[Git][security-tracker-team/security-tracker][master] Add CVE-2022-23552 and CVE-2022-39324 for grafana

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b62e5b62 by Salvatore Bonaccorso at 2023-01-31T08:47:21+01:00 Add CVE-2022-23552 and CVE-2022-39324 for grafana - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-2392{1,2,3}/moodle

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 83ff8ab0 by Salvatore Bonaccorso at 2023-01-31T08:31:55+01:00 Add CVE-2023-2392{1,2,3}/moodle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add a note for rails

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 0da904c6 by Utkarsh Gupta at 2023-01-31T06:20:40+05:30 Add a note for rails - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Take ruby-sidekiq and libapache2-mod-auth-mellon

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 305e3012 by Utkarsh Gupta at 2023-01-31T06:07:26+05:30 Take ruby-sidekiq and libapache2-mod-auth-mellon - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3303-1 for ruby-git

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: be53887b by Utkarsh Gupta at 2023-01-31T03:50:15+05:30 Reserve DLA-3303-1 for ruby-git - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3302-1 for nova

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
-team.pages.debian.net/wiki/TestSuites/nodejs.html -- -nova - NOTE: 20230130: Same issue in cinder, glance and nova packages: claim all three? (lamby) - NOTE: 20230130: Programming language: Python - NOTE: 20230130: VCS: https://salsa.debian.org/openstack-team/services/nova - NOTE: 20230130: Testsuite: https

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3301-1 for cinder

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
/ceph.git -- -cinder - NOTE: 20230130: Same issue in cinder, glance and nova packages: claim all three? (lamby) - NOTE: 20230130: Programming language: Python - NOTE: 20230130: VCS: https://salsa.debian.org/lts-team/packages/cinder.git --- consul NOTE: 20221031: Programming language: Go

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3300-1 for glance

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
serious (gladk). -- -glance - NOTE: 20230130: Same issue in cinder, glance and nova packages: claim all three? (lamby) - NOTE: 20230130: Programming language: Python - NOTE: 20230130: VCS: https://salsa.debian.org/lts-team/packages/glance.git --- golang-1.11 NOTE: 20220916: Programming language

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3298-1 for ruby-rack

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 66debdde by Utkarsh Gupta at 2023-01-31T03:20:06+05:30 Reserve DLA-3298-1 for ruby-rack - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3297-1 for tiff

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: b87f2096 by Utkarsh Gupta at 2023-01-31T03:07:20+05:30 Reserve DLA-3297-1 for tiff - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3296-1 for libhtml-stripscripts-perl

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 72ce3811 by Utkarsh Gupta at 2023-01-31T03:01:20+05:30 Reserve DLA-3296-1 for libhtml-stripscripts-perl - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3295-1 for node-moment

2023-01-30 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 4abda771 by Utkarsh Gupta at 2023-01-31T02:54:50+05:30 Reserve DLA-3295-1 for node-moment - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-0240/linux

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 26324005 by Salvatore Bonaccorso at 2023-01-30T21:42:57+01:00 Add CVE-2023-0240/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Meta-Information to some newly added packages

2023-01-30 Thread Anton Gladky (@gladk)
: = data/dla-needed.txt = @@ -42,6 +42,8 @@ ceph -- cinder NOTE: 20230130: Same issue in cinder, glance and nova packages: claim all three? (lamby) + NOTE: 20230130: Programming language: Python + NOTE: 20230130: VCS: https://salsa.debian.org/lts-team

[Git][security-tracker-team/security-tracker][master] Process one NFU

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dd6b0921 by Salvatore Bonaccorso at 2023-01-30T21:21:18+01:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9229fd15 by security tracker role at 2023-01-30T20:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Restore fixing information for CVE-2021-35368

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c0eaa50f by Salvatore Bonaccorso at 2023-01-30T20:41:23+01:00 Restore fixing information for CVE-2021-35368 - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Change VCS for libgit2

2023-01-30 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: de321af1 by Anton Gladky at 2023-01-30T19:54:25+01:00 Change VCS for libgit2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3294-1 for libarchive

2023-01-30 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 172027fc by Thorsten Alteholz at 2023-01-30T19:39:21+01:00 Reserve DLA-3294-1 for libarchive - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3293-1 for modsecurity-crs

2023-01-30 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 709f5572 by Tobias Frost at 2023-01-30T19:15:37+01:00 Reserve DLA-3293-1 for modsecurity-crs - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage redis for buster LTS (CVE-2022-35977)

2023-01-30 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 0e85f946 by Chris Lamb at 2023-01-30T10:14:41-08:00 data/dla-needed.txt: Triage redis for buster LTS (CVE-2022-35977) - - - - - a64db5a0 by Chris Lamb at 2023-01-30T10:14:47-08:00 data/dla-needed.txt:

[Git][security-tracker-team/security-tracker][master] bugnums

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e6d7b5b by Moritz Mühlenhoff at 2023-01-30T19:02:12+01:00 bugnums - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage cinder, glance and nova for buster LTS (CVE-2022-47951)

2023-01-30 Thread Chris Lamb (@lamby)
= data/dla-needed.txt = @@ -40,6 +40,9 @@ ceph NOTE: 20221130: https://lists.debian.org/debian-lts/2022/11/msg00025.html (zigo/maintainer) NOTE: 20230111: VCS: https://salsa.debian.org/lts-team/packages/ceph.git -- +cinder + NOTE: 20230130

[Git][security-tracker-team/security-tracker][master] libzen spu

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f27ad5bf by Moritz Mühlenhoff at 2023-01-30T18:21:29+01:00 libzen spu - - - - - 1 changed file: - data/next-point-update.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream commit reference for CVE-2023-23627/ruby-sanitize

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 32943e9b by Salvatore Bonaccorso at 2023-01-30T18:08:43+01:00 Add upstream commit reference for CVE-2023-23627/ruby-sanitize - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2022-48285

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c6207ecd by Salvatore Bonaccorso at 2023-01-30T18:06:24+01:00 Add upstream tag information for CVE-2022-48285 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] NFU

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 82b1acf7 by Moritz Muehlenhoff at 2023-01-30T16:54:38+01:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFU

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d8a2ee0 by Moritz Muehlenhoff at 2023-01-30T16:50:29+01:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] twisted fixed in sid

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: bd41bcf8 by Moritz Muehlenhoff at 2023-01-30T16:44:58+01:00 twisted fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new opusfile issue

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cbb2edf8 by Moritz Muehlenhoff at 2023-01-30T16:30:44+01:00 new opusfile issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] node-qs: Add note for CVE-2022-24999.

2023-01-30 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 44790b81 by Guilhem Moulin at 2023-01-30T16:28:20+01:00 node-qs: Add note for CVE-2022-24999. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] new pgpool2 issue

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 1deaedf7 by Moritz Muehlenhoff at 2023-01-30T16:13:28+01:00 new pgpool2 issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new ruby-sanitize issue

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ca94b5d by Moritz Muehlenhoff at 2023-01-30T16:09:12+01:00 new ruby-sanitize issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] two gitlab n/a

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f4264848 by Moritz Muehlenhoff at 2023-01-30T15:48:39+01:00 two gitlab n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b662276 by Moritz Muehlenhoff at 2023-01-30T15:46:14+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new node-jszip issue

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e5eea4e8 by Moritz Muehlenhoff at 2023-01-30T15:34:46+01:00 new node-jszip issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] tar non issue

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 37eb5ed5 by Moritz Muehlenhoff at 2023-01-30T14:37:24+01:00 tar non issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 1021ab02 by Moritz Muehlenhoff at 2023-01-30T14:35:08+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] drop RUSTSEC-2023-0002 (retracted, possibly because it's for a new security...

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e7e07a25 by Moritz Muehlenhoff at 2023-01-30T13:17:55+01:00 drop RUSTSEC-2023-0002 (retracted, possibly because its for a new security feature, not vulnerability) - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] bullseye triage

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e5dd925 by Moritz Muehlenhoff at 2023-01-30T13:14:37+01:00 bullseye triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: LTS: claim node-qs in dla-needed.txt

2023-01-30 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 0250004d by Guilhem Moulin at 2023-01-30T12:05:26+01:00 LTS: claim node-qs in dla-needed.txt - - - - - d137ffdb by Guilhem Moulin at 2023-01-30T12:05:31+01:00 LTS: claim node-url-parse in

[Git][security-tracker-team/security-tracker][master] bullseye triage

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 11ade977 by Moritz Mühlenhoff at 2023-01-30T11:55:30+01:00 bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: Add note for node-css-what.

2023-01-30 Thread Guilhem Moulin (@guilhem)
: = data/dla-needed.txt = @@ -163,6 +163,7 @@ nheko (Abhijith PA) -- node-css-what NOTE: 20221031: Programming language: Javascript. + NOTE: 20230130: Module has been rewritten in Typescript since Buster released (guilhem). -- node-got NOTE: 2022

[Git][security-tracker-team/security-tracker][master] also track nvidia-open-gpu-kernel-modules for recent Nvidia issues

2023-01-30 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d0756d7b by Moritz Muehlenhoff at 2023-01-30T09:34:11+01:00 also track nvidia-open-gpu-kernel-modules for recent Nvidia issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2023-01-30 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 75ee869b by security tracker role at 2023-01-30T08:10:16+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list