[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim libspring-security-2.0-java

2019-07-07 Thread Abhijith PA
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker Commits: cba50bb4 by Abhijith PA at 2019-07-08T05:39:51Z data/dla-needed.txt: Claim libspring-security-2.0-java - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: work is still ongoing on this one

2019-07-07 Thread Adrian Bunk
is ongoing + NOTE: 20190707: work is ongoing -- libqb NOTE: 20190616: Upstream patch does not apply at all, but it appears that View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2de51d7945e5541af8c6c1c0433359ebcdd1a248 -- View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] automatic update

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 68560c4b by security tracker role at 2019-07-07T20:10:25Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] jasperreports removed from unstable

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 38c1fb07 by Salvatore Bonaccorso at 2019-07-07T19:17:49Z jasperreports removed from unstable - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1846-1 for unzip

2019-07-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: da78e550 by Markus Koschany at 2019-07-07T18:29:12Z Reserve DLA-1846-1 for unzip - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Track some fixes for binutils via unstable

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8f22861a by Salvatore Bonaccorso at 2019-07-07T17:32:08Z Track some fixes for binutils via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-1845-1 for dosbox

2019-07-07 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4c937c8c by Markus Koschany at 2019-07-07T17:17:28Z Reserve DLA-1845-1 for dosbox - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add fixed version for two CVEs affecting mupdf in unstable

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 564d13f7 by Salvatore Bonaccorso at 2019-07-07T15:42:01Z Add fixed version for two CVEs affecting mupdf in unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add note re. golang-go.crypto

2019-07-07 Thread Chris Lamb
= @@ -33,6 +33,7 @@ glib2.0 (Mike Gabriel) NOTE: 20190626: https://lists.debian.org/debian-lts/2019/06/msg00031.html -- golang-go.crypto + NOTE: 20190707: Check that an upload of this will not require reverse build-deps to also be recompiled (see previous golang

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim squid3.

2019-07-07 Thread Chris Lamb
(Chris Lamb) NOTE: 20190707: 2 XSS: first one unaffected AFAICS, second one reflected NOTE: 20190707: cachemgr.cgi allows sensitive operations if authenticated (beuc) -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit

[Git][security-tracker-team/security-tracker][master] CVE-2019-11841/golang-go.crypto: jessie triage

2019-07-07 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: a86514bc by Sylvain Beucler at 2019-07-07T11:06:35Z CVE-2019-11841/golang-go.crypto: jessie triage - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] taking another week this month

2019-07-07 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: e0961e6c by Thorsten Alteholz at 2019-07-07T10:10:54Z taking another week this month - - - - - 1 changed file: - org/lts-frontdesk.2019.txt Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-13345/squid3: jessie triage

2019-07-07 Thread Sylvain Beucler
+ NOTE: 20190707: 2 XSS: first one unaffected AFAICS, second one reflected + NOTE: 20190707: cachemgr.cgi allows sensitive operations if authenticated (beuc) +-- squirrelmail NOTE: 20190702: no patch available, upstream apparently inactive, NOTE: 20190702: reporter just recommends

[Git][security-tracker-team/security-tracker][master] CVE-2019-13351/jackd2: jessie: fix package name

2019-07-07 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b4454c2 by Sylvain Beucler at 2019-07-07T09:27:14Z CVE-2019-13351/jackd2: jessie: fix package name - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track gitlab/11.10.8 upload to experimental for easier merge fixing version...

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 391e82c8 by Salvatore Bonaccorso at 2019-07-07T08:41:56Z Track gitlab/11.10.8 upload to experimental for easier merge fixing version once uploaded to unstable again - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c8733df by Salvatore Bonaccorso at 2019-07-07T08:39:20Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c7dbd5db by security tracker role at 2019-07-07T08:36:31Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Disable fetching of backports

2019-07-07 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 02cd33cd by Salvatore Bonaccorso at 2019-07-07T08:28:45Z Disable fetching of backports They ship Packages/Sources.gz only and backports is anyway not very good supported in tracker. Until