[Git][security-tracker-team/security-tracker][master] Take sendmail

2024-03-16 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: c7a6472c by Bastien Roucariès at 2024-03-16T21:23:20+00:00 Take sendmail - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add more comment on php-composer

2024-03-16 Thread @rouca
(rouca) NOTE: 20240315: DSA 5632-1 is out (Beuc/front-desk) + NOTE: 20240316: Ask clarification about some fixes on DSA 5632-1 without CVE -- curl (rouca) NOTE: 20231229: Added by Front-Desk (lamby) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] CVE-2024-24821

2024-03-16 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 8d90a5cd by Bastien Roucariès at 2024-03-16T20:51:51+00:00 CVE-2024-24821 InstalledVersion feature was created in 2.0 so buster is not affected - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] NFUs

2024-03-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c94f8051 by Moritz Muehlenhoff at 2024-03-16T21:17:48+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e42d6681 by security tracker role at 2024-03-16T20:12:40+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-27043/python*: sync with stable triage

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8d1975f9 by Sylvain Beucler at 2024-03-16T19:28:53+01:00 CVE-2023-27043/python*: sync with stable triage - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim libvirt in dla-needed.txt

2024-03-16 Thread Guilhem Moulin (@guilhem)
: 20240316: Added by Front-Desk (Beuc) NOTE: 20240316: A few years of minor vulnerabilities piled up; NOTE: 20240316: coordinate with stable/oldstable to fix them uniformly (Beuc/front-desk) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-26540/cimg: buster postponed, reference patch

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 8cea774f by Sylvain Beucler at 2024-03-16T13:36:03+01:00 CVE-2024-26540/cimg: buster postponed, reference patch - - - - - 246888dc by Sylvain Beucler at 2024-03-16T13:44:52+01:00

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-2496/libvirt: buster postponed

2024-03-16 Thread Sylvain Beucler (@beuc)
NOTE: 20240314: and bookwork. Uploads to spu and ospu should be coordinated. (roberto) -- +libvirt + NOTE: 20240316: Added by Front-Desk (Beuc) + NOTE: 20240316: A few years of minor vulnerabilities piled up; + NOTE: 20240316: coordinate with stable/oldstable to fix them uniformly (Beuc/front

[Git][security-tracker-team/security-tracker][master] CVE-2024-2467/libcrypt-openssl-rsa-perl: buster postponed

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 72788521 by Sylvain Beucler at 2024-03-16T12:52:06+01:00 CVE-2024-2467/libcrypt-openssl-rsa-perl: buster postponed - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-28318,CVE-2024-28319/gpac: buster end-of-life

2024-03-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2c12 by Sylvain Beucler at 2024-03-16T12:42:12+01:00 CVE-2024-28318,CVE-2024-28319/gpac: buster end-of-life - - - - - de17954c by Sylvain Beucler at 2024-03-16T12:42:14+01:00 intel-microcode:

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-22259/libspring-java

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a2277a69 by Salvatore Bonaccorso at 2024-03-16T11:25:15+01:00 Add CVE-2024-22259/libspring-java - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-22513/python-djangorestframework-simplejwt

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 76166ca8 by Salvatore Bonaccorso at 2024-03-16T11:18:59+01:00 Add CVE-2024-22513/python-djangorestframework-simplejwt - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2024-28859 as NFU

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 745fc863 by Salvatore Bonaccorso at 2024-03-16T11:15:30+01:00 Mark CVE-2024-28859 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-28849

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c02d9634 by Salvatore Bonaccorso at 2024-03-16T11:09:18+01:00 Add Debian bug reference for CVE-2024-28849 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2024-2467/libcrypt-openssl-rsa-perl

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c5301ac0 by Salvatore Bonaccorso at 2024-03-16T10:56:16+01:00 Add Debian bug reference for CVE-2024-2467/libcrypt-openssl-rsa-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-2496/libvirt

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 29fc8f5f by Salvatore Bonaccorso at 2024-03-16T10:18:16+01:00 Add CVE-2024-2496/libvirt - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-2467/libcrypt-openssl-rsa-perl

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dbc7270f by Salvatore Bonaccorso at 2024-03-16T10:15:15+01:00 Add CVE-2024-2467/libcrypt-openssl-rsa-perl - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-7250/iperf3

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e8b888e7 by Salvatore Bonaccorso at 2024-03-16T10:12:56+01:00 Add CVE-2023-7250/iperf3 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entries for CVE-2023-39513

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ff18e35f by Salvatore Bonaccorso at 2024-03-16T09:55:53+01:00 Remove no-dsa tagged entries for CVE-2023-39513 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2024-28862/ruby-rotp

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8367a3b0 by Salvatore Bonaccorso at 2024-03-16T09:45:31+01:00 Update information for CVE-2024-28862/ruby-rotp - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Take care of fontforge DSA, acked debdiffs

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a58abcd7 by Salvatore Bonaccorso at 2024-03-16T09:30:42+01:00 Take care of fontforge DSA, acked debdiffs - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5ca1e271 by Salvatore Bonaccorso at 2024-03-16T09:23:36+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2024-28862/ruby-rotp

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: eb16e05d by Salvatore Bonaccorso at 2024-03-16T09:22:53+01:00 Add CVE-2024-28862/ruby-rotp - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d52480e8 by security tracker role at 2024-03-16T08:12:04+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2024-27297/guix

2024-03-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1eff25cb by Salvatore Bonaccorso at 2024-03-16T09:09:10+01:00 Add fixed version for CVE-2024-27297/guix - - - - - 1 changed file: - data/CVE/list Changes: