[Secure-testing-commits] r40743 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-04 05:30:16 + (Mon, 04 Apr 2016)
New Revision: 40743

Modified:
   data/CVE/list
Log:
bind9 1:9.10.3.dfsg.P4-6 uploaded to unstable

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-04 05:14:29 UTC (rev 40742)
+++ data/CVE/list   2016-04-04 05:30:16 UTC (rev 40743)
@@ -7535,13 +7535,11 @@
NOT-FOR-US: Cisco ASA
 CVE-2016-1286 (named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 
9.10.3-P4 ...)
{DSA-3511-1}
-   [experimental] - bind9 1:9.10.3.dfsg.P4-1
-   - bind9 
+   - bind9 1:9.10.3.dfsg.P4-6
NOTE: https://kb.isc.org/article/AA-01353
 CVE-2016-1285 (named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 
9.10.3-P4 ...)
{DSA-3511-1}
-   [experimental] - bind9 1:9.10.3.dfsg.P4-1
-   - bind9 
+   - bind9 1:9.10.3.dfsg.P4-6
NOTE: https://kb.isc.org/article/AA-01352
 CVE-2016-1284 (rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S 
before ...)
- bind9  (Only Supported Preview Edition/Subscription 
Edition)
@@ -8007,8 +8005,7 @@
NOTE: https://kb.isc.org/article/AA-01336
 CVE-2015-8704 (apl_42.c in ISC BIND 9.x before 9.9.8-P3 and 9.9.x and 9.10.x 
before ...)
{DSA-3449-1 DLA-396-1}
-   - bind9  (bug #812077)
-   [experimental] - bind9 1:9.10.3.dfsg.P4-1
+   - bind9 1:9.10.3.dfsg.P4-6 (bug #812077)
NOTE: https://kb.isc.org/article/AA-01335
 CVE-2015-8703 (ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and 
ZXV10 ...)
NOT-FOR-US: ZTE router


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40742 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-04 05:14:29 + (Mon, 04 Apr 2016)
New Revision: 40742

Modified:
   data/CVE/list
Log:
ntop removed from the archive

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-04 05:12:45 UTC (rev 40741)
+++ data/CVE/list   2016-04-04 05:14:29 UTC (rev 40742)
@@ -50876,7 +50876,7 @@
 CVE-2014-4166 (Cross-site scripting (XSS) vulnerability in the song history in 
...)
NOT-FOR-US: SHOUTcast DNAS
 CVE-2014-4165 (Cross-site scripting (XSS) vulnerability in ntop allows remote 
...)
-   - ntop  (bug #751946)
+   - ntop  (bug #751946)
[jessie] - ntop  (Minor issue)
[wheezy] - ntop  (Minor issue)
 CVE-2014-4164 (Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 
6.3-b230 ...)


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40741 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-04 05:12:45 + (Mon, 04 Apr 2016)
New Revision: 40741

Modified:
   data/CVE/list
Log:
Update information for two lxcfs issues

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-04 05:02:34 UTC (rev 40740)
+++ data/CVE/list   2016-04-04 05:12:45 UTC (rev 40741)
@@ -32815,13 +32815,13 @@
 CVE-2015-1347 (Cross-site scripting (XSS) vulnerability in client.inc.php in 
osTicket ...)
NOT-FOR-US: osTicket
 CVE-2015-1344 (The do_write_pids function in lxcfs.c in LXCFS before 0.12 does 
not ...)
-   - lxcfs 
+   - lxcfs  (Fixed before initial upload to the archive)
NOTE: https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1512854
TODO: check
 CVE-2015-1343
RESERVED
 CVE-2015-1342 (LXCFS before 0.12 does not properly enforce directory escapes, 
which ...)
-   - lxcfs 
+   - lxcfs  (Fixed before initial upload to the archive)
NOTE: https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1508481
TODO: check
 CVE-2015-1341


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40740 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-04 05:02:34 + (Mon, 04 Apr 2016)
New Revision: 40740

Modified:
   data/CVE/list
Log:
Mark lxcfs issues as undetermined for now, check two Ubuntu bugs

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-03 21:10:11 UTC (rev 40739)
+++ data/CVE/list   2016-04-04 05:02:34 UTC (rev 40740)
@@ -32815,13 +32815,15 @@
 CVE-2015-1347 (Cross-site scripting (XSS) vulnerability in client.inc.php in 
osTicket ...)
NOT-FOR-US: osTicket
 CVE-2015-1344 (The do_write_pids function in lxcfs.c in LXCFS before 0.12 does 
not ...)
-   - lxcfs  (bug #775021)
-   NOTE: recheck when it enters archive
+   - lxcfs 
+   NOTE: https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1512854
+   TODO: check
 CVE-2015-1343
RESERVED
 CVE-2015-1342 (LXCFS before 0.12 does not properly enforce directory escapes, 
which ...)
-   - lxcfs  (bug #775021)
-   NOTE: recheck when it enters archive
+   - lxcfs 
+   NOTE: https://bugs.launchpad.net/ubuntu/+source/lxcfs/+bug/1508481
+   TODO: check
 CVE-2015-1341
RESERVED
 CVE-2015-1340


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40739 failed

2016-04-03 Thread security tracker role
The error message was:

data/CVE/list:32817: ITPed package lxcfs is in the archive
data/CVE/list:32822: ITPed package lxcfs is in the archive
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40739 - data/CVE

2016-04-03 Thread security tracker role
Author: sectracker
Date: 2016-04-03 21:10:11 + (Sun, 03 Apr 2016)
New Revision: 40739

Modified:
   data/CVE/list
Log:
automatic update

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-03 20:11:19 UTC (rev 40738)
+++ data/CVE/list   2016-04-03 21:10:11 UTC (rev 40739)
@@ -4097,6 +4097,7 @@
RESERVED
 CVE-2016-2347 [decode_level3_header heap corruption vulnerability]
RESERVED
+   {DSA-3540-1}
- lhasa 0.3.1-1
NOTE: http://www.talosintel.com/reports/TALOS-2016-0095/
 CVE-2016-2346


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40738 - data

2016-04-03 Thread Moritz Muehlenhoff
Author: jmm
Date: 2016-04-03 20:11:19 + (Sun, 03 Apr 2016)
New Revision: 40738

Modified:
   data/dsa-needed.txt
Log:
take fuseiso
add cgit


Modified: data/dsa-needed.txt
===
--- data/dsa-needed.txt 2016-04-03 18:34:52 UTC (rev 40737)
+++ data/dsa-needed.txt 2016-04-03 20:11:19 UTC (rev 40738)
@@ -18,10 +18,12 @@
 --
 botan1.10
 --
+cgit
+--
 extplorer/oldstable (Thorsten Alteholz)
   NOTE: .debdiff sent to the Security Team, waiting for feedback
 --
-fuseiso/oldstable (Thorsten Alteholz)
+fuseiso/oldstable (jmm)
   NOTE: debdiff sent by Thorsten Alteholz to the Security Team on 2016-03-25
 --
 gosa/oldstable (Mike Gabriel)


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40735 - data

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 17:53:03 + (Sun, 03 Apr 2016)
New Revision: 40735

Modified:
   data/dsa-needed.txt
Log:
Add libxstream-java

Modified: data/dsa-needed.txt
===
--- data/dsa-needed.txt 2016-04-03 15:45:50 UTC (rev 40734)
+++ data/dsa-needed.txt 2016-04-03 17:53:03 UTC (rev 40735)
@@ -39,6 +39,10 @@
   https://people.debian.org/~ghedo/libidn_1.29-1+deb8u1.diff
   Help is needed to fix it so that it doesn't FTBFS
 --
+libxstream-java
+  Emmanuel Bourg proposed debdiff for both wheezy- and jessie-security
+  TODO: check, ack or redirect to pu
+--
 linux
 --
 mediawiki/oldstable


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40734 - data

2016-04-03 Thread Paul Wise
Author: pabs
Date: 2016-04-03 15:45:50 + (Sun, 03 Apr 2016)
New Revision: 40734

Modified:
   data/embedded-code-copies
Log:
freedroidrpg embeds lua5.3

Modified: data/embedded-code-copies
===
--- data/embedded-code-copies   2016-04-03 15:41:05 UTC (rev 40733)
+++ data/embedded-code-copies   2016-04-03 15:45:50 UTC (rev 40734)
@@ -3013,3 +3013,6 @@
- spades  (embed)
- ossim  (embed)
- gnudatalanguage  (embed)
+
+lua5.3
+   - freedroidrpg  (embed)


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40733 - bin

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 15:41:05 + (Sun, 03 Apr 2016)
New Revision: 40733

Modified:
   bin/check-new-issues
Log:
Update regexp to match allowd source package names as per policy 5.6.1

Modified: bin/check-new-issues
===
--- bin/check-new-issues2016-04-03 15:17:31 UTC (rev 40732)
+++ bin/check-new-issues2016-04-03 15:41:05 UTC (rev 40733)
@@ -450,7 +450,7 @@

my ($code, $pkg);
while (my $line = <$fh>) {
-   if ($line =~ /^([-\w]+)/) {
+   if ($line =~ /^([\w][\w+-.]+)/) {
$code = lc($1);
$pkg  = undef;
if (exists $embed_code->{$code}) {


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40732 - data/packages

2016-04-03 Thread security tracker role
Author: sectracker
Date: 2016-04-03 15:17:31 + (Sun, 03 Apr 2016)
New Revision: 40732

Modified:
   data/packages/removed-packages
Log:
These packages have been removed

Modified: data/packages/removed-packages
===
--- data/packages/removed-packages  2016-04-03 14:41:41 UTC (rev 40731)
+++ data/packages/removed-packages  2016-04-03 15:17:31 UTC (rev 40732)
@@ -463,3 +463,121 @@
 phpdocx
 php5.6
 owncloud-documents
+nspluginwrapper
+r-base-core-ra
+ebug-http
+rampart
+pilot-qof
+tn5250
+wxwidgets2.6
+mnemo2
+kronolith2
+libspring-2.5-java
+spread
+silc-server
+icecast-server
+pike7.6
+nag2
+tleds
+libspf
+opendchub
+qt-x11-free
+popfile
+amd64-libs
+libtunepimp
+tremulous
+autofs5
+picasm
+osiris
+postfix-policyd
+poker-network
+silc-toolkit
+pwlib
+lustre
+nordugrid-arc-nox
+tucan
+xmame
+kdebase-workspace
+sysklogd
+libservlet2.4-java
+aptlinex
+smbind
+cyrus-imapd-2.2
+sork-passwd-h3
+dlr-languages
+asterisk-addons
+nvidia-kernel-common
+ldapdiff
+ltp
+kazehakase
+php-net-ping
+mime-tools
+wwwoffle
+sitebar
+pdfjam
+turqstat
+dbmail
+python-4suite
+kompozer
+chora2
+op
+yiff
+luxman
+ihu
+cgiirc
+tork
+ipplan
+pootle
+imp4
+termpkg
+venkman
+frox
+orpheus
+cheesetracker
+dimp1
+gnatsweb
+libhaml-ruby
+convirt
+netapplet
+hybserv
+sdm
+automake1.7
+libfwbuilder
+radare
+dkim-milter
+activeldap
+emil
+kolabd
+log2mail
+mt-daapd
+mysql-gui-tools
+qpopper
+ingo1
+scponly
+silc-client
+wu-ftpd
+jabberd14
+xtradius
+rt-extension-emailcompletion
+honeyd
+gmime2.2
+libmusicbrainz-2.1
+gmime2.4
+tkdiff
+loop-aes-utils
+mongrel
+kphone
+tkman
+viewglob
+kdeedu
+kdeutils
+lwat
+gollem
+gpsdrive
+libpam-opie
+compiz-fusion-plugins-main
+alsa-driver
+mono-debugger
+xmcd
+hobix
+oprofile


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40731 - data

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 14:41:41 + (Sun, 03 Apr 2016)
New Revision: 40731

Modified:
   data/config.json
Log:
oldoldstable is gone, thus remove from config.json

Modified: data/config.json
===
--- data/config.json2016-04-03 14:08:05 UTC (rev 40730)
+++ data/config.json2016-04-03 14:41:41 UTC (rev 40731)
@@ -37,7 +37,6 @@
"supported" : ["squeeze", "squeeze-security"],
"optional" : ["squeeze-proposed-updates"]
   },
-  "release" : "oldoldstable"
 },
 "wheezy" : {
   "members" : {


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] Processing r40730 failed

2016-04-03 Thread security tracker role
The error message was:

Traceback (most recent call last):
  File "bin/update-db", line 62, in 
db.readPackages(cursor, 'data/packages')
  File 
"/srv/security-tracker.debian.org/website/secure-testing/lib/python/security_db.py",
 line 713, in readPackages
self._readBinaryPackages(cursor, directory)
  File 
"/srv/security-tracker.debian.org/website/secure-testing/lib/python/security_db.py",
 line 802, in _readBinaryPackages
(unch, parsed) = self._parseFile(cursor, filename)
  File 
"/srv/security-tracker.debian.org/website/secure-testing/lib/python/security_db.py",
 line 626, in _parseFile
current_print = self.filePrint(filename)
  File 
"/srv/security-tracker.debian.org/website/secure-testing/lib/python/security_db.py",
 line 620, in filePrint
st = os.stat(filename)
OSError: [Errno 2] No such file or directory: 
'data/packages/squeeze-backports__contrib_amd64_Packages'
Makefile:22: recipe for target 'all' failed
make: *** [all] Error 1

___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40730 - data

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 14:08:05 + (Sun, 03 Apr 2016)
New Revision: 40730

Modified:
   data/config.json
Log:
data/config.json: update for the jessie release

Modified: data/config.json
===
--- data/config.json2016-04-03 13:18:04 UTC (rev 40729)
+++ data/config.json2016-04-03 14:08:05 UTC (rev 40730)
@@ -37,20 +37,27 @@
"supported" : ["squeeze", "squeeze-security"],
"optional" : ["squeeze-proposed-updates"]
   },
-  "release" : "oldstable"
+  "release" : "oldoldstable"
 },
 "wheezy" : {
   "members" : {
"supported" : ["wheezy", "wheezy-security"],
"optional" : ["wheezy-proposed-updates"]
   },
-  "release" : "stable"
+  "release" : "oldstable"
 },
 "jessie" : {
   "members" : {
"supported" : ["jessie", "jessie-security"],
"optional" : ["jessie-proposed-updates"]
   },
+  "release" : "stable"
+},
+"stretch" : {
+  "members" : {
+   "supported" : ["stretch", "stretch-security"],
+   "optional" : ["stretch-proposed-updates"]
+  },
   "release" : "testing"
 },
 "sid" : {


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40729 - data/CVE

2016-04-03 Thread Henri Salo
Author: fgeek-guest
Date: 2016-04-03 13:18:04 + (Sun, 03 Apr 2016)
New Revision: 40729

Modified:
   data/CVE/list
Log:
giflib gif2rgb heap buffer overflow

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-03 12:26:32 UTC (rev 40728)
+++ data/CVE/list   2016-04-03 13:18:04 UTC (rev 40729)
@@ -1,3 +1,7 @@
+CVE-2016- [gif2rgb: heap buffer overflow]
+   - giflib 
+   NOTE: https://sourceforge.net/p/giflib/bugs/87/
+   NOTE: 
https://sourceforge.net/p/giflib/code/ci/ea8dbc5786862a3e16a5acfa3d24e2c2f608cd88/
 CVE-2016-3948 [Denial of service]
- squid3  (bug #819784)
[jessie] - squid3  (Minor issue; needs substantial backporting; 
too intrusive to backport)


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40728 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 12:26:32 + (Sun, 03 Apr 2016)
New Revision: 40728

Modified:
   data/CVE/list
Log:
Fix source package name for CVE-2016-3177

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-03 12:25:36 UTC (rev 40727)
+++ data/CVE/list   2016-04-03 12:26:32 UTC (rev 40728)
@@ -1607,7 +1607,7 @@
NOTE: https://github.com/micahflee/torbrowser-launcher/issues/229
 CVE-2016-3177 [gifcolor: use-after-free in EGifCloseFile]
RESERVED
-   - giflib-tools  (unimportant)
+   - giflib  (unimportant)
NOTE: https://sourceforge.net/p/giflib/bugs/83/
NOTE: Issue only in gifcolor utility, not installed into giflib-tools
 CVE-2016-3176 [insecure configuration of PAM external authentication service]


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40727 - data/CVE

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 12:25:36 + (Sun, 03 Apr 2016)
New Revision: 40727

Modified:
   data/CVE/list
Log:
Add missing source package name for CVE-2016-0823

Modified: data/CVE/list
===
--- data/CVE/list   2016-04-03 12:19:42 UTC (rev 40726)
+++ data/CVE/list   2016-04-03 12:25:36 UTC (rev 40727)
@@ -9305,7 +9305,7 @@
TODO: check
 CVE-2016-0823 (The pagemap_open function in fs/proc/task_mmu.c in the Linux 
kernel ...)
- linux 4.0.2-1
-   [jessie] - 3.16.7-ckt11-1
+   [jessie] - linux 3.16.7-ckt11-1
[wheezy] - linux 3.2.71-1
NOTE: Upstream patch: 
https://git.kernel.org/linus/ab676b7d6fbf4b294bf198fb27ade5b0e865c7ce (v4.0-rc5)
NOTE: 
https://googleprojectzero.blogspot.cz/2015/03/exploiting-dram-rowhammer-bug-to-gain.html


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40726 - data/DSA

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 12:19:42 + (Sun, 03 Apr 2016)
New Revision: 40726

Modified:
   data/DSA/list
Log:
Add DSA entry for lhasa

Modified: data/DSA/list
===
--- data/DSA/list   2016-04-03 11:17:16 UTC (rev 40725)
+++ data/DSA/list   2016-04-03 12:19:42 UTC (rev 40726)
@@ -1,3 +1,7 @@
+[03 Apr 2016] DSA-3540-1 lhasa - security update
+   {CVE-2016-2347}
+   [wheezy] - lhasa 0.0.7-2+deb7u1
+   [jessie] - lhasa 0.2.0+git3fe46-1+deb8u1
 [02 Apr 2016] DSA-3539-1 srtp - security update
{CVE-2015-6360}
[wheezy] - srtp 1.4.4+20100615~dfsg-2+deb7u2


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits


[Secure-testing-commits] r40725 - bin

2016-04-03 Thread Salvatore Bonaccorso
Author: carnil
Date: 2016-04-03 11:17:16 + (Sun, 03 Apr 2016)
New Revision: 40725

Modified:
   bin/tracker_service.py
Log:
Remove old comment from temporary disable of json export functionality

Modified: bin/tracker_service.py
===
--- bin/tracker_service.py  2016-04-02 21:10:11 UTC (rev 40724)
+++ bin/tracker_service.py  2016-04-03 11:17:16 UTC (rev 40725)
@@ -165,7 +165,6 @@
 self.register('data/funny-versions', self.page_data_funny_versions)
 self.register('data/fake-names', self.page_data_fake_names)
 self.register('data/pts/1', self.page_data_pts)
-# temorarly disabled on 2016-02-01 due to load on security-tracker
 self.register('data/json', self.page_json)
 self.register('debsecan/**', self.page_debsecan)
 self.register('data/report', self.page_report)


___
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits