[Git][security-tracker-team/security-tracker][master] data/CVE/list: Mark freerdp/stretch as not affected by CVE-2020-15103.

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 02fab9be by Mike Gabriel at 2020-08-30T01:59:19+02:00 data/CVE/list: Mark freerdp/stretch as not affected by CVE-2020-15103. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: re-add freerdp and claim it, more issues to look at in more depth

2020-08-29 Thread Mike Gabriel
Changes: = data/dla-needed.txt = @@ -72,6 +72,8 @@ firefox-esr (Emilio) -- fossil (Mike Gabriel) -- +freerdp (Mike Gabriel) +-- gnome-shell (Mike Gabriel) NOTE: 20200829: https://salsa.debian.org/gnome-team/gnome-shell

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2356-1 for freerdp

2020-08-29 Thread Mike Gabriel
(Emilio) -- fossil (Mike Gabriel) -- -freerdp (Mike Gabriel) - NOTE: 20200510: Vulnerable to at least CVE-2020-11042. (lamby) --- gnome-shell (Mike Gabriel) NOTE: 20200829: https://salsa.debian.org/gnome-team/gnome-shell/-/merge_requests/41 (sunweaver) -- View it on GitLab: https

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Revert the idea of EOL'ing freerdp. The Ubuntu security...

2020-08-29 Thread Mike Gabriel
-11042. (lamby) - NOTE: 20200531: Discussing if EOL'ing of freerdp (1.1) makes sense (sunweaver) - NOTE: 20200815: freerdp 1.1 will be EOL'ed this month (sunweaver) -- gnome-shell (Mike Gabriel) NOTE: 20200829: https://salsa.debian.org/gnome-team/gnome-shell/-/merge_requests/41 (sunweaver

[Git][security-tracker-team/security-tracker][master] Ola claims ceph.

2020-08-29 Thread Ola Lundqvist
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: be8b0f21 by Ola Lundqvist at 2020-08-29T23:38:04+02:00 Ola claims ceph. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2355-1 for bind9

2020-08-29 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: dcd41971 by Thorsten Alteholz at 2020-08-29T23:28:06+02:00 Reserve DLA-2355-1 for bind9 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2354-1 for ndpi

2020-08-29 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: d6ca2798 by Thorsten Alteholz at 2020-08-29T23:20:33+02:00 Reserve DLA-2354-1 for ndpi - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2353-1 for bacula

2020-08-29 Thread Thorsten Alteholz
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 597deb05 by Thorsten Alteholz at 2020-08-29T23:17:20+02:00 Reserve DLA-2353-1 for bacula - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add notes for CVE-2019-12095/php-horde-trean.

2020-08-29 Thread Mike Gabriel
: = data/dla-needed.txt = @@ -133,6 +133,8 @@ opendmarc openexr (Adrian Bunk) -- php-horde-trean (Mike Gabriel) + NOTE: 20200829: Reconsidering CVE-2019-12095 and what has been written in https://bugs.horde.org/ticket/14926 (sunweaver

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add note for gnome-shell.

2020-08-29 Thread Mike Gabriel
: = data/dla-needed.txt = @@ -82,6 +82,7 @@ freerdp (Mike Gabriel) NOTE: 20200815: freerdp 1.1 will be EOL'ed this month (sunweaver) -- gnome-shell (Mike Gabriel) + NOTE: 20200829: https://salsa.debian.org/gnome-team/gnome-shell/-/merge_requests/41 (sunweaver

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Typo fix in pkg name.

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 72d2321b by Mike Gabriel at 2020-08-29T22:25:07+02:00 data/dla-needed.txt: Typo fix in pkg name. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 44277987 by security tracker role at 2020-08-29T20:10:21+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2352-1 for php-horde-gollem

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 19180022 by Mike Gabriel at 2020-08-29T22:02:34+02:00 Reserve DLA-2352-1 for php-horde-gollem - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2351-1 for php-horde-kronolith

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: be5460f5 by Mike Gabriel at 2020-08-29T21:49:53+02:00 Reserve DLA-2351-1 for php-horde-kronolith - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2350-1 for php-horde-kronolith

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 92bcaa0a by Mike Gabriel at 2020-08-29T21:36:13+02:00 Reserve DLA-2350-1 for php-horde-kronolith - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Mark CVE-2020-5818 as fixed by php-horde-data 2.1.5-1 (uploaded in 07/2020).

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: be8f145c by Mike Gabriel at 2020-08-29T21:15:40+02:00 data/CVE/list: Mark CVE-2020-5818 as fixed by php-horde-data 2.1.5-1 (uploaded in 07/2020). - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Take apache2 from dsa-needed list

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bb188283 by Salvatore Bonaccorso at 2020-08-29T20:55:06+02:00 Take apache2 from dsa-needed list - - - - - 1 changed file: - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entry for CVE-2020-14347

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d139e859 by Salvatore Bonaccorso at 2020-08-29T19:52:53+02:00 Remove no-dsa tagged entry for CVE-2020-14347 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] thunderbird, lilypond, openexr DSAs

2020-08-29 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f95756e4 by Moritz Muehlenhoff at 2020-08-29T19:26:59+02:00 thunderbird, lilypond, openexr DSAs - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Regroup entries by source packages

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 51fd398f by Salvatore Bonaccorso at 2020-08-29T17:51:40+02:00 Regroup entries by source packages - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-11984/apache2 as not-affected and add uwsgi

2020-08-29 Thread Utkarsh Gupta
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 76ae2bc3 by Utkarsh Gupta at 2020-08-29T21:15:27+05:30 Mark CVE-2020-11984/apache2 as not-affected and add uwsgi - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2020-25016/rust-rgb assigned for RUSTSEC-2020-0029 issue

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 85795bf8 by Salvatore Bonaccorso at 2020-08-29T17:42:49+02:00 CVE-2020-25016/rust-rgb assigned for RUSTSEC-2020-0029 issue - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2349-1 for php-horde

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 415e3b18 by Mike Gabriel at 2020-08-29T17:38:52+02:00 Reserve DLA-2349-1 for php-horde - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2348-1 for php-horde-core

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: c0056003 by Mike Gabriel at 2020-08-29T17:36:49+02:00 Reserve DLA-2348-1 for php-horde-core - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-11984 and add uwsgi

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 66bbaf69 by Salvatore Bonaccorso at 2020-08-29T17:29:59+02:00 Update information on CVE-2020-11984 and add uwsgi uwsgi embedds apache2/mod_proxy_uwsgi.c which has the issue. But since

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for mupdf update

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9a2fe840 by Salvatore Bonaccorso at 2020-08-29T16:58:04+02:00 Reserve DSA number for mupdf update - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for rust-rgb for tracking (given no CVE assigned)

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 90268d7e by Salvatore Bonaccorso at 2020-08-29T13:52:14+02:00 Add Debian bug reference for rust-rgb for tracking (given no CVE assigned) - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Remove two no-dsa tagged entries which will be contained in update

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a95b78be by Salvatore Bonaccorso at 2020-08-29T13:38:38+02:00 Remove two no-dsa tagged entries which will be contained in update - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Sync note for CVE-2020-17489

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c161f4f2 by Salvatore Bonaccorso at 2020-08-29T12:38:14+02:00 Sync note for CVE-2020-17489 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] dla: take thunderbird

2020-08-29 Thread Emilio Pozuelo Monfort
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: a351e6ed by Emilio Pozuelo Monfort at 2020-08-29T12:18:13+02:00 dla: take thunderbird - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: data/dla-needed.txt: Add various php-horde-* components and claim them.

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 73171607 by Mike Gabriel at 2020-08-29T12:06:32+02:00 data/dla-needed.txt: Add various php-horde-* components and claim them. - - - - - 42e89034 by Mike Gabriel at 2020-08-29T12:09:02+02:00

[Git][security-tracker-team/security-tracker][master] Revert "data/dla-needed.txt: Drop gnome-shell, nothing to be done (see prev commit)."

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 89d26b8b by Mike Gabriel at 2020-08-29T11:54:10+02:00 Revert data/dla-needed.txt: Drop gnome-shell, nothing to be done (see prev commit). This reverts commit a94c4ff91126b3ff31e2035dce97749e9614898b

[Git][security-tracker-team/security-tracker][master] Add CVE-2019-19499/grafana

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1ba37de3 by Salvatore Bonaccorso at 2020-08-29T10:56:01+02:00 Add CVE-2019-19499/grafana - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process NFUs

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69e9747c by Salvatore Bonaccorso at 2020-08-29T10:55:36+02:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2020-08-29 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 31294e14 by security tracker role at 2020-08-29T08:10:17+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Drop gnome-shell, nothing to be done (see prev commit).

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: a94c4ff9 by Mike Gabriel at 2020-08-29T08:16:49+02:00 data/dla-needed.txt: Drop gnome-shell, nothing to be done (see prev commit). - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] data/CVE/list: Mark gnome-shell/stretch and gnome-shell/buster as not affected by CVE-2020-17489.

2020-08-29 Thread Mike Gabriel
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker Commits: 11b15e87 by Mike Gabriel at 2020-08-29T08:02:24+02:00 data/CVE/list: Mark gnome-shell/stretch and gnome-shell/buster as not affected by CVE-2020-17489. - - - - - 1 changed file: - data/CVE/list