[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-13936/velocity via unstable

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 00efb2d4 by Salvatore Bonaccorso at 2021-03-17T06:26:03+01:00 Track fixed version for CVE-2020-13936/velocity via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: (re)claim shiro in dla-needed.txt

2021-03-16 Thread Roberto C . Sánchez
: = data/dla-needed.txt = @@ -117,7 +117,7 @@ salt (Utkarsh) shadow (Sylvain Beucler) NOTE: 20210316: found new CVE, discussing with secteam -- -shiro +shiro (Roberto C. Sánchez) NOTE: 20200920: WIP NOTE: 20200928: Still awaiting reponse to request

[Git][security-tracker-team/security-tracker][master] bullseye triage

2021-03-16 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 504892bc by Moritz Muehlenhoff at 2021-03-16T22:50:10+01:00 bullseye triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-28543/varnish-modules

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7a1c28a9 by Salvatore Bonaccorso at 2021-03-16T21:53:58+01:00 Add CVE-2021-28543/varnish-modules - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process more NFUs

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 02bdff8a by Salvatore Bonaccorso at 2021-03-16T21:49:46+01:00 Process more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug references for gitlab-ci-multi-runner issues

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aa472170 by Salvatore Bonaccorso at 2021-03-16T21:38:43+01:00 Add Debian bug references for gitlab-ci-multi-runner issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-35459

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8bb5969a by Salvatore Bonaccorso at 2021-03-16T21:36:39+01:00 Add Debian bug reference for CVE-2020-35459 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2d355442 by Salvatore Bonaccorso at 2021-03-16T21:34:58+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for tor update

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d67e06f3 by Salvatore Bonaccorso at 2021-03-16T21:19:42+01:00 Reserve DSA number for tor update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ab67182f by security tracker role at 2021-03-16T20:10:31+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2021-280{89,90}/tor via unstable

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dbd95bc8 by Salvatore Bonaccorso at 2021-03-16T21:02:53+01:00 Add fixed version for CVE-2021-280{89,90}/tor via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Take tor for DSA release

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6859a72f by Salvatore Bonaccorso at 2021-03-16T20:51:51+01:00 Take tor for DSA release - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: take python2.7

2021-03-16 Thread Anton Gladky
= @@ -76,7 +76,7 @@ php-pear -- pillow (Abhijith PA) -- -python2.7 +python2.7 (Anton Gladky) NOTE: 20210316: Same issue as python3.5 immediately below; suggest handled by same maintainer. (lamby) -- python3.5 (Anton Gladky) View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] Add end-of-life marking for stretch for CVE-2021-28089 and CVE-2021-28090

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e8103551 by Salvatore Bonaccorso at 2021-03-16T16:50:33+01:00 Add end-of-life marking for stretch for CVE-2021-28089 and CVE-2021-28090 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add tor to dsa-needed list

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dc7adc82 by Salvatore Bonaccorso at 2021-03-16T16:49:03+01:00 Add tor to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Further update CVE-2020-27844 status

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a575ed36 by Salvatore Bonaccorso at 2021-03-16T16:40:08+01:00 Further update CVE-2020-27844 status As Emilio has found this never affected an upstream tagged version nor a Debian released

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-280{89,90}/tor

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4811185e by Salvatore Bonaccorso at 2021-03-16T16:34:51+01:00 Add CVE-2021-280{89,90}/tor - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: reference work on shadow

2021-03-16 Thread Sylvain Beucler
-needed.txt = @@ -114,6 +114,9 @@ ruby-kaminari -- salt (Utkarsh) -- +shadow (Sylvain Beucler) + NOTE: 20210316: found new CVE, discussing with secteam +-- shiro NOTE: 20200920: WIP NOTE: 20200928: Still awaiting reponse to request for assistance sent

[Git][security-tracker-team/security-tracker][master] 2 commits: NFUs

2021-03-16 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 1dc92906 by Moritz Muehlenhoff at 2021-03-16T14:22:40+01:00 NFUs - - - - - 2326b6c9 by Moritz Muehlenhoff at 2021-03-16T14:23:39+01:00 NFU - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2020-27844/openjpeg2 n/a on buster & stretch

2021-03-16 Thread Emilio Pozuelo Monfort
) = data/dla-needed.txt = @@ -72,11 +72,6 @@ opendmarc NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto) NOTE: 20210104: wait for other CVEs (abhijith) -- -openjpeg2 (Emilio) - NOTE: 20210316: CVE-2020-27844

[Git][security-tracker-team/security-tracker][master] lts: take openjpeg2

2021-03-16 Thread Emilio Pozuelo Monfort
/dla-needed.txt = @@ -72,7 +72,7 @@ opendmarc NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto) NOTE: 20210104: wait for other CVEs (abhijith) -- -openjpeg2 +openjpeg2 (Emilio) NOTE: 20210316: CVE-2020-27844.patch exists in source

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage squid3 for stretch LTS (CVE-2020-25097 & CVE-2021-28116).

2021-03-16 Thread Chris Lamb
isit later (Beuc) -- +squid3 + NOTE: 20210316: Patch is for squid 4.0, but vulnerable to in CVE-2020-25097 in src/url.cc. (lamby) + NOTE: 20210316: Also check CVE-2021-28116. (lamby) +-- subversion (Thorsten Alteholz) NOTE: 20210307: solving build problems (on IPv6 only host) -- View it

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage ruby-activerecord-session-store for stretch LTS (CVE-2019-25025).

2021-03-16 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e2933b5 by Chris Lamb at 2021-03-16T11:02:15+00:00 data/dla-needed.txt: Triage ruby-activerecord-session-store for stretch LTS (CVE-2019-25025). - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Triage CVE-2020-8031 in open-build-service for stretch LTS>

2021-03-16 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: dbc0ad0a by Chris Lamb at 2021-03-16T10:59:05+00:00 Triage CVE-2020-8031 in open-build-service for stretch LTS - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Triage CVE-2021-24115 for botan1.10 in stretch LTS.

2021-03-16 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: fa9460ce by Chris Lamb at 2021-03-16T10:56:30+00:00 Triage CVE-2021-24115 for botan1.10 in stretch LTS. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Triage CVE-2021-20248, CVE-2021-20249, CVE-2021-20266 & CVE-2021-20271 for rpm in stretch LTS.

2021-03-16 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 44895e80 by Chris Lamb at 2021-03-16T10:53:48+00:00 Triage CVE-2021-20248, CVE-2021-20249, CVE-2021-20266 CVE-2021-20271 for rpm in stretch LTS. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage openjpeg2 for stretch LTS (CVE-2020-27844).

2021-03-16 Thread Chris Lamb
: = data/dla-needed.txt = @@ -72,6 +72,11 @@ opendmarc NOTE: 20201217: patch for CVE-2020-12460 has become available (roberto) NOTE: 20210104: wait for other CVEs (abhijith) -- +openjpeg2 + NOTE: 20210316: CVE-2020-27844.patch exists

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage python2.7 for stretch LTS (CVE-2021-23336).

2021-03-16 Thread Chris Lamb
: = data/dla-needed.txt = @@ -76,6 +76,9 @@ php-pear -- pillow (Abhijith PA) -- +python2.7 + NOTE: 20210316: Same issue as python3.5 immediately below; suggest handled by same maintainer. (lamby) +-- python3.5 (Anton Gladky) NOTE

[Git][security-tracker-team/security-tracker][master] Revert "Track qtwebengine-opensource-src for CVE-2021-21193"

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b735e66b by Salvatore Bonaccorso at 2021-03-16T09:28:15+01:00 Revert Track qtwebengine-opensource-src for CVE-2021-21193 This reverts commit 7a68d005eb91281aa3c1ca828a6f36502fc4763e. - - - -

[Git][security-tracker-team/security-tracker][master] automatic update

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 085d9a28 by security tracker role at 2021-03-16T08:10:24+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 5 commits: Add CVE-2021-20283/moodle

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6705c661 by Salvatore Bonaccorso at 2021-03-16T08:21:54+01:00 Add CVE-2021-20283/moodle - - - - - 5a2ac639 by Salvatore Bonaccorso at 2021-03-16T08:22:26+01:00 Add CVE-2021-20282/moodle - - -

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-20284/binutils

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5f70fa9c by Salvatore Bonaccorso at 2021-03-16T08:20:52+01:00 Add CVE-2021-20284/binutils - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-28210/edk2

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f7a9b503 by Salvatore Bonaccorso at 2021-03-16T08:19:34+01:00 Add CVE-2021-28210/edk2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-202-28211/edk2

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b576274e by Salvatore Bonaccorso at 2021-03-16T08:17:39+01:00 Add CVE-202-28211/edk2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3443/jasper

2021-03-16 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 246f11c9 by Salvatore Bonaccorso at 2021-03-16T08:12:45+01:00 Add CVE-2021-3443/jasper - - - - - 1 changed file: - data/CVE/list Changes: =