[Git][security-tracker-team/security-tracker][master] Add two issues from INTEL-SA-00690 in mdadm

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a557ee82 by Salvatore Bonaccorso at 2023-08-17T08:43:28+02:00 Add two issues from INTEL-SA-00690 in mdadm Unfortunately no clear information from the intel advisories, apart to get the fixes on

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3532-1 for openssh

2023-08-16 Thread Utkarsh Gupta (@utkarsh)
jtreg version (pochu) -- -openssh (utkarsh) - NOTE: 20230814: Added by Front-Desk (ta) - NOTE: 20230816: taking this one as it's high prio, given one of the customers pinged. (utkarsh) --- orthanc (gladk) NOTE: 20230812: Added by Front-Desk (Beuc) NOTE: 20230812: Experimental issue-

[Git][security-tracker-team/security-tracker][master] Revert "Mark CVE-2017-18641/lxc/jessie as ignored"

2023-08-16 Thread Santiago R.R. (@santiago)
Santiago R.R. pushed to branch master at Debian Security Tracker / security-tracker Commits: 0c1e17c4 by Santiago Ruano Rincón at 2023-08-16T21:24:13-03:00 Revert "Mark CVE-2017-18641/lxc/jessie as ignored" This reverts commit 319b9d38c5ab7f2494ba644ee0284c44e8531487. - - - - - 1 changed f

[Git][security-tracker-team/security-tracker][master] CVE-2021-36100/otrs2: Add link to advisory and fixing commits.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: eed1e199 by Guilhem Moulin at 2023-08-17T02:18:57+02:00 CVE-2021-36100/otrs2: Add link to advisory and fixing commits. >From znuny 6.0.41. - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] CVE-2019-14889/stretch is being fixed

2023-08-16 Thread @roberto
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 3bf17820 by Roberto C. Sánchez at 2023-08-16T19:16:52-04:00 CVE-2019-14889/stretch is being fixed - - - - - 1 changed file: - data/CVE/list Changes: = da

[Git][security-tracker-team/security-tracker][master] CVE-2021-21441/otrs2: Add link to fixing commit.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 493dcf07 by Guilhem Moulin at 2023-08-17T01:05:25+02:00 CVE-2021-21441/otrs2: Add link to fixing commit. >From znuny 6.0.34. - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2021-21439/otrs2: Add link to fixing commit.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 22924391 by Guilhem Moulin at 2023-08-17T00:24:21+02:00 CVE-2021-21439/otrs2: Add link to fixing commit. For znuny 6.0.33. - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] new faad2 issues

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 624c9397 by Moritz Muehlenhoff at 2023-08-16T23:50:09+02:00 new faad2 issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-39975/krb5

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 684e28d0 by Salvatore Bonaccorso at 2023-08-16T23:09:12+02:00 Add CVE-2023-39975/krb5 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a09e06bf by Salvatore Bonaccorso at 2023-08-16T23:05:36+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-4387/linux

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3a40661f by Salvatore Bonaccorso at 2023-08-16T22:36:27+02:00 Add CVE-2023-4387/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-4389/linux

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bdec9ad8 by Salvatore Bonaccorso at 2023-08-16T22:32:40+02:00 Add CVE-2023-4389/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-4385/linux

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 07f489a8 by Salvatore Bonaccorso at 2023-08-16T22:24:01+02:00 Add CVE-2023-4385/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1927f825 by Salvatore Bonaccorso at 2023-08-16T22:17:34+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3118d130 by security tracker role at 2023-08-16T20:13:16+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fix via experimental for CVE-2023-34872/poppler

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3905c8de by Salvatore Bonaccorso at 2023-08-16T22:08:25+02:00 Track fix via experimental for CVE-2023-34872/poppler Note, while an experimental upload as 23.08.0-2 mentioned the CVE as fixed, t

[Git][security-tracker-team/security-tracker][master] Mark CVE-2017-18641/lxc/jessie as ignored

2023-08-16 Thread Santiago R.R. (@santiago)
Santiago R.R. pushed to branch master at Debian Security Tracker / security-tracker Commits: 319b9d38 by Santiago Ruano Rincón at 2023-08-16T17:06:44-03:00 Mark CVE-2017-18641/lxc/jessie as ignored - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add commit reference for CVE-2023-1206/linux

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5c177d03 by Salvatore Bonaccorso at 2023-08-16T21:00:57+02:00 Add commit reference for CVE-2023-1206/linux - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2023-2898/linux

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ef6d9d47 by Salvatore Bonaccorso at 2023-08-16T20:48:20+02:00 Update information on CVE-2023-2898/linux - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2023-33250/linux in unstable

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 750cb68e by Salvatore Bonaccorso at 2023-08-16T20:38:18+02:00 Track fixed version for CVE-2023-33250/linux in unstable - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] efibootguard spu

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 03643b92 by Moritz Mühlenhoff at 2023-08-16T20:31:40+02:00 efibootguard spu - - - - - 1 changed file: - data/next-point-update.txt Changes: = data/next-p

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2023-38898 commits

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d042ac67 by Salvatore Bonaccorso at 2023-08-16T20:29:04+02:00 Add upstream tag information for CVE-2023-38898 commits - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] openjdk-11 DSA

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e7fd8c53 by Moritz Mühlenhoff at 2023-08-16T20:15:52+02:00 openjdk-11 DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: = dat

[Git][security-tracker-team/security-tracker][master] Claim mediawiki in dla-needed.txt

2023-08-16 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 8141b724 by Markus Koschany at 2023-08-16T20:05:19+02:00 Claim mediawiki in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/d

[Git][security-tracker-team/security-tracker][master] CVE-2020-1776/otrs2: Add link to fixing commit.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 75184deb by Guilhem Moulin at 2023-08-16T19:22:40+02:00 CVE-2020-1776/otrs2: Add link to fixing commit. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3531-1 for open-vm-tools

2023-08-16 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: deb3e9e9 by Utkarsh Gupta at 2023-08-16T22:43:36+05:30 Reserve DLA-3531-1 for open-vm-tools - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Mark CVE-2009-1143/open-vm-tools as ignored for buster

2023-08-16 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: c5d8f3ab by Utkarsh Gupta at 2023-08-16T22:38:25+05:30 Mark CVE-2009-1143/open-vm-tools as ignored for buster It's a very minor issue and mount.vmhgfs is not suid in Debian. Also, dropping that from b

[Git][security-tracker-team/security-tracker][master] opensmtpd fixed in sid

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 35035674 by Moritz Muehlenhoff at 2023-08-16T18:16:11+02:00 opensmtpd fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ===

[Git][security-tracker-team/security-tracker][master] efibootguard fixed in sid

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 404f0f90 by Moritz Muehlenhoff at 2023-08-16T18:13:10+02:00 efibootguard fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2019-18179/otrs2: Add follow-up commits.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 4bd8ca57 by Guilhem Moulin at 2023-08-16T17:05:15+02:00 CVE-2019-18179/otrs2: Add follow-up commits. - - - - - 1 changed file: - data/CVE/list Changes: = dat

[Git][security-tracker-team/security-tracker][master] CVE-2019-{18179,18180}/otrs2: Add links to fixing commits.

2023-08-16 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: 659eb0f6 by Guilhem Moulin at 2023-08-16T16:40:38+02:00 CVE-2019-{18179,18180}/otrs2: Add links to fixing commits. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] NFUs

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: b9ed0dc9 by Moritz Muehlenhoff at 2023-08-16T16:00:36+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] new Python issue (CVE description is bogus)

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: fcf7face by Moritz Muehlenhoff at 2023-08-16T15:11:24+02:00 new Python issue (CVE description is bogus) - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] NFUs

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: cb47a68e by Moritz Muehlenhoff at 2023-08-16T13:46:41+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-08-16 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 50054c99 by Moritz Muehlenhoff at 2023-08-16T13:22:36+02:00 bullseye/bookworm triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] Process some new NFUs

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c18ef39d by Salvatore Bonaccorso at 2023-08-16T10:57:06+02:00 Process some new NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Take openssh for buster

2023-08-16 Thread Utkarsh Gupta (@utkarsh)
: 20230816: taking this one as it's high prio, given one of the customers pinged. (utkarsh) -- orthanc (gladk) NOTE: 20230812: Added by Front-Desk (Beuc) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34e3570ab50342536d5432e8a6563547ac9

[Git][security-tracker-team/security-tracker][master] automatic update

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dba8b538 by security tracker role at 2023-08-16T08:12:13+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track CVEs for chromium upload to unstable

2023-08-16 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c5b41c60 by Salvatore Bonaccorso at 2023-08-16T09:03:34+02:00 Track CVEs for chromium upload to unstable Note for reviewers: CVE-2023-2312 is slightly unclear if it is Android specific or not.