Add CVE-2023-38199/modsecurity-crs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add new CVE-2023-3825{2,3}/w3m

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7576e783 by Salvatore Bonaccorso at 2023-07-14T23:06:27+02:00 Add new CVE-2023-3825{2,3}/w3m - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-2975/openssl

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
: The AES-SIV cipher implementation contains a bug that c ...) - TODO: check + - openssl + NOTE: https://www.openssl.org/news/secadv/20230714.txt + NOTE: Fixed by: https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=00e2f5eea29994d19293ec4e8c8775ba73678598 (openssl-3.0

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1f537283 by Salvatore Bonaccorso at 2023-07-14T22:34:58+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3497-1 for pypdf2

2023-07-14 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: fac94237 by Adrian Bunk at 2023-07-14T23:31:24+03:00 Reserve DLA-3497-1 for pypdf2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a6908d47 by security tracker role at 2023-07-14T20:12:24+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-37271: Reference commit from 5.3 version upstream

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4aab917f by Salvatore Bonaccorso at 2023-07-14T21:49:09+02:00 CVE-2023-37271: Reference commit from 5.3 version upstream - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reference upstream commit for CVE-2023-3783{6,7}

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 54265aea by Salvatore Bonaccorso at 2023-07-14T21:44:46+02:00 Reference upstream commit for CVE-2023-3783{6,7} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add reference for CVE-2023-37278

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 25b6eab3 by Salvatore Bonaccorso at 2023-07-14T21:25:11+02:00 Add reference for CVE-2023-37278 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: Add notes

2023-07-14 Thread Adrian Bunk (@bunk)
: and possibly issue a DSA with a few CVEs that were fixed in later dists (Beuc/front-desk) + NOTE: 20230714: Still reviewing+testing CVEs. (bunk) -- tiff (Adrian Bunk) NOTE: 20230702: Added by Front-Desk (ta) + NOTE: 20230714: Waiting for upstream reaction on CVE-2023-3618. (bunk) -- xqilla (tobi

[Git][security-tracker-team/security-tracker][master] gpac DSA

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c296769 by Moritz Mühlenhoff at 2023-07-14T20:45:04+02:00 gpac DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2023-36807 does not affect buster or bullseye

2023-07-14 Thread Adrian Bunk (@bunk)
Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker Commits: ab1a0c52 by Adrian Bunk at 2023-07-14T21:40:57+03:00 CVE-2023-36807 does not affect buster or bullseye And bookworm is after the fixed version. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] nvidia-open-gpu-kernel-modules spu

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: bc104ac6 by Moritz Mühlenhoff at 2023-07-14T20:38:59+02:00 nvidia-open-gpu-kernel-modules spu - - - - - 1 changed file: - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] cpp-httplib spu

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 92fc44fe by Moritz Mühlenhoff at 2023-07-14T20:37:41+02:00 cpp-httplib spu - - - - - 1 changed file: - data/next-point-update.txt Changes: =

[Git][security-tracker-team/security-tracker][master] change nftables duplocate to NOTE

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 86ab0a35 by Moritz Muehlenhoff at 2023-07-14T19:20:40+02:00 change nftables duplocate to NOTE - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 84d9555e by Moritz Muehlenhoff at 2023-07-14T19:16:53+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new zabbix issues

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a4e8f5d by Moritz Muehlenhoff at 2023-07-14T19:11:44+02:00 new zabbix issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new opendkim issue

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5fbf2768 by Moritz Muehlenhoff at 2023-07-14T18:34:53+02:00 new opendkim issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new restrictedpython issue

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 4c95f974 by Moritz Muehlenhoff at 2023-07-14T18:32:24+02:00 new restrictedpython issue - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Correct triage for CVE-2023-35001

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 815e714d by Salvatore Bonaccorso at 2023-07-14T17:32:58+02:00 Correct triage for CVE-2023-35001 For some reason I confused 5.13-rc1 with 3.13-rc1 ... - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 20c85db5 by Moritz Muehlenhoff at 2023-07-14T17:15:37+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] firefox n/a

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d38a4cab by Moritz Muehlenhoff at 2023-07-14T17:04:08+02:00 firefox n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] okio n/a

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: dd212131 by Moritz Muehlenhoff at 2023-07-14T16:39:00+02:00 okio n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new gitlab issues

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: bb70fa6c by Moritz Muehlenhoff at 2023-07-14T16:27:26+02:00 new gitlab issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e5cecbd4 by Moritz Muehlenhoff at 2023-07-14T16:25:10+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new Qt issue

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a9116832 by Moritz Muehlenhoff at 2023-07-14T16:04:32+02:00 new Qt issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new cmark-gfm issue

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a0db6945 by Moritz Muehlenhoff at 2023-07-14T15:55:50+02:00 new cmark-gfm issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new libjpeg issues

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 909f3035 by Moritz Muehlenhoff at 2023-07-14T15:29:34+02:00 new libjpeg issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 17c428e5 by Moritz Muehlenhoff at 2023-07-14T14:51:48+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new wireshark issues

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: da943b78 by Moritz Muehlenhoff at 2023-07-14T14:14:35+02:00 new wireshark issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] linux n/a

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f0f172cf by Moritz Muehlenhoff at 2023-07-14T14:07:31+02:00 linux n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new gitlab issues

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f71ec469 by Moritz Muehlenhoff at 2023-07-14T13:53:48+02:00 new gitlab issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c8aa792 by Moritz Muehlenhoff at 2023-07-14T13:43:43+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] nvidia-open-gpu-kernel-modules fixed in sid

2023-07-14 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ea3b15a by Moritz Muehlenhoff at 2023-07-14T13:34:17+02:00 nvidia-open-gpu-kernel-modules fixed in sid - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3496-1 for lemonldap-ng

2023-07-14 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 4be5b41f by Guilhem Moulin at 2023-07-14T12:24:54+02:00 Reserve DLA-3496-1 for lemonldap-ng - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-07-14 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c8cfc32a by security tracker role at 2023-07-14T08:11:31+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list