[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-30847 as not-affected in Debian

2023-10-19 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 2e7dd3e1 by Anton Gladky at 2023-10-20T06:51:42+02:00 Mark CVE-2023-30847 as not-affected in Debian - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dsa-needed: add and claim roundcube

2023-10-19 Thread Sebastien Delafond (@seb)
Sebastien Delafond pushed to branch master at Debian Security Tracker / security-tracker Commits: 39cb3fed by Sébastien Delafond at 2023-10-20T06:31:09+02:00 dsa-needed: add and claim roundcube - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] bookworm/bullseye triage

2023-10-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 881f1876 by Moritz Mühlenhoff at 2023-10-20T00:02:27+02:00 bookworm/bullseye triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] new apache2 issues

2023-10-19 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fde6a13 by Moritz Mühlenhoff at 2023-10-19T23:36:45+02:00 new apache2 issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove CVE-2023-1989 from DLA-3623-1

2023-10-19 Thread Ben Hutchings (@benh)
Ben Hutchings pushed to branch master at Debian Security Tracker / security-tracker Commits: 458df432 by Ben Hutchings at 2023-10-19T23:25:01+02:00 Remove CVE-2023-1989 from DLA-3623-1 CVE-2023-1989 was already fixed in an earlier upload of linux-5.10, and has since been reverted and re-done

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-20588/xen via unstable (XSA-439)

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dc8875da by Salvatore Bonaccorso at 2023-10-19T22:52:36+02:00 Track fixed version for CVE-2023-20588/xen via unstable (XSA-439) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process some more NFUs

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 81d9013a by Salvatore Bonaccorso at 2023-10-19T22:47:53+02:00 Process some more NFUs Not done yet the new Oracle MySQL CVEs as they need cross-checking with the Oracle CPU advsory. - - - - -

[Git][security-tracker-team/security-tracker][master] Process some more NFUs

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c50697f4 by Salvatore Bonaccorso at 2023-10-19T22:26:13+02:00 Process some more NFUs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-38703/pjproject

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a4c1e18b by Salvatore Bonaccorso at 2023-10-19T22:14:23+02:00 Add CVE-2023-38703/pjproject - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a242378 by security tracker role at 2023-10-19T20:11:38+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add for now RT4 and RT5 to dsa-needed list

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1f3af91d by Salvatore Bonaccorso at 2023-10-19T22:01:05+02:00 Add for now RT4 and RT5 to dsa-needed list Need a second evaluation if a DSA is warranted yet. - - - - - 1 changed file: -

[Git][security-tracker-team/security-tracker][master] Add new RT issues

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b4c851c by Salvatore Bonaccorso at 2023-10-19T21:58:24+02:00 Add new RT issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-37543 after feedback from upstream

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3288ad78 by Salvatore Bonaccorso at 2023-10-19T21:27:38+02:00 Update status for CVE-2023-37543 after feedback from upstream It is a very unfortunate situation that the fix is not pinpointed.

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2023-46009/gifsicle

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7927e1b7 by Salvatore Bonaccorso at 2023-10-19T18:14:56+02:00 Update information on CVE-2023-46009/gifsicle - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for two more exim4 issues as fixed via unstable upload

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 36e82f81 by Salvatore Bonaccorso at 2023-10-19T18:12:34+02:00 Track fixed version for two more exim4 issues as fixed via unstable upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-44487/h2o

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bc30802d by Salvatore Bonaccorso at 2023-10-19T18:08:56+02:00 Add Debian bug reference for CVE-2023-44487/h2o - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-46228/zchunk

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c40ec64d by Salvatore Bonaccorso at 2023-10-19T18:07:46+02:00 Add Debian bug reference for CVE-2023-46228/zchunk - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-44487/netty

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8cd274fb by Salvatore Bonaccorso at 2023-10-19T18:06:51+02:00 Add Debian bug reference for CVE-2023-44487/netty - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2023-45145/redis

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b04cb841 by Salvatore Bonaccorso at 2023-10-19T18:05:51+02:00 Track fixed version via unstable for CVE-2023-45145/redis - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-45803

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fe4d9e94 by Salvatore Bonaccorso at 2023-10-19T16:06:38+02:00 Add Debian bug reference for CVE-2023-45803 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-45683

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e1d113d by Salvatore Bonaccorso at 2023-10-19T16:00:43+02:00 Add Debian bug reference for CVE-2023-45683 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-44981/zookeeper

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b4f4d2e by Salvatore Bonaccorso at 2023-10-19T15:59:43+02:00 Add Debian bug reference for CVE-2023-44981/zookeeper - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2023-45145/redis

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b71d0727 by Salvatore Bonaccorso at 2023-10-19T15:58:46+02:00 Add Debian bug reference for CVE-2023-45145/redis - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark for now slurm-wlm in bullseye as postponed

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9f5b70b4 by Salvatore Bonaccorso at 2023-10-19T15:41:08+02:00 Mark for now slurm-wlm in bullseye as postponed The patch is quite intrusive, it was more important to address CVE-2023-41914 for

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-45683/golang-github-crewjam-saml

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ae56831 by Salvatore Bonaccorso at 2023-10-19T15:32:13+02:00 Add CVE-2023-45683/golang-github-crewjam-saml - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-45803/python-urllib3

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a0fc7dec by Salvatore Bonaccorso at 2023-10-19T15:29:06+02:00 Add CVE-2023-45803/python-urllib3 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Slightly redact note for regression fixing commit as commit is in 1.25

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6730491c by Salvatore Bonaccorso at 2023-10-19T15:07:46+02:00 Slightly redact note for regression fixing commit as commit is in 1.25 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add pmix to dsa-needed list

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: faa77a4b by Salvatore Bonaccorso at 2023-10-19T14:57:22+02:00 Add pmix to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add slurm-llnl for CVE-2023-41914

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 945c1be1 by Salvatore Bonaccorso at 2023-10-19T14:55:51+02:00 Add slurm-llnl for CVE-2023-41914 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-28999/nextcloud-desktop via unstable

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 67ceb4c7 by Salvatore Bonaccorso at 2023-10-19T14:49:10+02:00 Track fixed version for CVE-2023-28999/nextcloud-desktop via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] lts: take openjdk-11

2023-10-19 Thread Emilio Pozuelo Monfort (@pochu)
/dla-needed.txt = @@ -157,6 +157,9 @@ opendkim NOTE: 20230821: Added by Front-Desk (ta) NOTE: 20231006: Unfixed upstream as of today. (spwhitton) -- +openjdk-11 (Emilio) + NOTE: 20231019: Added by pochu +-- osslsigncode NOTE: 20230925: Added by Front

[Git][security-tracker-team/security-tracker][master] Add additonal reference for tracker-minier sandboxing escape issue

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 202a928b by Salvatore Bonaccorso at 2023-10-19T11:32:16+02:00 Add additonal reference for tracker-minier sandboxing escape issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-45145/redis

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0c3aea25 by Salvatore Bonaccorso at 2023-10-19T11:03:50+02:00 Add CVE-2023-45145/redis - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f6438ca by Salvatore Bonaccorso at 2023-10-19T11:03:22+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-46228/zchunk

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 57b6e16f by Salvatore Bonaccorso at 2023-10-19T10:55:02+02:00 Add CVE-2023-46228/zchunk - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d21d5e2 by Salvatore Bonaccorso at 2023-10-19T10:51:37+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-10-19 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d3577dcc by security tracker role at 2023-10-19T08:12:12+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list