[Git][security-tracker-team/security-tracker][master] chromium dsa

2024-02-22 Thread Andres Salomon (@dilinger)
Andres Salomon pushed to branch master at Debian Security Tracker / security-tracker Commits: 5831ba74 by Andres Salomon at 2024-02-23T01:06:04-05:00 chromium dsa - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: = data/DSA/lis

[Git][security-tracker-team/security-tracker][master] Add additional version tracking notes for new ruby-rack issues

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9547f5ac by Salvatore Bonaccorso at 2024-02-23T06:47:52+01:00 Add additional version tracking notes for new ruby-rack issues - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Add new ruby-rack CVEs

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 159e03af by Salvatore Bonaccorso at 2024-02-23T06:44:06+01:00 Add new ruby-rack CVEs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] dla: update cacti status

2024-02-22 Thread Sylvain Beucler (@beuc)
patches, update patch commits (Beuc) + NOTE: 20240222: Coordinating with maintainer to prepare bullseye&bookworm updates (Beuc) + NOTE: 20240222: Reported incomplete fix upstream (Beuc) -- cairosvg NOTE: 20230323: Added by Front-Desk (gladk) View it on GitLab: https://salsa.debian

[Git][security-tracker-team/security-tracker][master] Add some fixing commits for bind9 issues

2024-02-22 Thread Santiago R.R. (@santiago)
Santiago R.R. pushed to branch master at Debian Security Tracker / security-tracker Commits: 9b7664c8 by Santiago Ruano Rincón at 2024-02-22T18:52:05-03:00 Add some fixing commits for bind9 issues - - - - - 1 changed file: - data/CVE/list Changes: = d

[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e020bdd9 by Salvatore Bonaccorso at 2024-02-22T22:47:32+01:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: = dat

[Git][security-tracker-team/security-tracker][master] Merge Linux CVEs from kernel-sec

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e0c4100 by Salvatore Bonaccorso at 2024-02-22T22:31:08+01:00 Merge Linux CVEs from kernel-sec - - - - - 1 changed file: - data/CVE/list Changes: = dat

[Git][security-tracker-team/security-tracker][master] Adjust not-affected note for CVE-2023-5679

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d2e212c1 by Salvatore Bonaccorso at 2024-02-22T21:13:08+01:00 Adjust not-affected note for CVE-2023-5679 - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Pinpoint upstream version for CVE-2024-1597 commits

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: eeb65677 by Salvatore Bonaccorso at 2024-02-22T21:09:04+01:00 Pinpoint upstream version for CVE-2024-1597 commits - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] NFUs

2024-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 7f4f4c51 by Moritz Muehlenhoff at 2024-02-22T20:20:33+01:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] imagemagick DSA

2024-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 7be9fc49 by Moritz Mühlenhoff at 2024-02-22T19:52:46+01:00 imagemagick DSA - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] lts: add thunderbird

2024-02-22 Thread Emilio Pozuelo Monfort (@pochu)
/dla-needed.txt = @@ -280,6 +280,10 @@ suricata NOTE: 20231016: Still reviewing+testing CVEs. (bunk) NOTE: 20231120: DLA coming soon. (bunk) -- +thunderbird + NOTE: 20240222: Added by Front-Desk (pochu) + NOTE: 20240222: send DLA after maintainer uploads

[Git][security-tracker-team/security-tracker][master] lts: take firefox-esr

2024-02-22 Thread Emilio Pozuelo Monfort (@pochu)
: = data/dla-needed.txt = @@ -94,6 +94,9 @@ engrampa exiftags NOTE: 20240121: Added by Front-Desk (apo) -- +firefox-esr (Emilio) + NOTE: 20240222: Added by Front-Desk (pochu) +-- freeimage NOTE: 20240121: Added by Front-Desk (apo) -- View it on GitLab

[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-5679/bind9/buster as not affected

2024-02-22 Thread Santiago R.R. (@santiago)
Santiago R.R. pushed to branch master at Debian Security Tracker / security-tracker Commits: 4396c971 by Santiago Ruano Rincón at 2024-02-22T15:07:44-03:00 Mark CVE-2023-5679/bind9/buster as not affected - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] CVE-2023-39360/cacti: precise note again

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 79e1fa5a by Sylvain Beucler at 2024-02-22T18:26:28+01:00 CVE-2023-39360/cacti: precise note again - - - - - 1 changed file: - data/CVE/list Changes: = data/

[Git][security-tracker-team/security-tracker][master] CVE-2023-49088,CVE-2023-50250/cacti: another follow-up commit

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 0470d1be by Sylvain Beucler at 2024-02-22T18:00:36+01:00 CVE-2023-49088,CVE-2023-50250/cacti: another follow-up commit - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] CVE-2023-49088/cacti: reference additional patches

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 296cb887 by Sylvain Beucler at 2024-02-22T17:39:49+01:00 CVE-2023-49088/cacti: reference additional patches Despite the reference to CVE-2023-49088 in 56f9d99e6e5ab434ea18fa344236f41e78f99c59, that

[Git][security-tracker-team/security-tracker][master] nodejs commit references

2024-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 15973cb7 by Moritz Muehlenhoff at 2024-02-22T17:03:02+01:00 nodejs commit references - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] new libpgjava issue

2024-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 554757e5 by Moritz Muehlenhoff at 2024-02-22T15:49:30+01:00 new libpgjava issue - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2023-52437

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e0377017 by Salvatore Bonaccorso at 2024-02-22T14:52:16+01:00 Remove notes from CVE-2023-52437 - - - - - 1 changed file: - data/CVE/list Changes: = dat

[Git][security-tracker-team/security-tracker][master] Partial revert of "CVE-2023-43907/OptiPNG fixed in 0.7.8+ds-1"

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 5083748a by Salvatore Bonaccorso at 2024-02-22T14:43:10+01:00 Partial revert of "CVE-2023-43907/OptiPNG fixed in 0.7.8+ds-1" This (partially) reverts commit dae7f314618bf7e6ff7b69b6f9c3d4f8f0ef

[Git][security-tracker-team/security-tracker][master] CVE-2023-43907/OptiPNG fixed in 0.7.8+ds-1

2024-02-22 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: dae7f314 by Bastien Roucariès at 2024-02-22T13:38:13+00:00 CVE-2023-43907/OptiPNG fixed in 0.7.8+ds-1 Mark this CVE as fixed - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3738-1 for iwd

2024-02-22 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: efddaa4c by Chris Lamb at 2024-02-22T12:59:37+00:00 Reserve DLA-3738-1 for iwd - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: = data/DL

[Git][security-tracker-team/security-tracker][master] CVE-2023-39360/cacti: precise note

2024-02-22 Thread Sylvain Beucler (@beuc)
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker Commits: 56b966d9 by Sylvain Beucler at 2024-02-22T12:36:19+01:00 CVE-2023-39360/cacti: precise note - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] sqlfluff fixed in sid

2024-02-22 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 06a67291 by Moritz Muehlenhoff at 2024-02-22T11:51:22+01:00 sqlfluff fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] CVE-2023-39978/imagemagick only mentioned on changelog not fixed

2024-02-22 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 6ffd3d73 by Bastien Roucariès at 2024-02-22T09:38:40+00:00 CVE-2023-39978/imagemagick only mentioned on changelog not fixed CVE-2023-39978 was fixed due to be introduced by fixes of other problems

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 062a767a by Salvatore Bonaccorso at 2024-02-22T10:27:29+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Keep imagemagick dla entry

2024-02-22 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 857719c3 by Bastien Roucariès at 2024-02-22T09:25:51+00:00 Keep imagemagick dla entry Imagemagick has a few CVEs that need more investigation - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3737-1 for imagemagick

2024-02-22 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f250824 by Bastien Roucariès at 2024-02-22T09:25:02+00:00 Reserve DLA-3737-1 for imagemagick - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] buster CVE-2023-3745/imagemagick

2024-02-22 Thread @rouca
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker Commits: fdc095e7 by Bastien Roucariès at 2024-02-22T09:16:52+00:00 buster CVE-2023-3745/imagemagick Buster is not affected - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 152cc177 by Salvatore Bonaccorso at 2024-02-22T09:54:56+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2024-02-22 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 04ac12b5 by security tracker role at 2024-02-22T08:11:36+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list