[Git][security-tracker-team/security-tracker][master] Add CVE-2021-43337/slurm-wlm

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f2088928 by Salvatore Bonaccorso at 2021-11-17T08:30:10+01:00 Add CVE-2021-43337/slurm-wlm - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3917 as NFU

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0615f678 by Salvatore Bonaccorso at 2021-11-17T08:24:02+01:00 Add CVE-2021-3917 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3935/pgbouncer

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 31bff9aa by Salvatore Bonaccorso at 2021-11-17T08:22:40+01:00 Add CVE-2021-3935/pgbouncer - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3943/moodle

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 38058b0c by Salvatore Bonaccorso at 2021-11-17T08:19:08+01:00 Add CVE-2021-3943/moodle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3962/imagemagick

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 904814ad by Salvatore Bonaccorso at 2021-11-17T08:18:20+01:00 Add CVE-2021-3962/imagemagick - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-42114 as NFU

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 875b815f by Salvatore Bonaccorso at 2021-11-17T08:15:00+01:00 Add CVE-2021-42114 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-202-143558/moodle

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 01419775 by Salvatore Bonaccorso at 2021-11-17T08:12:21+01:00 Add CVE-202-143558/moodle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-43559/moodle

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6bc14cd0 by Salvatore Bonaccorso at 2021-11-17T08:11:45+01:00 Add CVE-2021-43559/moodle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-43560/moodle

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a14ba88c by Salvatore Bonaccorso at 2021-11-17T08:10:56+01:00 Add CVE-2021-43560/moodle - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update status for CVE-2019-3686/openqa

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 99ce2e30 by Salvatore Bonaccorso at 2021-11-17T08:09:49+01:00 Update status for CVE-2019-3686/openqa - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: CVEs of atftp postponed until now

2021-11-16 Thread Thorsten Alteholz (@alteholz)
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker Commits: 20a7383c by Thorsten Alteholz at 2021-11-17T01:25:05+01:00 CVEs of atftp postponed until now - - - - - f130652d by Thorsten Alteholz at 2021-11-17T01:25:46+01:00 Reserve DLA-2820-1 for atftp - -

Processing 31f166206ca0eff8c65f8f92baf614d4071d094f failed

2021-11-16 Thread security tracker role
The error message was: data/CVE/list:189050: ITPed package openqa is in the archive make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net

[Git][security-tracker-team/security-tracker][master] openqa entered the archive, move from itp status to unfixed for further checks

2021-11-16 Thread @gcs
László Böszörményi pushed to branch master at Debian Security Tracker / security-tracker Commits: e3ed57c0 by Laszlo Boszormenyi (GCS) at 2021-11-17T00:15:16+01:00 openqa entered the archive, move from itp status to unfixed for further checks - - - - - 1 changed file: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-41653, Readd the whitespace character

2021-11-16 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 31f16620 by Markus Koschany at 2021-11-17T00:12:18+01:00 CVE-2021-41653, Readd the whitespace character This is the only unrelated change which might cause the processing errors. The whitespace was

Processing 83a5b72a4d39814983d32011ce1bc24000d30def failed

2021-11-16 Thread security tracker role
The error message was: data/CVE/list:189050: ITPed package openqa is in the archive make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net

Processing 83a5b72a4d39814983d32011ce1bc24000d30def failed

2021-11-16 Thread security tracker role
The error message was: data/CVE/list:189050: ITPed package openqa is in the archive make: *** [Makefile:19: all] Error 1 ___ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net

[Git][security-tracker-team/security-tracker][master] 2 commits: Claim firmware-nonfree in dla-needed.txt

2021-11-16 Thread Markus Koschany (@apo)
@@ exiv2 (Thorsten Alteholz) firefox-esr (Emilio) NOTE: 2026: blocked on toolchain backports (pochu) -- -firmware-nonfree +firmware-nonfree (Markus Koschany) NOTE: 20210731: WIP: https://salsa.debian.org/lts-team/packages/firmware-nonfree NOTE: 20210828: Most CVEs are difficult

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3feeb376 by Salvatore Bonaccorso at 2021-11-16T21:25:21+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2deaa223 by Salvatore Bonaccorso at 2021-11-16T21:12:22+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 19484c84 by security tracker role at 2021-11-16T20:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Mark CVE-2021-43618/gmp as no-dsa

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 55ad1348 by Salvatore Bonaccorso at 2021-11-16T20:48:06+01:00 Mark CVE-2021-43618/gmp as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2021-3756/libmysofa via unstable

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5410f991 by Salvatore Bonaccorso at 2021-11-16T20:46:00+01:00 Track fixed version for CVE-2021-3756/libmysofa via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Triage CVE-2020-20891, CVE-2020-20892, CVE-2020-20896, CVE-2020-21688,...

2021-11-16 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 60b0dac9 by Chris Lamb at 2021-11-16T07:48:55-08:00 Triage CVE-2020-20891, CVE-2020-20892, CVE-2020-20896, CVE-2020-21688, CVE-2020-21697 CVE-2020-20902 in ffmpeg for stretch LTS. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] NFUS

2021-11-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 71f9d433 by Moritz Muehlenhoff at 2021-11-16T14:49:00+01:00 NFUS resolve TODO for older golang versions - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] nomad n/a

2021-11-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ab16bd58 by Moritz Muehlenhoff at 2021-11-16T14:03:40+01:00 nomad n/a add note for pdf2json - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] CVE-2020-36477/mbedtls n/a on stretch

2021-11-16 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 0532f71a by Emilio Pozuelo Monfort at 2021-11-16T13:40:02+01:00 CVE-2020-36477/mbedtls n/a on stretch - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed verison via unstable for CVE-2021-3918/node-json-schema

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 701f6d6e by Salvatore Bonaccorso at 2021-11-16T13:12:40+01:00 Track fixed verison via unstable for CVE-2021-3918/node-json-schema - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] busybox: stretch postponed

2021-11-16 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: af773e06 by Sylvain Beucler at 2021-11-16T12:44:33+01:00 busybox: stretch postponed - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-3918/node-json-schema #999765

2021-11-16 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 7dedc819 by Neil Williams at 2021-11-16T11:10:08+00:00 CVE-2021-3918/node-json-schema #999765 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2021-11-16 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 91955775 by Neil Williams at 2021-11-16T10:35:02+00:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-6492/chromium - EOL stretch, add to DSA-4714-1

2021-11-16 Thread Neil Williams (@codehelp)
Neil Williams pushed to branch master at Debian Security Tracker / security-tracker Commits: 09909448 by Neil Williams at 2021-11-16T10:34:01+00:00 Add CVE-2020-6492/chromium - EOL stretch, add to DSA-4714-1 - - - - - 2 changed files: - data/CVE/list - data/DSA/list Changes:

[Git][security-tracker-team/security-tracker][master] new laravel issue

2021-11-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 704136f4 by Moritz Muehlenhoff at 2021-11-16T10:39:27+01:00 new laravel issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Re-claim libssh2.

2021-11-16 Thread Ola Lundqvist (@opal)
= @@ -63,9 +63,10 @@ libgit2 (Utkarsh) NOTE: 20211029: and TAL later next week. (utkarsh) NOTE: 2026: backports prepped; checking build and smoke-testing package. (utkarsh) -- -libssh2 +libssh2 (Ola Lundqvist) NOTE: 20211031: CVE-2019-13115 and CVE-2019

[Git][security-tracker-team/security-tracker][master] lts: reclaim firefox & thunderbird

2021-11-16 Thread Emilio Pozuelo Monfort (@pochu)
: = data/dla-needed.txt = @@ -36,7 +36,8 @@ debian-archive-keyring exiv2 (Thorsten Alteholz) NOTE: 20211109: testing package -- -firefox-esr +firefox-esr (Emilio) + NOTE: 2026: blocked on toolchain backports (pochu) -- firmware-nonfree NOTE

[Git][security-tracker-team/security-tracker][master] CVE-2020-3647[78]/mbedtls: add fixing commits

2021-11-16 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: ed6b52cd by Emilio Pozuelo Monfort at 2021-11-16T09:41:34+01:00 CVE-2020-3647[78]/mbedtls: add fixing commits - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Process NFUs

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a52da49c by Salvatore Bonaccorso at 2021-11-16T09:27:09+01:00 Process NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2013-7109

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5547ba09 by Salvatore Bonaccorso at 2021-11-16T09:14:03+01:00 Remove notes from CVE-2013-7109 It was withdrawn by its CNA. Further investigation showed that it was not a security issue. - - -

[Git][security-tracker-team/security-tracker][master] automatic update

2021-11-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0a2d48bd by security tracker role at 2021-11-16T08:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list