[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2019-19906/cyrus-sasl2

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 65d4bebb by Salvatore Bonaccorso at 2019-12-20T07:31:17Z Add Debian bug reference for CVE-2019-19906/cyrus-sasl2 - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] add missing CVE ID

2019-12-19 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f96117fa by Moritz Muehlenhoff at 2019-12-19T23:05:52Z add missing CVE ID - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] add and take mediawiki

2019-12-19 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c47b6f96 by Moritz Muehlenhoff at 2019-12-19T22:53:01Z add and take mediawiki - - - - - 1 changed file: - data/dsa-needed.txt Changes: = data/dsa-needed.

[Git][security-tracker-team/security-tracker][master] cyrus-imapd DSA

2019-12-19 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a4b203de by Moritz Muehlenhoff at 2019-12-19T22:50:14Z cyrus-imapd DSA - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] claim php5

2019-12-19 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 411e231e by Thorsten Alteholz at 2019-12-19T22:28:26Z claim php5 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt ==

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: add php5

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 37cb804e by Mike Gabriel at 2019-12-19T21:34:23Z data/dla-needed.txt: add php5 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: add cyrus-sasl2 and claim it

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 6aff0bc6 by Mike Gabriel at 2019-12-19T21:33:28Z data/dla-needed.txt: add cyrus-sasl2 and claim it - - - - - 1 changed file: - data/dla-needed.txt Changes: = d

[Git][security-tracker-team/security-tracker][master] data/CVE/list: tightvnc also affected by CVE-2018-20022

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 92c154c2 by Mike Gabriel at 2019-12-19T20:41:18Z data/CVE/list: tightvnc also affected by CVE-2018-20022 - - - - - 1 changed file: - data/CVE/list Changes: = d

[Git][security-tracker-team/security-tracker][master] data/CVE/list: tightvnc also affected by CVE-2018-20020

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 21a8829a by Mike Gabriel at 2019-12-19T20:35:35Z data/CVE/list: tightvnc also affected by CVE-2018-20020 - - - - - 1 changed file: - data/CVE/list Changes: = d

[Git][security-tracker-team/security-tracker][master] data/CVE/list: tightvnc also affected by CVE-2018-20021

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 06e8aca4 by Mike Gabriel at 2019-12-19T20:33:25Z data/CVE/list: tightvnc also affected by CVE-2018-20021 - - - - - 1 changed file: - data/CVE/list Changes: = d

[Git][security-tracker-team/security-tracker][master] Track new CVEs for Backdrop CMS (itp'ed as #914257)

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 20f1c46b by Salvatore Bonaccorso at 2019-12-19T20:28:08Z Track new CVEs for Backdrop CMS (itp'ed as #914257) - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-19907/kopanocore

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 88f0fbc9 by Salvatore Bonaccorso at 2019-12-19T20:26:53Z Add CVE-2019-19907/kopanocore - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] Process NFUs

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5f8871fe by Salvatore Bonaccorso at 2019-12-19T20:27:38Z Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] Add cyrus-sasl2 to dsa-needed list

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7984bc7b by Salvatore Bonaccorso at 2019-12-19T20:12:28Z Add cyrus-sasl2 to dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9309bf05 by security tracker role at 2019-12-19T20:10:18Z automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] data/CVE/list: tightvnc also affected by CVE-2018-7225

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ad284c4 by Mike Gabriel at 2019-12-19T20:03:12Z data/CVE/list: tightvnc also affected by CVE-2018-7225 - - - - - 1 changed file: - data/CVE/list Changes: = da

[Git][security-tracker-team/security-tracker][master] 2 commits: data/CVE/list: for CVE-2019-15681, also apply tags to italc and vino

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 384f153b by Mike Gabriel at 2019-12-19T19:56:43Z data/CVE/list: for CVE-2019-15681, also apply tags to italc and vino - - - - - 5b85ab8c by Mike Gabriel at 2019-12-19T19:57:59Z data/CVE/list:

[Git][security-tracker-team/security-tracker][master] data/CVE/list: mark currently open CVEs for libjpeg-turbo as resolved in experimental

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 5044d4e0 by Mike Gabriel at 2019-12-19T19:53:20Z data/CVE/list: mark currently open CVEs for libjpeg-turbo as resolved in experimental - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-19906/cyrus-sasl2

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fb5c123 by Salvatore Bonaccorso at 2019-12-19T19:43:36Z Add CVE-2019-19906/cyrus-sasl2 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/l

[Git][security-tracker-team/security-tracker][master] CVE-2019-19905/nethack assigned

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 743b5094 by Salvatore Bonaccorso at 2019-12-19T19:35:16Z CVE-2019-19905/nethack assigned - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/

[Git][security-tracker-team/security-tracker][master] 2 commits: issues fixed now

2019-12-19 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: a12d6da7 by Thorsten Alteholz at 2019-12-19T18:34:57Z issues fixed now - - - - - c15d7722 by Thorsten Alteholz at 2019-12-19T18:34:57Z Reserve DLA-2043-1 for gdk-pixbuf - - - - - 2 changed file

[Git][security-tracker-team/security-tracker][master] Add note for ruby-rack

2019-12-19 Thread Utkarsh Gupta
= @@ -86,6 +86,8 @@ radare2 ruby-excon (Utkarsh Gupta) -- ruby-rack + NOTE: 20191219: The security update causes a regression and also, there's a + NOTE: slight possibility of this patch inducing a backdoor on its own. (utkarsh2102) -- ruby-rack-cors (Ut

[Git][security-tracker-team/security-tracker][master] data/CVE/list: mark CVE-2019-2201/libjpeg-turbo as already fixed in experimental

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 81d15124 by Mike Gabriel at 2019-12-19T15:46:31Z data/CVE/list: mark CVE-2019-2201/libjpeg-turbo as already fixed in experimental - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Claim packages and update notes

2019-12-19 Thread Utkarsh Gupta
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 3f6129cb by Utkarsh Gupta at 2019-12-19T15:33:20Z Claim packages and update notes Roberto ack'ed for me to take over opensc - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] add mediawiki reference

2019-12-19 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c200d447 by Moritz Muehlenhoff at 2019-12-19T14:29:27Z add mediawiki reference nethack no-dsa - - - - - 1 changed file: - data/CVE/list Changes: = data/C

[Git][security-tracker-team/security-tracker][master] data/{dla-needed.txt,CVE/list}: CVE-2019-2201/libjpeg-turbo only gets...

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 54231ea5 by Mike Gabriel at 2019-12-19T13:58:25Z data/{dla-needed.txt,CVE/list}: CVE-2019-2201/libjpeg-turbo only gets triggered via TurboJPEG API. There is no package in Debian jessie that uses the Tu

[Git][security-tracker-team/security-tracker][master] Revert "Two CVEs CVE-2019-5870 and CVE-2019-13720 are associated as well with...

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f5423498 by Salvatore Bonaccorso at 2019-12-19T13:11:25Z Revert "Two CVEs CVE-2019-5870 and CVE-2019-13720 are associated as well with qtwebengine-opensource-src" It is explicitly not supporte

[Git][security-tracker-team/security-tracker][master] Add new issue in nethack

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0ddad249 by Salvatore Bonaccorso at 2019-12-19T12:15:22Z Add new issue in nethack - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] Two CVEs CVE-2019-5870 and CVE-2019-13720 are associated as well with qtwebengine-opensource-src

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 16987dc6 by Salvatore Bonaccorso at 2019-12-19T12:03:19Z Two CVEs CVE-2019-5870 and CVE-2019-13720 are associated as well with qtwebengine-opensource-src - - - - - 1 changed file: - data/CV

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim libjpeg-turbo

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: ed51bb93 by Mike Gabriel at 2019-12-19T11:57:33Z data/dla-needed.txt: claim libjpeg-turbo - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-n

[Git][security-tracker-team/security-tracker][master] Correct source package name

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2242b97a by Salvatore Bonaccorso at 2019-12-19T11:56:10Z Correct source package name - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] data/{dla-needed.txt,CVE/list}: triage transfix/jessie regarding CVE-2019-19797

2019-12-19 Thread Mike Gabriel
= @@ -111,6 +111,9 @@ tightvnc (Mike Gabriel) NOTE: 20191030: has open issues on its own and NOTE: 20191030: contains non-security-maintained code from libvncserver (sunweaver) -- +transfig + NOTE: 20191219: and unimportant issues only (sunweaver) +-- wordpress NOTE

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: add ruby-rack

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: b5daa238 by Mike Gabriel at 2019-12-19T11:50:47Z data/dla-needed.txt: add ruby-rack - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.

[Git][security-tracker-team/security-tracker][master] Add new php issues

2019-12-19 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f54b4eb by Salvatore Bonaccorso at 2019-12-19T11:43:45Z Add new php issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] data/CVE/list: For npm/jessie mark CVE-2019-1677{5,6,7} as ignored.

2019-12-19 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 787c67ba by Mike Gabriel at 2019-12-19T11:37:39Z data/CVE/list: For npm/jessie mark CVE-2019-1677{5,6,7} as ignored. - - - - - 1 changed file: - data/CVE/list Changes: ===