[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2023-27585,asterisk: Buster is affected

2023-04-18 Thread Markus Koschany (@apo)
! Package is used by many customers and users!. NOTE: 20230326: VCS: https://salsa.debian.org/apache-team/apache2. Yadd is ok for using apache2 salsa tree -- +asterisk (Markus Koschany) + NOTE: 20230418: Programming language: C. + NOTE: 20230418: VCS: https://salsa.debian.org/lts-team/packages

[Git][security-tracker-team/security-tracker][master] Concluded that CVE-2023-1625 do not require a DLA for buster. It is an...

2023-04-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f8f4753 by Ola Lundqvist at 2023-04-18T23:16:31+02:00 Concluded that CVE-2023-1625 do not require a DLA for buster. It is an information leak vulnerability to authenticated users with low impact. -

[Git][security-tracker-team/security-tracker][master] LTS: add connman to dla-needed.txt

2023-04-18 Thread Ola Lundqvist (@opal)
-needed.txt = @@ -54,6 +54,11 @@ configobj (Chris Lamb) NOTE: 20230416: Special attention: Low priority but high popcon. NOTE: 20230417: No upstream-blessed patch yet. (lamby) -- +connman + NOTE: 20230418: Programming language: C. + NOTE: 20230418: VCS

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 20d8b5cf by security tracker role at 2023-04-18T20:10:22+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Concluded that frr package does not need an update for buster. The...

2023-04-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fc98b78d by Ola Lundqvist at 2023-04-18T23:43:31+02:00 Concluded that frr package does not need an update for buster. The vilnerability at hand is clearly less problematic than many other open

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3394-1 for asterisk

2023-04-18 Thread Markus Koschany (@apo)
!. NOTE: 20230326: VCS: https://salsa.debian.org/apache-team/apache2. Yadd is ok for using apache2 salsa tree -- -asterisk (Markus Koschany) - NOTE: 20230418: Programming language: C. - NOTE: 20230418: VCS: https://salsa.debian.org/lts-team/packages/asterisk.git - NOTE: 20230418: Special attention

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-29197/php-guzzlehttp-psr7

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4597ba98 by Salvatore Bonaccorso at 2023-04-18T22:35:07+02:00 Add CVE-2023-29197/php-guzzlehttp-psr7 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5383ce48 by Salvatore Bonaccorso at 2023-04-18T22:27:41+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] LTS: add avahi to dla-needed.txt

2023-04-18 Thread Ola Lundqvist (@opal)
-needed.txt = @@ -31,6 +31,10 @@ asterisk (Markus Koschany) NOTE: 20230418: VCS: https://salsa.debian.org/lts-team/packages/asterisk.git NOTE: 20230418: Special attention: pjproject library is included in debian directory!. -- +avahi + NOTE: 20230418

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-30536/php-slim-psr7

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e743fb4f by Salvatore Bonaccorso at 2023-04-18T22:38:40+02:00 Add CVE-2023-30536/php-slim-psr7 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-30536/php-slim-psr7

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 45a167ff by Salvatore Bonaccorso at 2023-04-18T23:18:51+02:00 Add Debian bug reference for CVE-2023-30536/php-slim-psr7 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-29197/php-guzzlehttp-psr7

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 249ee9b4 by Salvatore Bonaccorso at 2023-04-18T23:23:47+02:00 Add Debian bug reference for CVE-2023-29197/php-guzzlehttp-psr7 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-30539/nextcloud-server

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69e35a37 by Salvatore Bonaccorso at 2023-04-18T22:28:15+02:00 Add CVE-2023-30539/nextcloud-server - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Triage CVE-2023-27585 in asterisk for buster LTS.

2023-04-18 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 3dd091ab by Chris Lamb at 2023-04-18T18:21:44+01:00 Triage CVE-2023-27585 in asterisk for buster LTS. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-045{8,9}/linux

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: deed6cae by Salvatore Bonaccorso at 2023-04-18T20:35:03+02:00 Add CVE-2023-045{8,9}/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] owslib fixed in sid

2023-04-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d1314235 by Moritz Muehlenhoff at 2023-04-18T16:13:23+02:00 owslib fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2022-1949 mark as ignored for buster

2023-04-18 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 4d0d4bd4 by Anton Gladky at 2023-04-19T06:45:22+02:00 CVE-2022-1949 mark as ignored for buster - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-1981/avahi

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aed53b23 by Salvatore Bonaccorso at 2023-04-19T06:40:47+02:00 Add Debian bug reference for CVE-2023-1981/avahi - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2023-3077{4,5}/tiff

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9f482b94 by Salvatore Bonaccorso at 2023-04-18T08:31:02+02:00 Update information on CVE-2023-3077{4,5}/tiff - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-294{79,80}/rnp

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a0f19053 by Salvatore Bonaccorso at 2023-04-18T08:57:34+02:00 Add CVE-2023-294{79,80}/rnp - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3393-1 for protobuf

2023-04-18 Thread Helmut Grohne (@helmutg)
Helmut Grohne pushed to branch master at Debian Security Tracker / security-tracker Commits: ad65f979 by Helmut Grohne at 2023-04-18T09:03:41+02:00 Reserve DLA-3393-1 for protobuf - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-1981/avahi

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9bd23c48 by Salvatore Bonaccorso at 2023-04-18T08:18:37+02:00 Add CVE-2023-1981/avahi - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: Correct name of openvswitch package.

2023-04-18 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 15779fa0 by Chris Lamb at 2023-04-18T09:07:53+01:00 dla-needed.txt: Correct name of openvswitch package. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-3077{4,5}/tiff

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d9979b69 by Salvatore Bonaccorso at 2023-04-18T08:21:34+02:00 Add CVE-2023-3077{4,5}/tiff - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-28856/redis

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 05acdd6f by Salvatore Bonaccorso at 2023-04-18T09:26:25+02:00 Add CVE-2023-28856/redis - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add additional reference for CVE-2023-28856/redis

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 678afd9f by Salvatore Bonaccorso at 2023-04-18T09:30:18+02:00 Add additional reference for CVE-2023-28856/redis - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e527d6ed by security tracker role at 2023-04-18T08:10:27+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug references for CVE-2023-294{79,80}/rnp

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2dbcf002 by Salvatore Bonaccorso at 2023-04-18T11:56:37+02:00 Add Debian bug references for CVE-2023-294{79,80}/rnp - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-04-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c30545da by Salvatore Bonaccorso at 2023-04-18T11:55:46+02:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] lts: add link to vcs for openvswitch

2023-04-18 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d6b7615 by Emilio Pozuelo Monfort at 2023-04-18T14:41:21+02:00 lts: add link to vcs for openvswitch - - - - - 1 changed file: - data/dla-needed.txt Changes: