[Git][security-tracker-team/security-tracker][master] Add CVE-2023-2260{4,5,6,7,8,9}/binutils

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e6b916e8 by Salvatore Bonaccorso at 2023-02-07T08:53:53+01:00 Add CVE-2023-2260{4,5,6,7,8,9}/binutils - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-22603/binutils

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a219cd6 by Salvatore Bonaccorso at 2023-02-07T08:47:16+01:00 Add CVE-2023-22603/binutils - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-23498/grafana

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c9b4374 by Salvatore Bonaccorso at 2023-02-07T08:40:58+01:00 Add CVE-2022-23498/grafana - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2023-0415 (wireshark) is not affecting buster.

2023-02-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 97153541 by Tobias Frost at 2023-02-07T08:38:00+01:00 CVE-2023-0415 (wireshark) is not affecting buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3310-1 for xorg-server

2023-02-06 Thread Thorsten Alteholz (@alteholz)
-2022-4729 CVE-2022-4730} [buster] - graphite-web 1.1.4-3+deb10u2 = data/dla-needed.txt = @@ -350,8 +350,6 @@ xfig (gladk) NOTE: 20230105: Follow fixes from bullseye 11.6 (Beuc/front-desk) NOTE: 20230206: VCS

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-20938/linux

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a21e4ab4 by Salvatore Bonaccorso at 2023-02-07T07:55:08+01:00 Add CVE-2023-20938/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-0494/xorg-server

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e51b47c1 by Salvatore Bonaccorso at 2023-02-07T07:17:44+01:00 Add CVE-2023-0494/xorg-server - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] claim xorg-server

2023-02-06 Thread Thorsten Alteholz (@alteholz)
-needed.txt = @@ -350,6 +350,8 @@ xfig (gladk) NOTE: 20230105: Follow fixes from bullseye 11.6 (Beuc/front-desk) NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/xfig.git -- +xorg-server (Thorsten Alteholz) +-- xrdp NOTE: 20221225: Programming

[Git][security-tracker-team/security-tracker][master] Tentatively take apr-util and apr from dsa-needed list

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5957612b by Salvatore Bonaccorso at 2023-02-07T06:29:23+01:00 Tentatively take apr-util and apr from dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Take haproxy from dsa-needed list

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dfdeffe by Salvatore Bonaccorso at 2023-02-07T06:24:35+01:00 Take haproxy from dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] add p0 reference

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 728807db by Moritz Muehlenhoff at 2023-02-06T22:58:48+01:00 add p0 reference - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-42330/xen via unstable

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a81045a9 by Salvatore Bonaccorso at 2023-02-06T22:28:50+01:00 Track fixed version for CVE-2022-42330/xen via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for three fava issues fixed via unstable

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a7c1252c by Salvatore Bonaccorso at 2023-02-06T22:25:38+01:00 Track fixed version for three fava issues fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: Add meta-information

2023-02-06 Thread Anton Gladky (@gladk)
= @@ -94,6 +94,9 @@ golang-yaml.v2 NOTE: 20230125: Special attention: limited support; requires rebuilding reverse build dependencies (though recent bullseye updates didn't). -- heimdal (Helmut Grohne) + NOTE: 20230206: Programming language: C + NOTE

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3309-1 for graphite-web

2023-02-06 Thread Chris Lamb (@lamby)
.git NOTE: 20230125: Special attention: limited support; requires rebuilding reverse build dependencies (though recent bullseye updates didn't). -- -graphite-web (Chris Lamb) - NOTE: 20221229: Programming language: Python. - NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages

[Git][security-tracker-team/security-tracker][master] Add three new CVEs for zammad: CVE-2022-4802{1,2,3}

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 316b7987 by Salvatore Bonaccorso at 2023-02-06T22:02:06+01:00 Add three new CVEs for zammad: CVE-2022-4802{1,2,3} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 005711b1 by Salvatore Bonaccorso at 2023-02-06T22:01:26+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-0687/glibc

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 56ed23ae by Salvatore Bonaccorso at 2023-02-06T21:56:29+01:00 Add CVE-2023-0687/glibc - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c5fc4428 by Salvatore Bonaccorso at 2023-02-06T21:35:47+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a4a6839 by security tracker role at 2023-02-06T20:10:25+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2021-23385/flask-security

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a37aca57 by Salvatore Bonaccorso at 2023-02-06T21:05:47+01:00 Update information for CVE-2021-23385/flask-security - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3308-1 for webkit2gtk

2023-02-06 Thread Emilio Pozuelo Monfort (@pochu)
@@ trafficserver NOTE: 20230202: Note recent DLA-3279-1 update. Removed notes (2d9f50586010) suggest CVE-2022-31779 may have already been investigated. (lamby) NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/trafficserver.git -- -webkit2gtk (Emilio) - NOTE: 20230203: Programming

[Git][security-tracker-team/security-tracker][master] NFUs

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 00d88108 by Moritz Muehlenhoff at 2023-02-06T17:52:59+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-0414 (wireshark) is not affecting buster.

2023-02-06 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: d895a354 by Tobias Frost at 2023-02-06T17:23:27+01:00 CVE-2023-0414 (wireshark) is not affecting buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] bullseye triage

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 891d9dab by Moritz Muehlenhoff at 2023-02-06T16:53:15+01:00 bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] webkit2gtk DSA-5340-1 and wpewebkit DSA-5341-1

2023-02-06 Thread Alberto Garcia (@berto)
Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker Commits: 1634dc77 by Alberto Garcia at 2023-02-06T16:32:30+01:00 webkit2gtk DSA-5340-1 and wpewebkit DSA-5341-1 - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] lts: CVE-2023-23456/upx-ucl no-dsa on buster

2023-02-06 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 8a60123f by Emilio Pozuelo Monfort at 2023-02-06T16:13:06+01:00 lts: CVE-2023-23456/upx-ucl no-dsa on buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3307-1 for openjdk-11

2023-02-06 Thread Emilio Pozuelo Monfort (@pochu)
(Emilio) - NOTE: 20230123: Programming language: Java. - NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/openjdk-11.git --- php-cas NOTE: 20221105: Programming language: PHP. NOTE: 20221105: The fix is not backwards compatible. Should be investigated further whether this issue

[Git][security-tracker-team/security-tracker][master] LTS: add spip to dla-needed.txt

2023-02-06 Thread Emilio Pozuelo Monfort (@pochu)
upstream ticket. RedHat issued notabug. Unfixed in stable and unstable. Don't run sox on untrusted input. (Helmut) -- +spip + NOTE: 20230206: Programming language: PHP. +-- sssd NOTE: 20230131: Programming language: C. NOTE: 20230205: VCS: https://salsa.debian.org/lts-team/packages/sssd.git

[Git][security-tracker-team/security-tracker][master] LTS: claim heimdal

2023-02-06 Thread Helmut Grohne (@helmutg)
= @@ -97,6 +97,8 @@ graphite-web (Chris Lamb) NOTE: 20221229: Programming language: Python. NOTE: 20230206: VCS: https://salsa.debian.org/lts-team/packages/graphite-web.git -- +heimdal (Helmut Grohne) +-- imagemagick (Roberto C. Sánchez) NOTE: 20220904

[Git][security-tracker-team/security-tracker][master] zabbix fixed in sid

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c2f6127 by Moritz Muehlenhoff at 2023-02-06T12:47:49+01:00 zabbix fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFU

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 725c1659 by Moritz Muehlenhoff at 2023-02-06T12:46:49+01:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] lts: take webkit2gtk

2023-02-06 Thread Emilio Pozuelo Monfort (@pochu)
/dla-needed.txt = @@ -338,8 +338,8 @@ trafficserver NOTE: 20230202: Note recent DLA-3279-1 update. Removed notes (2d9f50586010) suggest CVE-2022-31779 may have already been investigated. (lamby) NOTE: 20230206: VCS: https://salsa.debian.org/lts-team

[Git][security-tracker-team/security-tracker][master] NFU

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: d9ddbc94 by Moritz Muehlenhoff at 2023-02-06T09:36:15+01:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] puppet-module-puppetlabs-apt fixed in sid

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 93ad7f8c by Moritz Muehlenhoff at 2023-02-06T09:34:48+01:00 puppet-module-puppetlabs-apt fixed in sid - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] ruby-rails-html-sanitizer fixed in sid

2023-02-06 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 30285ea2 by Moritz Muehlenhoff at 2023-02-06T09:34:03+01:00 ruby-rails-html-sanitizer fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-02-06 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 272931f4 by security tracker role at 2023-02-06T08:10:13+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list