[Git][security-tracker-team/security-tracker][master] Fix typo

2022-10-27 Thread Henri Salo (@hsalo-guest)
Henri Salo pushed to branch master at Debian Security Tracker / security-tracker Commits: 3fbfc044 by Henri Salo at 2022-10-28T08:55:36+03:00 Fix typo - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add fixed version for curl issues fixed via unstable

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b20f0937 by Salvatore Bonaccorso at 2022-10-28T07:06:44+02:00 Add fixed version for curl issues fixed via unstable - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3166-1 for ruby-sinatra

2022-10-27 Thread Utkarsh Gupta (@utkarsh)
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker Commits: 29216582 by Utkarsh Gupta at 2022-10-28T09:21:37+05:30 Reserve DLA-3166-1 for ruby-sinatra - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Take dropbear and ruby-sinatra

2022-10-27 Thread Utkarsh Gupta (@utkarsh)
@@ curl (Emilio) NOTE: 20220904: VCS: https://salsa.debian.org/lts-team/packages/curl.git NOTE: 20220904: Special attention: high popcon!. -- -dropbear +dropbear (Utkarsh) NOTE: 20221027: Programming language: C. -- exiv2 NOTE: 20220819: Programming language: C++. NOTE: 20220819: https

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3719/exiv2

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c4abbbd9 by Salvatore Bonaccorso at 2022-10-27T22:59:47+02:00 Add CVE-2022-3719/exiv2 - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3725/wireshark

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e33720d by Salvatore Bonaccorso at 2022-10-27T22:48:10+02:00 Add CVE-2022-3725/wireshark - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] thunderbird DSA

2022-10-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: ceda112d by Moritz Mühlenhoff at 2022-10-27T22:45:36+02:00 thunderbird DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Take expat

2022-10-27 Thread Utkarsh Gupta (@utkarsh)
, but a very quick glance suggests the earlier code may be equally vulnerable. (Chris Lamb) -- -expat +expat (Utkarsh) NOTE: 20221027: Programming language: C. -- firmware-nonfree View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: d4d262da by Salvatore Bonaccorso at 2022-10-27T22:14:21+02:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: dbc98a9a by Salvatore Bonaccorso at 2022-10-27T22:12:19+02:00 Process some NFUs - - - - - 5b8aef77 by Salvatore Bonaccorso at 2022-10-27T22:12:20+02:00 Add CVE-2022-3363/rdiffweb - - - - -

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 42fcc87f by security tracker role at 2022-10-27T20:10:24+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3474/bazel

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b8506162 by Salvatore Bonaccorso at 2022-10-27T22:01:50+02:00 Add CVE-2022-3474/bazel - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Track proposed update for powerline-gitstatus via bullseye-pu

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 96fa6f55 by Salvatore Bonaccorso at 2022-10-27T21:48:33+02:00 Track proposed update for powerline-gitstatus via bullseye-pu - - - - - 1 changed file: - data/next-point-update.txt Changes:

[Git][security-tracker-team/security-tracker][master] Process one NFU

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 9e7d3165 by Salvatore Bonaccorso at 2022-10-27T21:47:08+02:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] batik fixed in sid

2022-10-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f15f0b6 by Moritz Mühlenhoff at 2022-10-27T21:15:43+02:00 batik fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3704/rails

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 313600d4 by Salvatore Bonaccorso at 2022-10-27T21:11:59+02:00 Add CVE-2022-3704/rails - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add upstream tag information for CVE-2020-21599

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 73017f53 by Salvatore Bonaccorso at 2022-10-27T20:34:38+02:00 Add upstream tag information for CVE-2020-21599 - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3164-1 for python-django

2022-10-27 Thread Chris Lamb (@lamby)
fixed in stretch: CVE-2022-34265, CVE-2022-28346, CVE-2022-23833, CVE-2022-22818, CVE-2021-33571, CVE-2021-33203, CVE-2021-31542 & CVE-2021-28658 (lamby) - NOTE: 20221027: To clarify, only the first CVE mentioned in the previous comment (CVE-2022-34265) is vulnerable and not fixed in str

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: No, CVE-2022-28346 is fixed in stretch like the others.

2022-10-27 Thread Chris Lamb (@lamby)
-22818, CVE-2021-33571, CVE-2021-33203, CVE-2021-31542 & CVE-2021-28658 (lamby) - NOTE: 20221027: To clarify, the first two CVEs mentioned in the previous comment (CVE-2022-34265 & CVE-2022-28346) are vulnerable and not fixed in stretch, and the next six have already been fixed in stretch

[Git][security-tracker-team/security-tracker][master] dla-needed.txt: Update note for python-django.

2022-10-27 Thread Chris Lamb (@lamby)
-2021-33203, CVE-2021-31542 & CVE-2021-28658 (lamby) + NOTE: 20221027: To clarify, the first two CVEs mentioned in the previous comment (CVE-2022-34265 & CVE-2022-28346) are vulnerable and not fixed in stretch, and the next six have already been fixed in stretch. I plan to fix these rem

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-41842,libcommons-jxpath-java: Link to proposed upstream changes

2022-10-27 Thread Markus Koschany (@apo)
: Programming language: C++. NOTE: 20220811: Proposed a patch to CVE-2022-26562 (#1016973) -- +libcommons-jxpath-java + NOTE: 20221027: Programming language: Java. + NOTE: 20221027: Maintainer notes: Wait for the outcome of upstream discussion. See CVE-2022-41852 for pull requests. +-- libreoffice

[Git][security-tracker-team/security-tracker][master] 3 commits: Add expat to dla-needed.txt

2022-10-27 Thread Markus Koschany (@apo)
: 20220904: VCS: https://salsa.debian.org/lts-team/packages/curl.git NOTE: 20220904: Special attention: high popcon!. -- +dropbear + NOTE: 20221027: Programming language: C. +-- exiv2 NOTE: 20220819: Programming language: C++. NOTE: 20220819: https://github.com/Exiv2/exiv2/commit

[Git][security-tracker-team/security-tracker][master] one libde265 issue fixed in sid

2022-10-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 92d3b469 by Moritz Mühlenhoff at 2022-10-27T16:46:10+02:00 one libde265 issue fixed in sid - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] two etcd issues fixed in experimental

2022-10-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: f952b859 by Moritz Mühlenhoff at 2022-10-27T16:13:36+02:00 two etcd issues fixed in experimental - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] additional sqlite reference

2022-10-27 Thread Moritz Muehlenhoff (@jmm)
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 13d24bca by Moritz Mühlenhoff at 2022-10-27T12:26:12+02:00 additional sqlite reference - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3705/vim

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ecf26d88 by Salvatore Bonaccorso at 2022-10-27T11:01:52+02:00 Add CVE-2022-3705/vim - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] lts: CVE-2022-42916/curl n/a on buster

2022-10-27 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 0de69910 by Emilio Pozuelo Monfort at 2022-10-27T10:31:05+02:00 lts: CVE-2022-42916/curl n/a on buster - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] automatic update

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: faf49d27 by security tracker role at 2022-10-27T08:10:15+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] lts: take curl

2022-10-27 Thread Emilio Pozuelo Monfort (@pochu)
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker Commits: 8e028103 by Emilio Pozuelo Monfort at 2022-10-27T08:36:38+02:00 lts: take curl - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3697/ansible

2022-10-27 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fe5d1e9f by Salvatore Bonaccorso at 2022-10-27T08:32:41+02:00 Add CVE-2022-3697/ansible - - - - - 1 changed file: - data/CVE/list Changes: =