[Git][security-tracker-team/security-tracker][master] Track fixed version for firefox-esr via unstable

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8ff7a103 by Salvatore Bonaccorso at 2024-01-24T07:47:23+01:00 Track fixed version for firefox-esr via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for chromium via unstable

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 637520d7 by Salvatore Bonaccorso at 2024-01-24T07:45:49+01:00 Track fixed version for chromium via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add chromium to dsa-needed list

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a4724ae2 by Salvatore Bonaccorso at 2024-01-24T07:40:55+01:00 Add chromium to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add batch of new chromium CVEs

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f7768b66 by Salvatore Bonaccorso at 2024-01-24T07:38:33+01:00 Add batch of new chromium CVEs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixes for thunderbird via unstable

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a949194 by Salvatore Bonaccorso at 2024-01-24T07:34:03+01:00 Track fixes for thunderbird via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixes for firefox for mfsa2024-01 issues fixed via unstable

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5e551b8d by Salvatore Bonaccorso at 2024-01-24T05:51:13+01:00 Track fixes for firefox for mfsa2024-01 issues fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] openjdk-11 DSA

2024-01-23 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e6d156ba by Moritz Mühlenhoff at 2024-01-23T22:44:42+01:00 openjdk-11 DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-32728 for bullseye

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 95ac1b1c by Salvatore Bonaccorso at 2024-01-23T22:39:08+01:00 Update status for CVE-2023-32728 for bullseye - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add upstream commit reference for CVE-2017-20189

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a6bb8f9 by Salvatore Bonaccorso at 2024-01-23T22:34:45+01:00 Add upstream commit reference for CVE-2017-20189 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Revert back URL for CVE-2023-32725

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d15630e7 by Salvatore Bonaccorso at 2024-01-23T22:19:46+01:00 Revert back URL for CVE-2023-32725 Fixes: 36e9a77145dd (CVE-2023-32727/zabbix - buster is not affected.) - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 31822729 by Salvatore Bonaccorso at 2024-01-23T22:15:39+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove one additional whitespace

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2cfba19e by Salvatore Bonaccorso at 2024-01-23T21:59:46+01:00 Remove one additional whitespace - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-22705/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 967815e6 by Salvatore Bonaccorso at 2024-01-23T21:57:24+01:00 Add CVE-2024-22705/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-51043/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7482a156 by Salvatore Bonaccorso at 2024-01-23T21:53:31+01:00 Add CVE-2023-51043/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-51042/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 03cf by Salvatore Bonaccorso at 2024-01-23T21:48:49+01:00 Add CVE-2023-51042/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-46343/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2118c5f4 by Salvatore Bonaccorso at 2024-01-23T21:40:16+01:00 Add CVE-2023-46343/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-23848/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 619309dd by Salvatore Bonaccorso at 2024-01-23T21:34:08+01:00 Add CVE-2024-23848/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-23849/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b4078026 by Salvatore Bonaccorso at 2024-01-23T21:25:32+01:00 Add CVE-2024-23849/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-23850/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 78b69305 by Salvatore Bonaccorso at 2024-01-23T21:22:53+01:00 Add CVE-2024-23850/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-23851/linux

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: baaeafb5 by Salvatore Bonaccorso at 2024-01-23T21:18:38+01:00 Add CVE-2024-23851/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ff81e261 by security tracker role at 2024-01-23T20:13:30+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Correct entry for CVE-2023-29159/starlette

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: adc25532 by Salvatore Bonaccorso at 2024-01-23T20:58:15+01:00 Correct entry for CVE-2023-29159/starlette - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for xorg-server update

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6fb5a281 by Salvatore Bonaccorso at 2024-01-23T20:39:31+01:00 Reserve DSA number for xorg-server update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Fix indentation in entries

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3f6b7ba8 by Salvatore Bonaccorso at 2024-01-23T20:38:57+01:00 Fix indentation in entries - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] s/ttps/https

2024-01-23 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 016eb657 by Tobias Frost at 2024-01-23T20:14:20+01:00 s/ttps/https - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-32727/zabbix - buster is not affected.

2024-01-23 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: 36e9a771 by Tobias Frost at 2024-01-23T20:13:31+01:00 CVE-2023-32727/zabbix - buster is not affected. The vulnerability is a format-string vulnerability, a user provided input (dst - intented to be a

[Git][security-tracker-team/security-tracker][master] CVE-2023-32728/zabbix (buster) vulnerable code introduced later.

2024-01-23 Thread Tobias Frost (@tobi)
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker Commits: c7631825 by Tobias Frost at 2024-01-23T18:59:00+01:00 CVE-2023-32728/zabbix (buster) vulnerable code introduced later. Vulnerable feature was introduced with this ticket:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3716-1 for ruby-httparty

2024-01-23 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: e41e5bb7 by Chris Lamb at 2024-01-23T09:02:36-08:00 Reserve DLA-3716-1 for ruby-httparty - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3715-1 for jinja2

2024-01-23 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 92240195 by Chris Lamb at 2024-01-23T08:53:12-08:00 Reserve DLA-3715-1 for jinja2 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add thunderbird issues from mfsa2024-04

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fbdf9fef by Salvatore Bonaccorso at 2024-01-23T16:56:17+01:00 Add thunderbird issues from mfsa2024-04 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add firefox-esr and thunderbird to dsa-needed list

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c37ae22 by Salvatore Bonaccorso at 2024-01-23T16:53:21+01:00 Add firefox-esr and thunderbird to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add firefox-esr issues from mfsa2024-02

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aa9fe727 by Salvatore Bonaccorso at 2024-01-23T16:51:11+01:00 Add firefox-esr issues from mfsa2024-02 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add firefox issues from mfsa204-01

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: da57220d by Salvatore Bonaccorso at 2024-01-23T16:48:03+01:00 Add firefox issues from mfsa204-01 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-01-23 Thread Sylvain Beucler (@beuc)
tasks, but all bugs are minor so far (Beuc) + NOTE: 20240123: Backport patches, report duplicate to MITRE (Beuc) -- cairosvg NOTE: 20230323: Added by Front-Desk (gladk) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] NFUs

2024-01-23 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 701fab4b by Moritz Muehlenhoff at 2024-01-23T11:47:30+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] gitlab fixed in sid

2024-01-23 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5599f978 by Moritz Muehlenhoff at 2024-01-23T11:41:59+01:00 gitlab fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim rear

2024-01-23 Thread Abhijith PA (@abhijith)
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: e1dc196f by Abhijith PA at 2024-01-23T16:09:26+05:30 data/dla-needed.txt: Claim rear - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Process some more NFUs

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c70bc3a7 by Salvatore Bonaccorso at 2024-01-23T10:13:12+01:00 Process some more NFUs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some more NFUs

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0540a760 by Salvatore Bonaccorso at 2024-01-23T09:48:48+01:00 Process some more NFUs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-23342/python-ecdsa

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cfcf513f by Salvatore Bonaccorso at 2024-01-23T09:40:22+01:00 Add CVE-2024-23342/python-ecdsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process one NFU

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dd48cbc8 by Salvatore Bonaccorso at 2024-01-23T09:38:15+01:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 30adcb2e by Salvatore Bonaccorso at 2024-01-23T09:36:28+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] mark spring as n/a, regardless of the affected upstream version we only have 4.x anyway

2024-01-23 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 6babd916 by Moritz Muehlenhoff at 2024-01-23T09:29:45+01:00 mark spring as n/a, regardless of the affected upstream version we only have 4.x anyway - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] new AMD GPU issue

2024-01-23 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 8ee4783e by Moritz Muehlenhoff at 2024-01-23T09:24:03+01:00 new AMD GPU issue While related fixes might also be needed in the Linux drivers, the gist of the fixes will be in the firmware, so

[Git][security-tracker-team/security-tracker][master] automatic update

2024-01-23 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 53671dca by security tracker role at 2024-01-23T08:11:54+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list