[Git][security-tracker-team/security-tracker][master] Add some additional reference for CVE-2022-4856{4,5}

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 54a44ecd by Salvatore Bonaccorso at 2023-08-25T06:23:28+02:00 Add some additional reference for CVE-2022-4856{4,5} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update information on CVE-2022-48560

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ed6fce39 by Salvatore Bonaccorso at 2023-08-25T06:18:10+02:00 Update information on CVE-2022-48560 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Update references for CVE-2022-48566

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4752e740 by Salvatore Bonaccorso at 2023-08-25T06:14:10+02:00 Update references for CVE-2022-48566 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-21896/mupdf

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c08bdcd by Salvatore Bonaccorso at 2023-08-24T23:22:17+02:00 Add CVE-2020-21896/mupdf - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-22219/flac

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e11d63d by Salvatore Bonaccorso at 2023-08-24T23:21:42+02:00 Add CVE-2020-22219/flac - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 14245744 by Salvatore Bonaccorso at 2023-08-24T23:21:16+02:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track some new "old' freeimage CVEs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 69ddffe3 by Salvatore Bonaccorso at 2023-08-24T23:20:39+02:00 Track some new old freeimage CVEs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-26683/mupdf

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 676ddc20 by Salvatore Bonaccorso at 2023-08-24T23:19:47+02:00 Add CVE-2020-26683/mupdf - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-32292/json-c

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 412798af by Salvatore Bonaccorso at 2023-08-24T22:50:56+02:00 Add CVE-2021-32292/json-c - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] wireshark fixed in sid

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 7810a9ef by Moritz Muehlenhoff at 2023-08-24T22:42:50+02:00 wireshark fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-34040/kafka

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 37911160 by Salvatore Bonaccorso at 2023-08-24T22:36:37+02:00 Add CVE-2023-34040/kafka - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 76204cc3 by Salvatore Bonaccorso at 2023-08-24T22:34:47+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Drop information on CVE-2023-38288 and CVE-2023-38289

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4fe188bf by Salvatore Bonaccorso at 2023-08-24T22:25:06+02:00 Drop information on CVE-2023-38288 and CVE-2023-38289 RedHat as assigning CNA now rejected both with Rejected Reason: Not

[Git][security-tracker-team/security-tracker][master] Process some new NFUs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6da2598a by Salvatore Bonaccorso at 2023-08-24T22:22:09+02:00 Process some new NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add new "old" set of dpic CVEs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bdbdd451 by Salvatore Bonaccorso at 2023-08-24T22:17:16+02:00 Add new old set of dpic CVEs - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f512bb00 by security tracker role at 2023-08-24T20:12:07+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-33390/dpic

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a6f9c5c8 by Salvatore Bonaccorso at 2023-08-24T22:07:22+02:00 Add CVE-2021-33390/dpic - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-34193/opensc

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9cff0514 by Salvatore Bonaccorso at 2023-08-24T21:50:46+02:00 Add CVE-2021-34193/opensc - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-40211/imagemagick

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a2ad0319 by Salvatore Bonaccorso at 2023-08-24T21:37:51+02:00 Add CVE-2021-40211/imagemagick - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Update information for CVE-2022-41444/cacti

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 159a99a7 by Salvatore Bonaccorso at 2023-08-24T21:26:21+02:00 Update information for CVE-2022-41444/cacti - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-41444/cacti

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e3926036 by Salvatore Bonaccorso at 2023-08-24T21:21:36+02:00 Add CVE-2022-41444/cacti - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] track tryton fix in sid

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ae122570 by Moritz Mühlenhoff at 2023-08-24T21:08:11+02:00 track tryton fix in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] tryton-server DSA

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f84c4581 by Moritz Mühlenhoff at 2023-08-24T21:04:04+02:00 tryton-server DSA - - - - - 1 changed file: - data/DSA/list Changes: = data/DSA/list

[Git][security-tracker-team/security-tracker][master] Add new (old) freeimage CVEs (yet with open upstream issue)

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c95f60d1 by Salvatore Bonaccorso at 2023-08-24T20:29:27+02:00 Add new (old) freeimage CVEs (yet with open upstream issue) Note that the version in the CVE is incorrect, it should be 3.18.0

[Git][security-tracker-team/security-tracker][master] Adjust notes for two older binutils CVEs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 557873f8 by Salvatore Bonaccorso at 2023-08-24T18:06:15+02:00 Adjust notes for two older binutils CVEs - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2020-35342/binutils

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 713d9663 by Salvatore Bonaccorso at 2023-08-24T18:05:28+02:00 Add CVE-2020-35342/binutils - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-46174/binutils

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 578276a2 by Salvatore Bonaccorso at 2023-08-24T17:54:38+02:00 Add CVE-2021-46174/binutils - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2021-46179/upx-ucl

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6aab269f by Salvatore Bonaccorso at 2023-08-24T17:53:13+02:00 Add CVE-2021-46179/upx-ucl - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add two new CVEs for djvulibre

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 27721ef6 by Salvatore Bonaccorso at 2023-08-24T17:52:36+02:00 Add two new CVEs for djvulibre - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-26592/libsass

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4078d5c7 by Salvatore Bonaccorso at 2023-08-24T17:51:54+02:00 Add CVE-2022-26592/libsass - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add new CVEs for radare2

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 33622399 by Salvatore Bonaccorso at 2023-08-24T17:21:53+02:00 Add new CVEs for radare2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-43357/libsass

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: cb8b9d6f by Salvatore Bonaccorso at 2023-08-24T17:21:22+02:00 Add CVE-2022-43357/libsass - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 413877b1 by Salvatore Bonaccorso at 2023-08-24T17:20:46+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add two new CVEs for airflow, itp'ed

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ef9f1fa0 by Salvatore Bonaccorso at 2023-08-24T17:19:50+02:00 Add two new CVEs for airflow, itped - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-4042/ghostscript

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e9ff01bb by Salvatore Bonaccorso at 2023-08-24T17:09:24+02:00 Add CVE-2023-4042/ghostscript - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Mark CVE-2022-29654/nasm as no-dsa

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dd6249dc by Salvatore Bonaccorso at 2023-08-24T17:06:48+02:00 Mark CVE-2022-29654/nasm as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] batik fixed in sid

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: e476572e by Moritz Muehlenhoff at 2023-08-24T16:14:08+02:00 batik fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3541-1 for w3m

2023-08-24 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 24816548 by Sylvain Beucler at 2023-08-24T13:42:17+02:00 Reserve DLA-3541-1 for w3m - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] rust-rustls-webpki fixed in sid

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ac43f235 by Moritz Muehlenhoff at 2023-08-24T11:37:11+02:00 rust-rustls-webpki fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 295a6867 by Moritz Muehlenhoff at 2023-08-24T10:58:32+02:00 bullseye/bookworm triage - - - - - 2 changed files: - data/CVE/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 099b08da by Salvatore Bonaccorso at 2023-08-24T10:40:49+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add three new wireshark issues: CVE-2023-451{1,2,3}

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c4cbe174 by Salvatore Bonaccorso at 2023-08-24T10:32:42+02:00 Add three new wireshark issues: CVE-2023-451{1,2,3} - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Correct version for CVE-2022-29654

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9ef99005 by Salvatore Bonaccorso at 2023-08-24T10:28:18+02:00 Correct version for CVE-2022-29654 The issue is still present in upstream 2.15.05 contrary to the CVE description but in

[Git][security-tracker-team/security-tracker][master] automatic update

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4f0178dc by security tracker role at 2023-08-24T08:12:20+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] new k8s issues

2023-08-24 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 5795fc5b by Moritz Muehlenhoff at 2023-08-24T10:06:22+02:00 new k8s issues - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Correct severity of CVE-2022-29654

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9302704e by Salvatore Bonaccorso at 2023-08-24T09:41:02+02:00 Correct severity of CVE-2022-29654 As it is an memory write, this can lead potentially lead to more as only a crash. Revert the

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-43358/libasass

2023-08-24 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e616d65 by Salvatore Bonaccorso at 2023-08-24T09:28:39+02:00 Add CVE-2022-43358/libasass - - - - - 1 changed file: - data/CVE/list Changes: =