[Git][security-tracker-team/security-tracker][master] Track fixed version for firefox issues covered in mfsa2022-44

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fce0b862 by Salvatore Bonaccorso at 2022-10-19T07:42:49+02:00 Track fixed version for firefox issues covered in mfsa2022-44 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-42902/lava via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4cfa0a2c by Salvatore Bonaccorso at 2022-10-19T07:38:24+02:00 Track fixed version for CVE-2022-42902/lava via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track firefox-esr issues from mfsa2022-45 fixed via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e5ca1efd by Salvatore Bonaccorso at 2022-10-19T07:36:59+02:00 Track firefox-esr issues from mfsa2022-45 fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update status of asterisk

2022-10-18 Thread Markus Koschany (@apo)
: 20221018: https://lists.debian.org/debian-lts/2022/10/msg00037.html -- bluez (Sylvain Beucler) NOTE: 20220902: Programming language: C. View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/36bf84915419abb844b46c2760d95c166bb25fec -- View it on GitLab

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3542/linux

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5a899ff6 by Salvatore Bonaccorso at 2022-10-18T23:31:08+02:00 Add CVE-2022-3542/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-29187/git via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c25c4f2a by Salvatore Bonaccorso at 2022-10-18T23:24:16+02:00 Track fixed version for CVE-2022-29187/git via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3544/linux

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 58474929 by Salvatore Bonaccorso at 2022-10-18T23:18:39+02:00 Add CVE-2022-3544/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Remove doubled entry for firefox-esr in CVE-2022-42927

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cfb7f17f by Salvatore Bonaccorso at 2022-10-18T22:36:47+02:00 Remove doubled entry for firefox-esr in CVE-2022-42927 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for zoneminder issues via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cabe63e4 by Salvatore Bonaccorso at 2022-10-18T22:34:35+02:00 Track fixed version for zoneminder issues via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] new firefox issues

2022-10-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 279ddb74 by Moritz Mühlenhoff at 2022-10-18T22:28:03+02:00 new firefox issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new firefox-esr issues

2022-10-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 12ef9d9e by Moritz Mühlenhoff at 2022-10-18T22:25:32+02:00 new firefox-esr issues - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f805057f by Salvatore Bonaccorso at 2022-10-18T22:20:34+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ce4c9248 by Salvatore Bonaccorso at 2022-10-18T22:16:12+02:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 421f887d by security tracker role at 2022-10-18T20:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Update note for python-django.

2022-10-18 Thread Chris Lamb (@lamby)
in stretch so it should also be fixed for buster. + NOTE: 20221018: There are 4 CVEs on the debian/buster branch that are seemingly unreleased: CVE-2020-24583, CVE-2020-24584, CVE-2021-3281 and CVE-2021-23336. (lamby) + NOTE: 20221018: This leaves 8 CVEs that need fixing, either simply because

[Git][security-tracker-team/security-tracker][master] additional commons-text reference

2022-10-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 47c6ba5e by Moritz Mühlenhoff at 2022-10-18T21:43:26+02:00 additional commons-text reference - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] python-opcua removed

2022-10-18 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 37b54c81 by Moritz Mühlenhoff at 2022-10-18T21:42:45+02:00 python-opcua removed - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Triage CVE-2022-28347 in python-django for buster LTS.

2022-10-18 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 845dbc2f by Chris Lamb at 2022-10-18T12:32:41-07:00 Triage CVE-2022-28347 in python-django for buster LTS. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-39260 and CVE-2022-39253

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f375f005 by Salvatore Bonaccorso at 2022-10-18T21:11:16+02:00 Add CVE-2022-39260 and CVE-2022-39253 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DSA number for linux update

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cc1637f4 by Salvatore Bonaccorso at 2022-10-18T20:44:23+02:00 Reserve DSA number for linux update - - - - - 1 changed file: - data/DSA/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DSA-5256-1 bcel

2022-10-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: d55a9604 by Markus Koschany at 2022-10-18T20:00:48+02:00 Reserve DSA-5256-1 bcel - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3155-1 for bcel

2022-10-18 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f86cc00b by Markus Koschany at 2022-10-18T19:53:59+02:00 Reserve DLA-3155-1 for bcel - - - - - 1 changed file: - data/DLA/list Changes: = data/DLA/list

[Git][security-tracker-team/security-tracker][master] CVE-2021-3658/bluez: precise buster triage

2022-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 6fa79b59 by Sylvain Beucler at 2022-10-18T19:50:32+02:00 CVE-2021-3658/bluez: precise buster triage - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2022-2602/linux

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4303c8ef by Salvatore Bonaccorso at 2022-10-18T19:14:51+02:00 Add CVE-2022-2602/linux - - - - - 0ff19462 by Salvatore Bonaccorso at 2022-10-18T19:34:20+02:00 Add oss-security reference for

[Git][security-tracker-team/security-tracker][master] CVE-2018-10911/bluez: clarify buster triage

2022-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: c2b134bc by Sylvain Beucler at 2022-10-18T18:51:53+02:00 CVE-2018-10911/bluez: clarify buster triage - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3545/linux

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d2dd4856 by Salvatore Bonaccorso at 2022-10-18T17:55:14+02:00 Add CVE-2022-3545/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim python-django.

2022-10-18 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: a87cef43 by Chris Lamb at 2022-10-18T08:53:19-07:00 data/dla-needed.txt: Claim python-django. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-39198 as NFU

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 711779dc by Salvatore Bonaccorso at 2022-10-18T17:43:27+02:00 Add CVE-2022-39198 as NFU - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] lts: remove CVE-2017-2625 from DLA-2006-1

2022-10-18 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: ac0b00e1 by Emilio Pozuelo Monfort at 2022-10-18T17:38:13+02:00 lts: remove CVE-2017-2625 from DLA-2006-1 The patch was included in the source package but not applied. - - - - - 1 changed

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-3563 as no-dsa

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 227dc750 by Salvatore Bonaccorso at 2022-10-18T17:27:25+02:00 Mark CVE-2022-3563 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-0367/libmodbus via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 33ca8193 by Salvatore Bonaccorso at 2022-10-18T17:25:13+02:00 Track fixed version for CVE-2022-0367/libmodbus via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2022-1328/neomutt via unstable

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e7d6efb by Salvatore Bonaccorso at 2022-10-18T17:24:00+02:00 Track fixed version for CVE-2022-1328/neomutt via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] dla: claim bluez

2022-10-18 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 06a682df by Sylvain Beucler at 2022-10-18T17:23:09+02:00 dla: claim bluez - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3154-1 for node-xmldom

2022-10-18 Thread Emilio Pozuelo Monfort (@pochu)
NOTE: 20220907: Programming language: JavaScript. -- -node-xmldom (Emilio) - NOTE: 20221018: Programming language: JavaScript. - NOTE: 20221018: Maintainer prepared an update. --- openexr NOTE: 20220904: Programming language: C++. NOTE: 20220904: Should be synced with Stretch. (apo

[Git][security-tracker-team/security-tracker][master] Process one NFU

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d945e62f by Salvatore Bonaccorso at 2022-10-18T14:34:56+02:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: lts: add node-xmldom

2022-10-18 Thread Emilio Pozuelo Monfort (@pochu)
-needed.txt = @@ -117,6 +117,10 @@ netatalk node-tar NOTE: 20220907: Programming language: JavaScript. -- +node-xmldom (Emilio) + NOTE: 20221018: Programming language: JavaScript. + NOTE: 20221018: Maintainer prepared an update. +-- openexr NOTE: 20220904

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-18 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3378fd9d by security tracker role at 2022-10-18T08:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Triage CVE-2022-2963/jasper as unimportant

2022-10-18 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 1a38ae98 by Emilio Pozuelo Monfort at 2022-10-18T09:01:59+02:00 Triage CVE-2022-2963/jasper as unimportant A memory leak just before calling exit() has no security impact. - - - - - 1