[Secure-testing-commits] r47269 - data/packages

2016-12-21 Thread security tracker role
Author: sectracker Date: 2016-12-21 08:40:07 + (Wed, 21 Dec 2016) New Revision: 47269 Modified: data/packages/removed-packages Log: These packages have been removed Modified: data/packages/removed-packages === --- data/package

[Secure-testing-commits] r47270 - data/CVE

2016-12-21 Thread security tracker role
Author: sectracker Date: 2016-12-21 09:10:17 + (Wed, 21 Dec 2016) New Revision: 47270 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2016-12-21 08:40:07 UTC (rev 47269) +++ da

[Secure-testing-commits] r47271 - data/DSA

2016-12-21 Thread Sebastien Delafond
Author: seb Date: 2016-12-21 11:20:12 + (Wed, 21 Dec 2016) New Revision: 47271 Modified: data/DSA/list Log: Reserve DSA-3737-2 for the regression in php-ssh2 Modified: data/DSA/list === --- data/DSA/list 2016-12-21 09:10

[Secure-testing-commits] r47272 - data/DSA

2016-12-21 Thread Sebastien Delafond
Author: seb Date: 2016-12-21 11:29:51 + (Wed, 21 Dec 2016) New Revision: 47272 Modified: data/DSA/list Log: DSA-3732-1 caused the php-ssh2 regression, not DSA-3737-1 Modified: data/DSA/list === --- data/DSA/list 2016-12-

[Secure-testing-commits] r47273 - data/CVE

2016-12-21 Thread Moritz Muehlenhoff
Author: jmm Date: 2016-12-21 12:01:16 + (Wed, 21 Dec 2016) New Revision: 47273 Modified: data/CVE/list Log: openssh triage Modified: data/CVE/list === --- data/CVE/list 2016-12-21 11:29:51 UTC (rev 47272) +++ data/CVE/l

[Secure-testing-commits] r47274 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 12:08:33 + (Wed, 21 Dec 2016) New Revision: 47274 Modified: data/CVE/list Log: Add CVE-2016-10025 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 12:01:16 UTC (rev 47273) +++ data

[Secure-testing-commits] r47275 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 12:09:35 + (Wed, 21 Dec 2016) New Revision: 47275 Modified: data/CVE/list Log: Fix XSA number Modified: data/CVE/list === --- data/CVE/list 2016-12-21 12:08:33 UTC (rev 47274) +++ data/CVE

[Secure-testing-commits] r47276 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 12:11:10 + (Wed, 21 Dec 2016) New Revision: 47276 Modified: data/CVE/list Log: Add CVE-2016-10024/xen Modified: data/CVE/list === --- data/CVE/list 2016-12-21 12:09:35 UTC (rev 47275) +++

[Secure-testing-commits] r47277 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 13:47:34 + (Wed, 21 Dec 2016) New Revision: 47277 Modified: data/CVE/list Log: Add fixed version for CVE-2016-7392/autotrace Modified: data/CVE/list === --- data/CVE/list 2016-12-21 12:11:

[Secure-testing-commits] r47278 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 15:11:59 + (Wed, 21 Dec 2016) New Revision: 47278 Modified: data/CVE/list Log: Add information for CVE-2012-5564 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 13:47:34 UTC (rev

[Secure-testing-commits] r47279 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 15:29:38 + (Wed, 21 Dec 2016) New Revision: 47279 Modified: data/CVE/list Log: Update status for CVE-2016-9932 according to Ian Jackson Modified: data/CVE/list === --- data/CVE/list 2016-1

[Secure-testing-commits] r47280 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 15:34:38 + (Wed, 21 Dec 2016) New Revision: 47280 Modified: data/CVE/list Log: Update references for CVE-2016-10012 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 15:29:38 UTC (r

[Secure-testing-commits] r47281 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 15:39:01 + (Wed, 21 Dec 2016) New Revision: 47281 Modified: data/CVE/list Log: Mark CVE-2016-10012 as no-dsa Modified: data/CVE/list === --- data/CVE/list 2016-12-21 15:34:38 UTC (rev 4728

[Secure-testing-commits] r47282 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 15:39:44 + (Wed, 21 Dec 2016) New Revision: 47282 Modified: data/CVE/list Log: CVE-2016-10012: mark as low Modified: data/CVE/list === --- data/CVE/list 2016-12-21 15:39:01 UTC (rev 47281)

[Secure-testing-commits] r47283 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:17:07 + (Wed, 21 Dec 2016) New Revision: 47283 Modified: data/CVE/list Log: Mark CVE-2016-9888/libgsf as no-dsa Modified: data/CVE/list === --- data/CVE/list 2016-12-21 15:39:44 UTC (re

[Secure-testing-commits] r47284 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:19:48 + (Wed, 21 Dec 2016) New Revision: 47284 Modified: data/CVE/list Log: Add fixing version for CVE-2016-3739 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:17:07 UTC (r

[Secure-testing-commits] r47285 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:28:01 + (Wed, 21 Dec 2016) New Revision: 47285 Modified: data/CVE/list Log: Add new apache2 issues Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:19:48 UTC (rev 47284) +++

[Secure-testing-commits] r47286 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:30:05 + (Wed, 21 Dec 2016) New Revision: 47286 Modified: data/CVE/list Log: Update note for CVE-2016-8743 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:28:01 UTC (rev 4728

[Secure-testing-commits] r47287 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:32:29 + (Wed, 21 Dec 2016) New Revision: 47287 Modified: data/CVE/list Log: Add description for CVE-2016-8743 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:30:05 UTC (rev

[Secure-testing-commits] r47288 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:32:39 + (Wed, 21 Dec 2016) New Revision: 47288 Modified: data/CVE/list Log: Add notes for CVE-2016-2161/apache2 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:32:29 UTC (re

[Secure-testing-commits] r47289 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 16:34:16 + (Wed, 21 Dec 2016) New Revision: 47289 Modified: data/CVE/list Log: Add notes for CVE-2016-0736/apache2 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:32:39 UTC (re

[Secure-testing-commits] r47291 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 19:04:44 + (Wed, 21 Dec 2016) New Revision: 47291 Modified: data/CVE/list Log: Mark CVE-2016-6812 as NFU Modified: data/CVE/list === --- data/CVE/list 2016-12-21 19:04:32 UTC (rev 47290) +

[Secure-testing-commits] r47292 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 19:04:54 + (Wed, 21 Dec 2016) New Revision: 47292 Modified: data/CVE/list Log: CVE-2016-4552 has to be used for previous CVE-2016-5103 CVE-2016-5103 will be rejected on next update, there was a duplicate assignment for this issue. All references to CVE-2016-

[Secure-testing-commits] r47290 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 19:04:32 + (Wed, 21 Dec 2016) New Revision: 47290 Modified: data/CVE/list Log: MarkCVE-2016-8739 as NFU Modified: data/CVE/list === --- data/CVE/list 2016-12-21 16:34:16 UTC (rev 47289) ++

[Secure-testing-commits] r47293 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 19:24:00 + (Wed, 21 Dec 2016) New Revision: 47293 Modified: data/CVE/list Log: Update for CVE-2016-9566 Actually it is not clear if the same CVE can be used for the similar vulnerability in icinga (beeing a fork of nagios3). Might need clarification from MIT

[Secure-testing-commits] r47294 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 19:25:29 + (Wed, 21 Dec 2016) New Revision: 47294 Modified: data/CVE/list Log: CVE-2016-9566 add commit for icinga Modified: data/CVE/list === --- data/CVE/list 2016-12-21 19:24:00 UTC (re

[Secure-testing-commits] r47296 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 20:15:27 + (Wed, 21 Dec 2016) New Revision: 47296 Modified: data/CVE/list Log: Update status for CVE-2016-2161/apache2 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 20:15:15 UTC

[Secure-testing-commits] r47295 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 20:15:15 + (Wed, 21 Dec 2016) New Revision: 47295 Modified: data/CVE/list Log: Add fix for CVE-2016-2161 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 19:25:29 UTC (rev 47294) +

[Secure-testing-commits] r47297 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 20:19:43 + (Wed, 21 Dec 2016) New Revision: 47297 Modified: data/CVE/list Log: Update information for CVE-2016-0736 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 20:15:27 UTC (r

[Secure-testing-commits] r47298 - data/CVE

2016-12-21 Thread security tracker role
Author: sectracker Date: 2016-12-21 21:10:12 + (Wed, 21 Dec 2016) New Revision: 47298 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2016-12-21 20:19:43 UTC (rev 47297) +++ da

[Secure-testing-commits] r47299 - data/CVE

2016-12-21 Thread Petter Reinholdtsen
Author: pere Date: 2016-12-21 21:10:37 + (Wed, 21 Dec 2016) New Revision: 47299 Modified: data/CVE/list Log: Add package reference for CVE-2016-9836 based on CPE tracking. Modified: data/CVE/list === --- data/CVE/list 20

[Secure-testing-commits] r47300 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 21:12:56 + (Wed, 21 Dec 2016) New Revision: 47300 Modified: data/CVE/list Log: Remove TODO item for CVE-2016-5103 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 21:10:37 UTC (rev

[Secure-testing-commits] r47301 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-21 21:13:06 + (Wed, 21 Dec 2016) New Revision: 47301 Modified: data/CVE/list Log: Remove TODO item for CVE-2016-9836 Modified: data/CVE/list === --- data/CVE/list 2016-12-21 21:12:56 UTC (rev

[Secure-testing-commits] r47302 - data

2016-12-21 Thread Antoine Beaupré
Author: anarcat Date: 2016-12-21 21:21:36 + (Wed, 21 Dec 2016) New Revision: 47302 Modified: data/dla-needed.txt Log: Summary: try to take on nss again Modified: data/dla-needed.txt === --- data/dla-needed.txt 2016-12-21 21:1

[Secure-testing-commits] r47303 - data/CVE

2016-12-21 Thread Ola Lundqvist
Author: opal Date: 2016-12-21 21:43:53 + (Wed, 21 Dec 2016) New Revision: 47303 Modified: data/CVE/list Log: No dsa for icinga. Modified: data/CVE/list === --- data/CVE/list 2016-12-21 21:21:36 UTC (rev 47302) +++ data/C

[Secure-testing-commits] r47304 - data/CVE

2016-12-21 Thread Ola Lundqvist
Author: opal Date: 2016-12-21 21:47:34 + (Wed, 21 Dec 2016) New Revision: 47304 Modified: data/CVE/list Log: No dsa for openssh. Same as triaged for jessie. Modified: data/CVE/list === --- data/CVE/list 2016-12-21 21:43:

[Secure-testing-commits] r47305 - data/CVE

2016-12-21 Thread Ola Lundqvist
Author: opal Date: 2016-12-21 22:07:21 + (Wed, 21 Dec 2016) New Revision: 47305 Modified: data/CVE/list Log: Start of apache2 triage. Modified: data/CVE/list === --- data/CVE/list 2016-12-21 21:47:34 UTC (rev 47304) +++

[Secure-testing-commits] r47306 - data/CVE

2016-12-21 Thread Henri Salo
Author: fgeek-guest Date: 2016-12-21 22:08:34 + (Wed, 21 Dec 2016) New Revision: 47306 Modified: data/CVE/list Log: CVE-2016-9838/joomla itp Modified: data/CVE/list === --- data/CVE/list 2016-12-21 22:07:21 UTC (rev 4730

[Secure-testing-commits] r47307 - data

2016-12-21 Thread Antoine Beaupré
Author: anarcat Date: 2016-12-21 22:17:10 + (Wed, 21 Dec 2016) New Revision: 47307 Modified: data/dla-needed.txt Log: Summary: add notes re. lxc: no-dsa? Modified: data/dla-needed.txt === --- data/dla-needed.txt 2016-12-21 22

[Secure-testing-commits] r47308 - data/CVE

2016-12-21 Thread Stefan Fritsch
Author: sf Date: 2016-12-21 23:13:30 + (Wed, 21 Dec 2016) New Revision: 47308 Modified: data/CVE/list Log: update apache2 issues Modified: data/CVE/list === --- data/CVE/list 2016-12-21 22:17:10 UTC (rev 47307) +++ data

[Secure-testing-commits] r47310 - in data: . DLA

2016-12-21 Thread Antoine Beaupré
Author: anarcat Date: 2016-12-22 01:35:59 + (Thu, 22 Dec 2016) New Revision: 47310 Modified: data/DLA/list data/dla-needed.txt Log: Reserve DLA-756-1 for imagemagick Modified: data/DLA/list === --- data/DLA/list 2016-

[Secure-testing-commits] r47311 - data

2016-12-21 Thread Balint Reczey
Author: rbalint Date: 2016-12-22 01:37:37 + (Thu, 22 Dec 2016) New Revision: 47311 Modified: data/dla-needed.txt Log: claim libgd2 DLA Modified: data/dla-needed.txt === --- data/dla-needed.txt 2016-12-22 01:35:59 UTC (rev 4731

[Secure-testing-commits] r47312 - data/CVE

2016-12-21 Thread Antoine Beaupré
Author: anarcat Date: 2016-12-22 01:58:24 + (Thu, 22 Dec 2016) New Revision: 47312 Modified: data/CVE/list Log: mark fixed bugs manually for DLA-756-1 for missing CVEs Modified: data/CVE/list === --- data/CVE/list 2016-1

[Secure-testing-commits] r47313 - data

2016-12-21 Thread Antoine Beaupré
Author: anarcat Date: 2016-12-22 02:03:05 + (Thu, 22 Dec 2016) New Revision: 47313 Modified: data/dla-needed.txt Log: Summary: gcc 4.7 support fixed in nss turns out that we needed a patch on the build chain for environment to propagata - guh. i also ran the test suite (on arm!) and it pa

[Secure-testing-commits] r47314 - data/CVE

2016-12-21 Thread Balint Reczey
Author: rbalint Date: 2016-12-22 02:51:42 + (Thu, 22 Dec 2016) New Revision: 47314 Modified: data/CVE/list Log: add bug for libgd2 CVE-2016-9933 Modified: data/CVE/list === --- data/CVE/list 2016-12-22 02:03:05 UTC (rev

[Secure-testing-commits] r47315 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:28:10 + (Thu, 22 Dec 2016) New Revision: 47315 Modified: data/CVE/list Log: CVE-2015-8869/ocaml fixed in unstable Modified: data/CVE/list === --- data/CVE/list 2016-12-22 02:51:42 UTC (

[Secure-testing-commits] r47316 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:29:07 + (Thu, 22 Dec 2016) New Revision: 47316 Modified: data/CVE/list Log: Add fixing version for CVE-2016-4429 Modified: data/CVE/list === --- data/CVE/list 2016-12-22 05:28:10 UTC (r

[Secure-testing-commits] r47317 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:46:02 + (Thu, 22 Dec 2016) New Revision: 47317 Modified: data/CVE/list Log: Mark CVE-2016-9595 as NFU Modified: data/CVE/list === --- data/CVE/list 2016-12-22 05:29:07 UTC (rev 47316) +

[Secure-testing-commits] r47318 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:52:33 + (Thu, 22 Dec 2016) New Revision: 47318 Modified: data/CVE/list Log: Add bug report for CVE-2016-9579 Modified: data/CVE/list === --- data/CVE/list 2016-12-22 05:46:02 UTC (rev 4

[Secure-testing-commits] r47319 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:56:14 + (Thu, 22 Dec 2016) New Revision: 47319 Modified: data/CVE/list Log: CVE-2016-8626/ceph fixed with 10.2.5-1 upload, #844200 Modified: data/CVE/list === --- data/CVE/list 2016-12-

[Secure-testing-commits] r47320 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 05:58:41 + (Thu, 22 Dec 2016) New Revision: 47320 Modified: data/CVE/list Log: CVE-2016-7031/ceph fixed as well with 10.2.5-1 Modified: data/CVE/list === --- data/CVE/list 2016-12-22 05:56

[Secure-testing-commits] r47321 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 06:02:49 + (Thu, 22 Dec 2016) New Revision: 47321 Modified: data/CVE/list Log: Add fixing version for CVE-2016-5009/ceph Modified: data/CVE/list === --- data/CVE/list 2016-12-22 05:58:41 U

[Secure-testing-commits] r47322 - in data: . DLA

2016-12-21 Thread Brian May
Author: bam Date: 2016-12-22 06:28:23 + (Thu, 22 Dec 2016) New Revision: 47322 Modified: data/DLA/list data/dla-needed.txt Log: Mark phpmyadmin as fixed Modified: data/DLA/list === --- data/DLA/list 2016-12-22 06:02:4

[Secure-testing-commits] r47323 - data/CVE

2016-12-21 Thread Petter Reinholdtsen
Author: pere Date: 2016-12-22 06:43:58 + (Thu, 22 Dec 2016) New Revision: 47323 Modified: data/CVE/list Log: Mark serendipity as removed in relevant CVEs. Add wolfssl as unfixed in relevant CVEs. Did not have time to check if wolfssl really is unfixed. Modified: data/CVE/list ==

[Secure-testing-commits] r47324 - data/CPE

2016-12-21 Thread Petter Reinholdtsen
Author: pere Date: 2016-12-22 06:44:28 + (Thu, 22 Dec 2016) New Revision: 47324 Modified: data/CPE/aliases data/CPE/list Log: More aliases and a new CPE mapping. Modified: data/CPE/aliases === --- data/CPE/aliases2016-1

[Secure-testing-commits] r47325 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 07:14:02 + (Thu, 22 Dec 2016) New Revision: 47325 Modified: data/CVE/list Log: Add fixed version for CVE-2015-7744/wolfssl Modified: data/CVE/list === --- data/CVE/list 2016-12-22 06:44:28

[Secure-testing-commits] r47326 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 07:15:19 + (Thu, 22 Dec 2016) New Revision: 47326 Modified: data/CVE/list Log: CVE-2016-743{8,9} fixed in unstable upload Modified: data/CVE/list === --- data/CVE/list 2016-12-22 07:14:02

[Secure-testing-commits] r47327 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 07:16:16 + (Thu, 22 Dec 2016) New Revision: 47327 Modified: data/CVE/list Log: CVE-2016-7440 fixed in unstable Modified: data/CVE/list === --- data/CVE/list 2016-12-22 07:15:19 UTC (rev 47

[Secure-testing-commits] r47328 - data/CVE

2016-12-21 Thread Salvatore Bonaccorso
Author: carnil Date: 2016-12-22 07:48:59 + (Thu, 22 Dec 2016) New Revision: 47328 Modified: data/CVE/list Log: CVE-2016-9588: Add reference to upstream fix Modified: data/CVE/list === --- data/CVE/list 2016-12-22 07:16:1