[Git][security-tracker-team/security-tracker][master] Add CVE-2018-12180/edk2

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 921ed184 by Salvatore Bonaccorso at 2019-02-28T07:54:14Z Add CVE-2018-12180/edk2 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2018-12178/edk2

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6087358c by Salvatore Bonaccorso at 2019-02-28T07:52:32Z Update status for CVE-2018-12178/edk2 - - - - - 1 changed file: - data/CVE/list Changes: = data/

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-12178/edk2

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e24cd32f by Salvatore Bonaccorso at 2019-02-28T07:51:20Z Add CVE-2018-12178/edk2 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] dla-needed: claim sox

2019-02-27 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 088d5f4a by Hugo Lefeuvre at 2019-02-28T07:47:00Z dla-needed: claim sox - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt =

[Git][security-tracker-team/security-tracker][master] CVE-2019-6501: qemu stretch & jessie not-affected

2019-02-27 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: aa4e021d by Hugo Lefeuvre at 2019-02-28T07:29:17Z CVE-2019-6501: qemu stretch & jessie not-affected The overflow was introduced in a71c775b24. Before that, page_len was neither read from r->buf nor used

[Git][security-tracker-team/security-tracker][master] claim libraw

2019-02-27 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 9d78569a by Thorsten Alteholz at 2019-02-28T07:28:51Z claim libraw - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt ==

[Git][security-tracker-team/security-tracker][master] CVE-2019-8331,twitter-bootstrap: Mark as no-dsa for Jessie

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e0f5c00 by Markus Koschany at 2019-02-27T23:14:43Z CVE-2019-8331,twitter-bootstrap: Mark as no-dsa for Jessie Not used by any sponsor. Minor issue. - - - - - 1 changed file: - data/CVE/list Cha

[Git][security-tracker-team/security-tracker][master] 2 commits: Claim openssl in dla-needed.txt

2019-02-27 Thread Markus Koschany
changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt = @@ -96,6 +96,8 @@ openssh (Mike Gabriel) NOTE: 20190227: Work in progress. First draft is still vulnerable to PoC: https://www.exploit-db.com/exploits/46193

[Git][security-tracker-team/security-tracker][master] buster triage

2019-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b2df4ff1 by Moritz Muehlenhoff at 2019-02-27T22:27:10Z buster triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===

[Git][security-tracker-team/security-tracker][master] Claim libvirt in dla-needed.txt

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4cbfb718 by Markus Koschany at 2019-02-27T22:14:09Z Claim libvirt in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed

[Git][security-tracker-team/security-tracker][master] CVE-2018-20797,CVE-2019-9199,libpodofo: Mark as no-dsa for Jessie

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: bde2a6c5 by Markus Koschany at 2019-02-27T22:12:11Z CVE-2018-20797,CVE-2019-9199,libpodofo: Mark as no-dsa for Jessie Minor issues. - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-9211/pspp

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: af13f228 by Salvatore Bonaccorso at 2019-02-27T21:42:50Z Add Debian bug reference for CVE-2019-9211/pspp - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] remove mysql-connector-python from dsa-needed

2019-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e2e78aad by Moritz Muehlenhoff at 2019-02-27T21:40:02Z remove mysql-connector-python from dsa-needed - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-9211/pspp

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 41365b80 by Salvatore Bonaccorso at 2019-02-27T21:28:08Z Add CVE-2019-9211/pspp - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-9210/advancecomp

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0af0f11e by Salvatore Bonaccorso at 2019-02-27T21:15:50Z Add Debian bug reference for CVE-2019-9210/advancecomp - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-9210/advancecomp

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 85fc04dd by Salvatore Bonaccorso at 2019-02-27T20:50:23Z Add CVE-2019-9210/advancecomp - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2018-20797/libpodofo

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2be61f08 by Salvatore Bonaccorso at 2019-02-27T20:42:32Z Add Debian bug reference for CVE-2018-20797/libpodofo - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-20797/libpodofo

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 38a83106 by Salvatore Bonaccorso at 2019-02-27T20:34:00Z Add CVE-2018-20797/libpodofo - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-9200/poppler: #923414

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ca8ae86e by Salvatore Bonaccorso at 2019-02-27T20:31:38Z Add Debian bug reference for CVE-2019-9200/poppler: #923414 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-9200/poppler

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b3aaee4 by Salvatore Bonaccorso at 2019-02-27T20:22:57Z Add CVE-2019-9200/poppler - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===

[Git][security-tracker-team/security-tracker][master] Move some older NFUs associated with Apache Airflow to itp tagged entry

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 117d6306 by Salvatore Bonaccorso at 2019-02-27T20:17:37Z Move some older NFUs associated with Apache Airflow to itp tagged entry Apache Airflow CVEs were marked as NFU previously but there is an

[Git][security-tracker-team/security-tracker][master] Add CVE-2018-20244/airflow, itp'ed, #819700

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 51abe9e2 by Salvatore Bonaccorso at 2019-02-27T20:15:47Z Add CVE-2018-20244/airflow, itp'ed, #819700 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c7dd by Salvatore Bonaccorso at 2019-02-27T20:15:20Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ef7f6ce2 by security tracker role at 2019-02-27T20:10:20Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===

[Git][security-tracker-team/security-tracker][master] One issue got an update in DLA, remove no-dsa tag for respective suite

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 58755cc5 by Salvatore Bonaccorso at 2019-02-27T19:44:50Z One issue got an update in DLA, remove no-dsa tag for respective suite - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1693-1 for gpac

2019-02-27 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: dbd26e26 by Thorsten Alteholz at 2019-02-27T19:29:46Z Reserve DLA-1693-1 for gpac - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] NFUs

2019-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f44cb213 by Moritz Muehlenhoff at 2019-02-27T17:47:31Z NFUs new podofo issue two exiv issues n/a - - - - - 1 changed file: - data/CVE/list Changes: = data/

[Git][security-tracker-team/security-tracker][master] NFUs

2019-02-27 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ce56b923 by Moritz Muehlenhoff at 2019-02-27T17:35:34Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2019-8979,libkohana2-php: Jessie is not affected.

2019-02-27 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4ba1d284 by Markus Koschany at 2019-02-27T14:49:21Z CVE-2019-8979,libkohana2-php: Jessie is not affected. The orderby function properly checks for invalid values. - - - - - 1 changed file: - data/

[Git][security-tracker-team/security-tracker][master] chromium regression dsa

2019-02-27 Thread Michael Gilbert
Michael Gilbert pushed to branch master at Debian Security Tracker / security-tracker Commits: fb9655c9 by Michael Gilbert at 2019-02-27T14:13:04Z chromium regression dsa - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list ===

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1692-1 for phpmyadmin

2019-02-27 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: db06eeb8 by Sylvain Beucler at 2019-02-27T13:49:01Z Reserve DLA-1692-1 for phpmyadmin - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add note to openssh.

2019-02-27 Thread Mike Gabriel
-needed.txt = @@ -95,6 +95,8 @@ nss openjdk-7 (Emilio) -- openssh (Mike Gabriel) + NOTE: 20190227: Work in progress. First draft is still vulnerable to PoC: https://www.exploit-db.com/exploits/46193 + NOTE: 20190227: Problematic is that jessie's / whe

[Git][security-tracker-team/security-tracker][master] automatic update

2019-02-27 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c906253 by security tracker role at 2019-02-27T08:10:55Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===