[Git][security-tracker-team/security-tracker][master] Mark remaining edk2 issues for Jessie as EOL.

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ed18722 by Markus Koschany at 2019-03-30T13:27:34Z Mark remaining edk2 issues for Jessie as EOL. - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] CVE-2019-0757,nuget: Link to upstream bug report.

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5853f8a8 by Markus Koschany at 2019-03-30T13:24:59Z CVE-2019-0757,nuget: Link to upstream bug report. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Claim gpsd in dla-needed.txt

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 93a689d3 by Markus Koschany at 2019-03-30T12:47:08Z Claim gpsd in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2017-7655,mosquitto: Mark as postponed for Jessie

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d1cb1f71 by Markus Koschany at 2019-03-30T12:45:55Z CVE-2017-7655,mosquitto: Mark as postponed for Jessie Minor issue, can be fixed later when more important issues arise. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Claim rails in dla-needed.txt

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: adaf26e7 by Markus Koschany at 2019-03-30T11:58:03Z Claim rails in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-0199,tomcat8: Jessie is not affected

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d5b62a4 by Markus Koschany at 2019-03-30T11:36:19Z CVE-2019-0199,tomcat8: Jessie is not affected HTTP/2 support is not implemented. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-10269,bwa: Jessie is not affected

2019-03-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 29bd819a by Markus Koschany at 2019-03-30T11:17:29Z CVE-2019-10269,bwa: Jessie is not affected Vulnerable code is not present. - - - - - 108c77a0 by Markus Koschany at 2019-03-30T11:21:22Z CVE

[Git][security-tracker-team/security-tracker][master] CVE-2019-0222,activemq: bug report sent

2019-03-29 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 75f739e7 by Markus Koschany at 2019-03-29T14:49:58Z CVE-2019-0222,activemq: bug report sent - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] CVE-2019-0222,activemq: Jessie is not affected

2019-03-29 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d3464c3 by Markus Koschany at 2019-03-29T14:24:40Z CVE-2019-0222,activemq: Jessie is not affected MQTT support is not enabled. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-0160,CVE-2019-0161,edk2: Mark as EOL for Jessie

2019-03-29 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bc4a2a19 by Markus Koschany at 2019-03-29T12:59:17Z CVE-2019-0160,CVE-2019-0161,edk2: Mark as EOL for Jessie edk2 is non-free and not used by any sponsor. - - - - - 1 changed file: - data/CVE

[Git][security-tracker-team/security-tracker][master] CVE-2018-12183,edk2: Mark as EOL for Jessie

2019-03-29 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d8d4644b by Markus Koschany at 2019-03-29T12:57:39Z CVE-2018-12183,edk2: Mark as EOL for Jessie edk2 is non-free and not used by any sponsor. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1736-1 for dovecot

2019-03-29 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9490c3ff by Markus Koschany at 2019-03-29T12:07:03Z Reserve DLA-1736-1 for dovecot - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim dovecot in dla-needed.txt

2019-03-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 0e678f43 by Markus Koschany at 2019-03-28T15:35:06Z Claim dovecot in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-0816,cloud-init: Jessie is not affected.

2019-03-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dd809f56 by Markus Koschany at 2019-03-28T15:25:48Z CVE-2019-0816,cloud-init: Jessie is not affected. Vulnerable code is not present. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-3830,ceilometer: Jessie is not affected.

2019-03-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 11f00f61 by Markus Koschany at 2019-03-28T13:38:30Z CVE-2019-3830,ceilometer: Jessie is not affected. The vulnerable code is not present. Stretch is affected though. - - - - - 1 changed file

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1733-1 for wpa

2019-03-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 903fe791 by Markus Koschany at 2019-03-28T11:56:37Z Reserve DLA-1733-1 for wpa - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim wpa in dla-needed.txt

2019-03-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ae77aa44 by Markus Koschany at 2019-03-27T17:29:01Z Claim wpa in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-9917,znc: Jessie is not affected.

2019-03-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 97273b5d by Markus Koschany at 2019-03-27T17:15:43Z CVE-2019-9917,znc: Jessie is not affected. It is not possible for a user to change or set the encoding. The vulnerable code is not present

[Git][security-tracker-team/security-tracker][master] Add ruby2.1 to dla-needed.txt

2019-03-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bed446dd by Markus Koschany at 2019-03-27T17:05:20Z Add ruby2.1 to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-3815,systemd: Remove not-affected tag for Jessie.

2019-03-12 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9dbfd0c3 by Markus Koschany at 2019-03-12T22:53:41Z CVE-2019-3815,systemd: Remove not-affected tag for Jessie. Jessie is affected. There is a memory leak in dispatch_message_real and we need

[Git][security-tracker-team/security-tracker][master] CVE-2017-2826,zabbix: Remove no-dsa tag for Jessie.

2019-03-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 783fa4a6 by Markus Koschany at 2019-03-11T20:35:48Z CVE-2017-2826,zabbix: Remove no-dsa tag for Jessie. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1708-1 for zabbix

2019-03-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a38fdca6 by Markus Koschany at 2019-03-11T20:35:21Z Reserve DLA-1708-1 for zabbix - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim zabbix in dla-needed.txt

2019-03-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d44c42d by Markus Koschany at 2019-03-07T22:47:01Z Claim zabbix in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2018-20662,poppler: Link to correct fixing commit.

2019-03-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b12426e0 by Markus Koschany at 2019-03-07T22:46:35Z CVE-2018-20662,poppler: Link to correct fixing commit. - - - - - d5a51772 by Markus Koschany at 2019-03-07T22:46:35Z Remove no-dsa tags from

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1703-1 for jackson-databind

2019-03-04 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1f1ffe83 by Markus Koschany at 2019-03-04T11:00:16Z Reserve DLA-1703-1 for jackson-databind - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Triage spice-xpi for Jessie.

2019-03-03 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f7eeaaf by Markus Koschany at 2019-03-03T20:48:40Z Triage spice-xpi for Jessie. This Firefox plugin does not work anymore with recent versions of Firefox. Not used by any sponsor hence mark

[Git][security-tracker-team/security-tracker][master] CVE-2009-5155,CVE-2019-9169,glibc: no-dsa for Jessie

2019-03-03 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a0771f16 by Markus Koschany at 2019-03-03T20:23:09Z CVE-2009-5155,CVE-2019-9169,glibc: no-dsa for Jessie Minor issue - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2018-1056,advancecomp: Remove no-dsa tag for Jessie.

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 26b69fa0 by Markus Koschany at 2019-03-02T22:23:01Z CVE-2018-1056,advancecomp: Remove no-dsa tag for Jessie. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Add zabbix to dla-needed.txt

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 44d573ea by Markus Koschany at 2019-03-02T21:46:55Z Add zabbix to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Claim poppler in dla-needed.txt

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 95304505 by Markus Koschany at 2019-03-02T20:34:56Z Claim poppler in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1702-1 for advancecomp

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 59a8682b by Markus Koschany at 2019-03-02T20:33:59Z Reserve DLA-1702-1 for advancecomp - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim advancecomp in dla-needed.txt

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: aa0769f2 by Markus Koschany at 2019-03-02T18:39:05Z Claim advancecomp in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-9210,advancecomp: Link to fixing commit

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a21730f by Markus Koschany at 2019-03-02T18:38:03Z CVE-2019-9210,advancecomp: Link to fixing commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] Triage edk2 for Jessie.

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: eb9b1e1d by Markus Koschany at 2019-03-02T18:32:38Z Triage edk2 for Jessie. edk2 is end-of-life. Not used by any sponsor and non-free is not supported. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add ikiwiki to dla-needed.txt

2019-03-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 344855e5 by Markus Koschany at 2019-03-02T18:29:16Z Add ikiwiki to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1701-1 for openssl

2019-03-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d18633d9 by Markus Koschany at 2019-03-01T20:45:19Z Reserve DLA-1701-1 for openssl - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim jackson-databind in dla-needed.txt

2019-02-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a76c273e by Markus Koschany at 2019-02-28T19:32:56Z Claim jackson-databind in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1696-1 for ceph

2019-02-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bf4483fd by Markus Koschany at 2019-02-28T19:24:24Z Reserve DLA-1696-1 for ceph - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2018-16846,ceph: Link to required fixing commit

2019-02-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 28562257 by Markus Koschany at 2019-02-28T18:18:03Z CVE-2018-16846,ceph: Link to required fixing commit - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-3840,libvirt: Jessie is not affected.

2019-02-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1ddd1ff3 by Markus Koschany at 2019-02-28T12:00:04Z CVE-2019-3840,libvirt: Jessie is not affected. The vulnerable code was introduced in version 1.2.14. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove libvirt from dla-needed.txt

2019-02-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ffd480b9 by Markus Koschany at 2019-02-28T12:00:49Z Remove libvirt from dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-8331,twitter-bootstrap: Mark as no-dsa for Jessie

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e0f5c00 by Markus Koschany at 2019-02-27T23:14:43Z CVE-2019-8331,twitter-bootstrap: Mark as no-dsa for Jessie Not used by any sponsor. Minor issue. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: Claim openssl in dla-needed.txt

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 73a801ee by Markus Koschany at 2019-02-27T22:45:33Z Claim openssl in dla-needed.txt - - - - - 03134072 by Markus Koschany at 2019-02-27T22:45:55Z Add wordpress to dla-needed.txt - - - - - 1

[Git][security-tracker-team/security-tracker][master] Claim libvirt in dla-needed.txt

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4cbfb718 by Markus Koschany at 2019-02-27T22:14:09Z Claim libvirt in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2018-20797,CVE-2019-9199,libpodofo: Mark as no-dsa for Jessie

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bde2a6c5 by Markus Koschany at 2019-02-27T22:12:11Z CVE-2018-20797,CVE-2019-9199,libpodofo: Mark as no-dsa for Jessie Minor issues. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-8979,libkohana2-php: Jessie is not affected.

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ba1d284 by Markus Koschany at 2019-02-27T14:49:21Z CVE-2019-8979,libkohana2-php: Jessie is not affected. The orderby function properly checks for invalid values. - - - - - 1 changed file: - data

[Git][security-tracker-team/security-tracker][master] Add ldb to dla-needed.txt

2019-02-26 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2943f801 by Markus Koschany at 2019-02-26T23:03:29Z Add ldb to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2019-8979,libkohana2-php: Add more information.

2019-02-26 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c50dde53 by Markus Koschany at 2019-02-26T22:42:59Z CVE-2019-8979,libkohana2-php: Add more information. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2019-8935,collabtive: Ignored for Jessie

2019-02-26 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 253a0ca6 by Markus Koschany at 2019-02-26T21:57:21Z CVE-2019-8935,collabtive: Ignored for Jessie Minor issue, not used by any sponsor, very low popcon. - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add sox to dla-needed.txt

2019-02-26 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 272d5704 by Markus Koschany at 2019-02-26T21:24:29Z Add sox to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] CVE-2017-3164,lucene-solr: unimportant

2019-02-19 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 15cf3821 by Markus Koschany at 2019-02-19T21:48:37Z CVE-2017-3164,lucene-solr: unimportant See discussion in #922242 - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: Remove no-dsa tag from CVE-2017-15105

2019-02-14 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1fe97a49 by Markus Koschany at 2019-02-14T19:18:00Z Remove no-dsa tag from CVE-2017-15105 - - - - - 5db47aef by Markus Koschany at 2019-02-14T19:18:41Z Reserve DLA-1676-1 for unbound - - - - - 3

[Git][security-tracker-team/security-tracker][master] Claim unbound in dla-needed.txt

2019-02-14 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ddbfae5d by Markus Koschany at 2019-02-14T14:15:30Z Claim unbound in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Claim ceph in dla-needed.txt

2019-02-14 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1101953d by Markus Koschany at 2019-02-14T13:42:02Z Claim ceph in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1675-1 for python-gnupg

2019-02-14 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7056225f by Markus Koschany at 2019-02-14T13:28:33Z Reserve DLA-1675-1 for python-gnupg - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim python-gnupg in dla-needed.txt

2019-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a7e5bfd8 by Markus Koschany at 2019-02-11T20:38:37Z Claim python-gnupg in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1673-1 for wordpress

2019-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c70a59c by Markus Koschany at 2019-02-11T20:11:33Z Reserve DLA-1673-1 for wordpress - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1662-1 for libthrift-java

2019-02-06 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9708050e by Markus Koschany at 2019-02-06T19:06:27Z Reserve DLA-1662-1 for libthrift-java - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Readd drupal7 to dla-needed.txt. Still an open issue.

2019-02-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a1942cf by Markus Koschany at 2019-02-02T21:28:16Z Readd drupal7 to dla-needed.txt. Still an open issue. - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] 4 commits: Add rssh to dla-needed.txt

2019-02-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d5ebd1fd by Markus Koschany at 2019-02-02T21:04:43Z Add rssh to dla-needed.txt - - - - - 9fb1c954 by Markus Koschany at 2019-02-02T21:06:23Z CVE-2019-6446,python-numpy: Jessie is no-dsa Switching

[Git][security-tracker-team/security-tracker][master] 2 commits: Add sox to dla-needed.txt

2019-02-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a4ab5417 by Markus Koschany at 2019-02-02T12:54:31Z Add sox to dla-needed.txt - - - - - 63e661c7 by Markus Koschany at 2019-02-02T12:56:17Z Remove sox no-dsa tags. - - - - - 2 changed files

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2017-18361,python-colander: Mark as no-dsa for Jessie.

2019-02-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a46de63e by Markus Koschany at 2019-02-02T12:49:28Z CVE-2017-18361,python-colander: Mark as no-dsa for Jessie. - - - - - 0023e6e4 by Markus Koschany at 2019-02-02T12:49:29Z CVE-2019-6438,slurm-llnl

[Git][security-tracker-team/security-tracker][master] Triage Enigmail for Jessie. It is end-of-life now.

2019-02-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1208d16a by Markus Koschany at 2019-02-02T12:37:11Z Triage Enigmail for Jessie. It is end-of-life now. - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 2 commits: Add mysql-connector-python to dla-needed.txt

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2ef8355c by Markus Koschany at 2019-02-02T06:14:04Z Add mysql-connector-python to dla-needed.txt - - - - - f964e430 by Markus Koschany at 2019-02-02T06:17:36Z Add mumble to dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add python-gnupg to dla-needed.txt

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e34641d8 by Markus Koschany at 2019-02-01T12:29:19Z Add python-gnupg to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-6446,python-numpy: Clarify upstream view

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 02b7e797 by Markus Koschany at 2019-02-01T11:56:33Z CVE-2019-6446,python-numpy: Clarify upstream view The current behavior is documented and it works as intended. The solution to switch the default

[Git][security-tracker-team/security-tracker][master] Claim libthrift-java in dla-needed.txt

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 415558b6 by Markus Koschany at 2019-02-01T11:46:44Z Claim libthrift-java in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data

[Git][security-tracker-team/security-tracker][master] Add openjdk-7 to dla-needed.txt

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 626a02d5 by Markus Koschany at 2019-02-01T11:42:59Z Add openjdk-7 to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2018-1340,guacamole-client: Link to possible upstream fix.

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c027a940 by Markus Koschany at 2019-02-01T11:34:57Z CVE-2018-1340,guacamole-client: Link to possible upstream fix. Just from reading the commit message and comparing it with the CVE description

[Git][security-tracker-team/security-tracker][master] CVE-2019-7282,CVE-2019-7283,netkit-rsh: no-dsa for Jessie

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 884510c3 by Markus Koschany at 2019-02-01T11:04:06Z CVE-2019-7282,CVE-2019-7283,netkit-rsh: no-dsa for Jessie Minor issue, requires malicious server. Not used by any sponsor. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1656-1 for agg.

2019-02-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9a12795e by Markus Koschany at 2019-02-01T10:14:17Z Reserve DLA-1656-1 for agg. - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Claim agg in dla-needed.txt

2019-01-31 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: aa39fe92 by Markus Koschany at 2019-01-31T15:01:34Z Claim agg in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1650-1 for rssh

2019-01-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 2733bdb6 by Markus Koschany at 2019-01-30T17:47:50Z Reserve DLA-1650-1 for rssh - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Add php5 to dla-needed.txt

2019-01-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dd339f5b by Markus Koschany at 2019-01-30T15:31:02Z Add php5 to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Add coturn to dla-needed.txt

2019-01-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6de2a8cb by Markus Koschany at 2019-01-30T13:18:48Z Add coturn to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-6131,mupdf: Jessie is not affected.

2019-01-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 1336a18c by Markus Koschany at 2019-01-30T12:59:39Z CVE-2019-6131,mupdf: Jessie is not affected. Vulnerable code is not present (svg support). - - - - - c4aeb744 by Markus Koschany at 2019-01-30T13

[Git][security-tracker-team/security-tracker][master] Claim rssh in dla-needed.txt

2019-01-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: ac408c2f by Markus Koschany at 2019-01-30T12:51:14Z Claim rssh in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Update status of wordpress in dla-needed.txt

2019-01-28 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 91252b9a by Markus Koschany at 2019-01-28T13:11:20Z Update status of wordpress in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] CVE-2018-17191,netbeans: Stretch is not affected.

2019-01-25 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d6da03c1 by Markus Koschany at 2019-01-25T17:55:53Z CVE-2018-17191,netbeans: Stretch is not affected. The nashorn module is not enabled. Javascript support is incomplete. See also Debian bug 815028

[Git][security-tracker-team/security-tracker][master] Claim wordpress in dla-needed.txt

2019-01-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 745d7bf2 by Markus Koschany at 2019-01-11T15:26:04Z Claim wordpress in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] 2 commits: sqlite3: Remove no-dsa tags for Jessie

2019-01-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 81805895 by Markus Koschany at 2019-01-11T15:11:45Z sqlite3: Remove no-dsa tags for Jessie - - - - - ed9a47db by Markus Koschany at 2019-01-11T15:11:45Z Reserve DLA-1633-1 for sqlite3 - - - - - 3

[Git][security-tracker-team/security-tracker][master] Claim sqlite3 in dla-needed.txt

2019-01-09 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4fd931fa by Markus Koschany at 2019-01-09T22:21:38Z Claim sqlite3 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1631-1 for libcaca

2019-01-09 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 80c6443e by Markus Koschany at 2019-01-09T21:46:56Z Reserve DLA-1631-1 for libcaca - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Assign myself to one week in February for LTS frontdesk.

2019-01-09 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 29cee61c by Markus Koschany at 2019-01-09T16:40:22Z Assign myself to one week in February for LTS frontdesk. - - - - - 1 changed file: - org/lts-frontdesk.2019.txt Changes

[Git][security-tracker-team/security-tracker][master] Readd libav to dla-needed.txt

2019-01-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e91eddaf by Markus Koschany at 2019-01-07T20:15:53Z Readd libav to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1630-1 for libav

2019-01-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5f4e184b by Markus Koschany at 2019-01-07T20:14:58Z Reserve DLA-1630-1 for libav - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Fix CVE/list entries about yaml-cpp0.3

2019-01-06 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 3de60132 by Markus Koschany at 2019-01-06T21:58:13Z Fix CVE/list entries about yaml-cpp0.3 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2018-20573,CVE-2018-20574,yaml-cpp,yaml-cpp0.3: postponed for Jessie

2019-01-06 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b98d5868 by Markus Koschany at 2019-01-06T21:54:02Z CVE-2018-20573,CVE-2018-20574,yaml-cpp,yaml-cpp0.3: postponed for Jessie Not urgent and postponed for now, hardly used but could be fixed later

[Git][security-tracker-team/security-tracker][master] CVE-2017-11684,libav: Link to fixing commit

2019-01-06 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 68c6a716 by Markus Koschany at 2019-01-06T20:44:51Z CVE-2017-11684,libav: Link to fixing commit - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] 4 commits: CVE-2018-20348,libpff: no-dsa for Jessie

2019-01-05 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 7222fe49 by Markus Koschany at 2019-01-05T18:18:14Z CVE-2018-20348,libpff: no-dsa for Jessie Minor issue, upstream states it is alpha software, not used by any sponsor. - - - - - d3f55eb9 by Markus

[Git][security-tracker-team/security-tracker][master] CVE-2018-16888,systemd: Mark as no-dsa for Jessie.

2019-01-03 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 02d6b1cb by Markus Koschany at 2019-01-03T22:06:12Z CVE-2018-16888,systemd: Mark as no-dsa for Jessie. This is arguably a longstanding bug in the PID file logic and systemd is now stricter when a PID

[Git][security-tracker-team/security-tracker][master] CVE-2018-19139,jasper: Issue is not yet fixed.

2019-01-03 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 733f0da5 by Markus Koschany at 2019-01-03T15:12:42Z CVE-2018-19139,jasper: Issue is not yet fixed. The memory leak did not seem to exist because ASAN was still enabled. - - - - - 2 changed files

[Git][security-tracker-team/security-tracker][master] Claim libcaca in dla-needed.txt

2019-01-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 608cbf51 by Markus Koschany at 2019-01-02T22:26:15Z Claim libcaca in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

[Git][security-tracker-team/security-tracker][master] CVE-2019-3500,aria2: Mark as no-dsa for Jessie.

2019-01-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: b320398e by Markus Koschany at 2019-01-02T22:24:55Z CVE-2019-3500,aria2: Mark as no-dsa for Jessie. Minor issue - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2018-19139, CVE-2018-18873, jasper: Remove no-dsa tags.

2019-01-02 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 682527d4 by Markus Koschany at 2019-01-02T21:43:18Z CVE-2018-19139, CVE-2018-18873, jasper: Remove no-dsa tags. - - - - - d2bc542d by Markus Koschany at 2019-01-02T21:48:43Z CVE-2018-19543,jasper

[Git][security-tracker-team/security-tracker][master] 4 commits: CVE-2018-20004,mxml: Link to fixing commit, remove no-dsa tag for Jessie.

2019-01-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: dd77373b by Markus Koschany at 2019-01-01T23:18:06Z CVE-2018-20004,mxml: Link to fixing commit, remove no-dsa tag for Jessie. - - - - - f091dc1c by Markus Koschany at 2019-01-01T23:18:06Z CVE-2016

[Git][security-tracker-team/security-tracker][master] Triage liblas for Jessie.

2019-01-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 50c003f1 by Markus Koschany at 2019-01-01T21:13:57Z Triage liblas for Jessie. Mark reported issues as no-dsa for now and follow Stretch. This library is not used by any sponsor. - - - - - 1

[Git][security-tracker-team/security-tracker][master] CVE-2018-20651,CVE-2018-20623,binutils: Mark as ignored for Jessie

2019-01-01 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 5a20ea57 by Markus Koschany at 2019-01-01T21:06:47Z CVE-2018-20651,CVE-2018-20623,binutils: Mark as ignored for Jessie Minor issue - - - - - 1 changed file: - data/CVE/list Changes

[Git][security-tracker-team/security-tracker][master] CVE-2018-20552,CVE-2018-20553,tcpreplay: no-dsa for Jessie

2018-12-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: a4fa71d8 by Markus Koschany at 2018-12-30T15:25:35Z CVE-2018-20552,CVE-2018-20553,tcpreplay: no-dsa for Jessie The heap-based buffer overflows are reproducible with ASAN, without ASAN the tcprep tool

[Git][security-tracker-team/security-tracker][master] Add libcaca to dla-needed.txt

2018-12-30 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e2c0493 by Markus Koschany at 2018-12-30T14:47:58Z Add libcaca to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla

<    6   7   8   9   10   11   12   13   14   15   >