[Git][security-tracker-team/security-tracker][master] Add CVE-2019-1485{0,1}/nbdkit

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0150ec78 by Salvatore Bonaccorso at 2019-10-02T06:15:14Z Add CVE-2019-1485{0,1}/nbdkit - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] CVE-2019-16935/python3.7 fixed in unstable via 3.7.5~rc1-1 upload

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 048ca31b by Salvatore Bonaccorso at 2019-10-02T05:30:43Z CVE-2019-16935/python3.7 fixed in unstable via 3.7.5~rc1-1 upload - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2019-16935/python3.8 fixed in unstable with 3.8.0~rc1-1 upload

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6987b251 by Salvatore Bonaccorso at 2019-10-02T05:29:18Z CVE-2019-16935/python3.8 fixed in unstable with 3.8.0~rc1-1 upload - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS/claim libreoffice

2019-10-01 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: fcbc9e84 by Roberto C. Sánchez at 2019-10-02T01:31:52Z LTS/claim libreoffice - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.t

[Git][security-tracker-team/security-tracker][master] Add libapreq2 to dsa-needed list

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d399596b by Salvatore Bonaccorso at 2019-10-01T21:14:02Z Add libapreq2 to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: = da

[Git][security-tracker-team/security-tracker][master] Process some more NFUs

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b19e6198 by Salvatore Bonaccorso at 2019-10-01T20:46:08Z Process some more NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-1694{2,3}/jackson-databind

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7ae24421 by Salvatore Bonaccorso at 2019-10-01T20:44:32Z Add Debian bug reference for CVE-2019-1694{2,3}/jackson-databind - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2019-17068/putty

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e7860091 by Salvatore Bonaccorso at 2019-10-01T20:43:12Z Update information for CVE-2019-17068/putty - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] 2 commits: Add fixing commit for CVE-2019-17069/putty

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7a585d09 by Salvatore Bonaccorso at 2019-10-01T20:38:58Z Add fixing commit for CVE-2019-17069/putty - - - - - 959f2b2b by Salvatore Bonaccorso at 2019-10-01T20:40:05Z Merge remote-tracking bran

[Git][security-tracker-team/security-tracker][master] putty non-issue

2019-10-01 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f6b32151 by Moritz Muehlenhoff at 2019-10-01T20:36:28Z putty non-issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-1694{2,3}/jackson-databind

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5413ffad by Salvatore Bonaccorso at 2019-10-01T20:29:57Z Add CVE-2019-1694{2,3}/jackson-databind - - - - - 1 changed file: - data/CVE/list Changes: = d

[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 433fa4ba by Salvatore Bonaccorso at 2019-10-01T20:20:29Z Process some NFUs - - - - - f17f6a50 by Salvatore Bonaccorso at 2019-10-01T20:20:30Z Add CVE-2019-1706{7,8,9}/putty - - - - - 1 chang

[Git][security-tracker-team/security-tracker][master] openssl DSAs

2019-10-01 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b84607d5 by Moritz Muehlenhoff at 2019-10-01T20:11:52Z openssl DSAs - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] automatic update

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 26b2e6d9 by security tracker role at 2019-10-01T20:10:24Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-1705{2,3,4,5,6}/linux

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b736972b by Salvatore Bonaccorso at 2019-10-01T19:26:57Z Add CVE-2019-1705{2,3,4,5,6}/linux All come from the individual commits in the "Merge branch 'check-CAP_NEW_RAW'". - - - - - 1 change

[Git][security-tracker-team/security-tracker][master] CVE-2019-12401 add additional reference for the upstream fix

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 21e05ccd by Salvatore Bonaccorso at 2019-10-01T19:16:16Z CVE-2019-12401 add additional reference for the upstream fix - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Add back original CVE assignment reference for CVE-2019-13504

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c92e2756 by Salvatore Bonaccorso at 2019-10-01T19:09:19Z Add back original CVE assignment reference for CVE-2019-13504 The pull request is direct reference back to the CVE assignment, so add it

[Git][security-tracker-team/security-tracker][master] Remove now TODO items for CVE-2019-14369 and CVE-2019-14370 after check

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8fc47a8e by Salvatore Bonaccorso at 2019-10-01T19:06:46Z Remove now TODO items for CVE-2019-14369 and CVE-2019-14370 after check - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] CVE-2019-12401/lucene-solr: issue potentially in dependencies

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f3e010dc by Sylvain Beucler at 2019-10-01T16:29:13Z CVE-2019-12401/lucene-solr: issue potentially in dependencies - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] CVE-2019-0193/lucene-solr: reference commit, request dla

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 33ed8623 by Sylvain Beucler at 2019-10-01T16:16:09Z CVE-2019-0193/lucene-solr: reference commit, request dla - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] dla: add libapreq2

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 814c1d28 by Sylvain Beucler at 2019-10-01T15:29:15Z dla: add libapreq2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt ==

[Git][security-tracker-team/security-tracker][master] CVE-2019-16370,CVE-2019-15052/gradle: jessie postponed

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: f1f984cb by Sylvain Beucler at 2019-10-01T15:25:15Z CVE-2019-16370,CVE-2019-15052/gradle: jessie postponed - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] dla: add thunderbird

2019-10-01 Thread Sylvain Beucler
= @@ -136,6 +136,10 @@ slurm-llnl -- spip (Thorsten Alteholz) -- +thunderbird + NOTE: 20191001: CVE-2019-11755: bug is private, not sure whether to backport to 60esr or wait for 68esr (Beuc) + NOTE: 20191001: CVE-2019-11755: https://bugzilla.mozilla.org

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2019-13504/exiv2: reference main patch

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 977f6619 by Sylvain Beucler at 2019-10-01T14:16:10Z CVE-2019-13504/exiv2: reference main patch - - - - - 73c05f3f by Sylvain Beucler at 2019-10-01T14:16:17Z CVE-2019-14369,CVE-2019-14370/exiv2: jess

[Git][security-tracker-team/security-tracker][master] NFUs

2019-10-01 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cb71fc38 by Moritz Muehlenhoff at 2019-10-01T13:43:59Z NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] CVE-2018-20839/xorg-server: precise triage

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0170b407 by Sylvain Beucler at 2019-10-01T11:44:48Z CVE-2018-20839/xorg-server: precise triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] CVE-2019-13376/phpbb3: clear-up confusion following my registering...

2019-10-01 Thread Sylvain Beucler
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 9c1aa9a4 by Sylvain Beucler at 2019-10-01T11:22:53Z CVE-2019-13376/phpbb3: clear-up confusion following my registering CVE-2019-16993 (earlier vulnerability with incomplete fix) - - - - - 2 chang

[Git][security-tracker-team/security-tracker][master] new undertow issue

2019-10-01 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b0b5d914 by Moritz Muehlenhoff at 2019-10-01T10:39:55Z new undertow issue NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] buster/stretch triage

2019-10-01 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: de6118ef by Moritz Muehlenhoff at 2019-10-01T10:17:24Z buster/stretch triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fdc8679 by Salvatore Bonaccorso at 2019-10-01T08:55:05Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] dla-needed: claim clamav and openjpeg2

2019-10-01 Thread Hugo Lefeuvre
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker Commits: 6dbde8cf by Hugo Lefeuvre at 2019-10-01T08:46:18Z dla-needed: claim clamav and openjpeg2 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-n

[Git][security-tracker-team/security-tracker][master] automatic update

2019-10-01 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c462bcb2 by security tracker role at 2019-10-01T08:10:12Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =