[Git][security-tracker-team/security-tracker][master] Add CVE-2021-37576/linux

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b76d745 by Salvatore Bonaccorso at 2021-07-27T08:46:44+02:00 Add CVE-2021-37576/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2021-32610/php-pear

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b1696be by Salvatore Bonaccorso at 2021-07-27T08:04:12+02:00 Add Debian bug reference for CVE-2021-32610/php-pear - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-32610/php-pear

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5dbc4520 by Salvatore Bonaccorso at 2021-07-27T07:55:47+02:00 Add CVE-2021-32610/php-pear - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] libsndfile fixed in sid

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c26da86a by Moritz Muehlenhoff at 2021-07-26T23:22:40+02:00 libsndfile fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] mark nvidia 340 issues as ignored since it's EOLed by Nvidia

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f5c77df6 by Moritz Muehlenhoff at 2021-07-26T22:59:08+02:00 mark nvidia 340 issues as ignored since it's EOLed by Nvidia - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] LTS: mark CVE-2020-22030 as not-affected for stretch

2021-07-26 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: 40706453 by Anton Gladky at 2021-07-26T22:53:51+02:00 LTS: mark CVE-2020-22030 as not-affected for stretch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2021-31811 and CVE-2021-31812 issues

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d9aad2bf by Salvatore Bonaccorso at 2021-07-26T22:46:41+02:00 Add Debian bug reference for CVE-2021-31811 and CVE-2021-31812 issues - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] LTS: mark CVE-2020-22029 as not-affected for stretch

2021-07-26 Thread Anton Gladky (@gladk)
Anton Gladky pushed to branch master at Debian Security Tracker / security-tracker Commits: ec0fc3c4 by Anton Gladky at 2021-07-26T22:33:38+02:00 LTS: mark CVE-2020-22029 as not-affected for stretch - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] nvidia spu

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 81be7fe0 by Moritz Mühlenhoff at 2021-07-26T22:28:29+02:00 nvidia spu - - - - - 1 changed file: - data/next-point-update.txt Changes: = data/next-point-u

[Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2021-23413/node-jszip via unstable

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6278e749 by Salvatore Bonaccorso at 2021-07-26T22:23:54+02:00 Add fixed version for CVE-2021-23413/node-jszip via unstable - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3279{1,2}/libapache2-mod-auth-openidc

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b8225e3 by Salvatore Bonaccorso at 2021-07-26T22:23:00+02:00 Add CVE-2021-3279{1,2}/libapache2-mod-auth-openidc - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6d6ef59b by Salvatore Bonaccorso at 2021-07-26T22:22:26+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 64d871e9 by Salvatore Bonaccorso at 2021-07-26T22:13:12+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ac37867a by security tracker role at 2021-07-26T20:10:32+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-36754/pdns

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 38df4b11 by Salvatore Bonaccorso at 2021-07-26T21:26:29+02:00 Add CVE-2021-36754/pdns - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] dsa-needed: Update note for jetty9

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ec427c48 by Salvatore Bonaccorso at 2021-07-26T21:02:41+02:00 dsa-needed: Update note for jetty9 - - - - - 1 changed file: - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Remove TODO for CVE-2021-33900/apache-directory-server

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3c8a2c2b by Salvatore Bonaccorso at 2021-07-26T21:01:06+02:00 Remove TODO for CVE-2021-33900/apache-directory-server - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] CVE-2021-24119: Add information that issue is fixed in 2.26.0 upstream

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dc91fe7 by Salvatore Bonaccorso at 2021-07-26T20:53:48+02:00 CVE-2021-24119: Add information that issue is fixed in 2.26.0 upstream - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Add upstream references for CVE-2020-1949{1,2}

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 58db73b3 by Salvatore Bonaccorso at 2021-07-26T20:48:28+02:00 Add upstream references for CVE-2020-1949{1,2} - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] CVE-2019-25050: Only reference the fixing commit

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 20e89fbe by Salvatore Bonaccorso at 2021-07-26T20:40:42+02:00 CVE-2019-25050: Only reference the fixing commit The issue was found by fuzzing gdal, and there are two set of introducing commits

[Git][security-tracker-team/security-tracker][master] Add CVE id reference for drupal7 issue

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4b82c384 by Salvatore Bonaccorso at 2021-07-26T20:33:01+02:00 Add CVE id reference for drupal7 issue - - - - - 2 changed files: - data/CVE/list - data/DLA/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Reserve DLA-2721-1 for drupal7

2021-07-26 Thread Gunnar Wolf (@gwolf)
Gunnar Wolf pushed to branch master at Debian Security Tracker / security-tracker Commits: 02716be2 by Gunnar Wolf at 2021-07-26T12:14:10-05:00 Reserve DLA-2721-1 for drupal7 - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Claim drupal7 in dla-needed.txt

2021-07-26 Thread Gunnar Wolf (@gwolf)
Gunnar Wolf pushed to branch master at Debian Security Tracker / security-tracker Commits: 522f8abc by Gunnar Wolf at 2021-07-26T12:10:11-05:00 Claim drupal7 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.

[Git][security-tracker-team/security-tracker][master] edk2 fixed in sid

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cd46735d by Moritz Muehlenhoff at 2021-07-26T18:17:44+02:00 edk2 fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new libmatio, mbedtls issues (concludes external check)

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b93faf35 by Moritz Muehlenhoff at 2021-07-26T15:46:02+02:00 new libmatio, mbedtls issues (concludes external check) - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2019-11098/edk2 via experimental

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 59b966ab by Salvatore Bonaccorso at 2021-07-26T15:41:59+02:00 Track fixed version for CVE-2019-11098/edk2 via experimental - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] "new" libheif issues

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: a7ffa61e by Moritz Muehlenhoff at 2021-07-26T15:04:52+02:00 "new" libheif issues NFUs also track the other two intel GPU issues as ignored for Linux - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e9f6badf by Salvatore Bonaccorso at 2021-07-26T14:39:29+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] "new" gdal issue

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 82810613 by Moritz Muehlenhoff at 2021-07-26T12:30:42+02:00 "new" gdal issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] bullseye triage

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e509178e by Moritz Muehlenhoff at 2021-07-26T12:08:33+02:00 bullseye triage - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

Re: [Git][security-tracker-team/security-tracker][master] bin/lts-needs-forward-port: fix lib path

2021-07-26 Thread Sylvain Beucler
Hi Emilio, On Mon, Jul 26, 2021 at 11:05:37AM +0200, Emilio Pozuelo Monfort wrote: > On 24/07/2021 15:10, Sylvain Beucler (@beuc) wrote: > > 64051666 by Sylvain Beucler at 2021-07-24T15:09:33+02:00 > > bin/lts-needs-forward-port: fix lib path > > - - - - - > > =

Re: [Git][security-tracker-team/security-tracker][master] bin/lts-needs-forward-port: fix lib path

2021-07-26 Thread Emilio Pozuelo Monfort
Hi Sylvain, On 24/07/2021 15:10, Sylvain Beucler (@beuc) wrote: 64051666 by Sylvain Beucler at 2021-07-24T15:09:33+02:00 bin/lts-needs-forward-port: fix lib path - - - - - = bin/lts-needs-forward-port.py = @@ -19,9 +19,9 @@

[Git][security-tracker-team/security-tracker][master] automatic update

2021-07-26 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9ee8450b by security tracker role at 2021-07-26T08:10:17+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update notes for condor and ceph in dla-needed.txt

2021-07-26 Thread Markus Koschany (@apo)
(after testing it). NOTE: 20210118: wip (Emilio) + NOTE: 20210726: https://people.debian.org/~apo/lts/ceph/ + NOTE: 20210726: Patch for CVE-2018-16846 is not complete yet. -- condor (Markus Koschany) NOTE: 20200502: Upstream has only released workarounds; complete fix is still embargoed

[Git][security-tracker-team/security-tracker][master] new node-jszip issue

2021-07-26 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: c3f47c16 by Moritz Muehlenhoff at 2021-07-26T09:35:01+02:00 new node-jszip issue NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list