[Secure-testing-commits] r58103 - data/CVE

2017-11-29 Thread Moritz Muehlenhoff
Author: jmm Date: 2017-11-29 08:09:13 + (Wed, 29 Nov 2017) New Revision: 58103 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2017-11-29 06:46:17 UTC (rev 58102) +++ data/CVE/list 2

[Secure-testing-commits] r58104 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 08:37:04 + (Wed, 29 Nov 2017) New Revision: 58104 Modified: data/CVE/list Log: Record fix for CVE-2017-1000248 via experimental Modified: data/CVE/list === --- data/CVE/list 2017-11-29 08:

[Secure-testing-commits] r58105 - data/CVE

2017-11-29 Thread security tracker role
Author: sectracker Date: 2017-11-29 09:10:23 + (Wed, 29 Nov 2017) New Revision: 58105 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2017-11-29 08:37:04 UTC (rev 58104) +++ da

[Secure-testing-commits] r58106 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 09:42:39 + (Wed, 29 Nov 2017) New Revision: 58106 Modified: data/CVE/list Log: Add new curl issues Modified: data/CVE/list === --- data/CVE/list 2017-11-29 09:10:23 UTC (rev 58105) +++ dat

[Secure-testing-commits] r58107 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 09:46:02 + (Wed, 29 Nov 2017) New Revision: 58107 Modified: data/CVE/list Log: Add references to patches for curl issues Modified: data/CVE/list === --- data/CVE/list 2017-11-29 09:42:39 U

[Secure-testing-commits] r58108 - data

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 09:49:11 + (Wed, 29 Nov 2017) New Revision: 58108 Modified: data/dsa-needed.txt Log: Add curl to dsa-needed list Modified: data/dsa-needed.txt === --- data/dsa-needed.txt 2017-11-29 09:46:02 UTC

[Secure-testing-commits] r58109 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 09:54:00 + (Wed, 29 Nov 2017) New Revision: 58109 Modified: data/CVE/list Log: Process NFUs Modified: data/CVE/list === --- data/CVE/list 2017-11-29 09:49:11 UTC (rev 58108) +++ data/CVE/l

[Secure-testing-commits] r58110 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 09:54:12 + (Wed, 29 Nov 2017) New Revision: 58110 Modified: data/CVE/list Log: Add CVE-2017-17054/aubio, not removed TODO yet since superficially checked only Modified: data/CVE/list === --- dat

[Secure-testing-commits] r58111 - in data: . DSA

2017-11-29 Thread Yves-Alexis Perez
Author: corsac Date: 2017-11-29 10:54:26 + (Wed, 29 Nov 2017) New Revision: 58111 Modified: data/DSA/list data/dsa-needed.txt Log: allocate DSA number for curl Modified: data/DSA/list === --- data/DSA/list 2017-11-29

[Secure-testing-commits] r58112 - data

2017-11-29 Thread Chris Lamb
Author: lamby Date: 2017-11-29 13:26:28 + (Wed, 29 Nov 2017) New Revision: 58112 Modified: data/dla-needed.txt Log: Triage curl for LTS Modified: data/dla-needed.txt === --- data/dla-needed.txt 2017-11-29 10:54:26 UTC (rev 581

[Secure-testing-commits] r58113 - data

2017-11-29 Thread Chris Lamb
(rev 58112) +++ data/dla-needed.txt 2017-11-29 13:28:50 UTC (rev 58113) @@ -107,6 +107,9 @@ swftools NOTE: 20171118: At least CVE-2017-16797 is present. (lamby) -- +thunderbird + NOTE: 20171129: Not sure if vulnerable as patches are private atm. (lamby) +-- tiff (Brian May) NOTE: CVE-2017

[Secure-testing-commits] r58114 - data/CVE

2017-11-29 Thread Chris Lamb
Author: lamby Date: 2017-11-29 13:34:57 + (Wed, 29 Nov 2017) New Revision: 58114 Modified: data/CVE/list Log: Triage qemu-kvm for wheezy. Modified: data/CVE/list === --- data/CVE/list 2017-11-29 13:28:50 UTC (rev 58113)

[Secure-testing-commits] r58115 - data

2017-11-29 Thread Thorsten Alteholz
Author: alteholz Date: 2017-11-29 14:21:57 + (Wed, 29 Nov 2017) New Revision: 58115 Modified: data/dla-needed.txt Log: claim curl Modified: data/dla-needed.txt === --- data/dla-needed.txt 2017-11-29 13:34:57 UTC (rev 58114) ++

[Secure-testing-commits] r58116 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 14:25:12 + (Wed, 29 Nov 2017) New Revision: 58116 Modified: data/CVE/list Log: Add fixing version for CVE-2017-14623/golang-github-go-ldap-ldap Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r58117 - data/CVE

2017-11-29 Thread Thorsten Alteholz
Author: alteholz Date: 2017-11-29 14:48:58 + (Wed, 29 Nov 2017) New Revision: 58117 Modified: data/CVE/list Log: CVE-2017-8816 not for Wheezy Modified: data/CVE/list === --- data/CVE/list 2017-11-29 14:25:12 UTC (rev 581

[Secure-testing-commits] r58118 - bin

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 15:21:40 + (Wed, 29 Nov 2017) New Revision: 58118 Modified: bin/report-vuln Log: report-vuln: Use spaces instead of tabs Modified: bin/report-vuln === --- bin/report-vuln 2017-11-29 14:48:58 UT

[Secure-testing-commits] r58119 - bin

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 15:22:09 + (Wed, 29 Nov 2017) New Revision: 58119 Modified: bin/report-vuln Log: report-vuln: don't fail if description_from_list return None If no description was found None is returned. This fixes Traceback (most recent call last): File "bin/report-vuln",

[Secure-testing-commits] r58120 - data/CVE

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 15:39:30 + (Wed, 29 Nov 2017) New Revision: 58120 Modified: data/CVE/list Log: CVE-2017-12596: link to upstream fix Modified: data/CVE/list === --- data/CVE/list 2017-11-29 15:22:09 UTC (rev

[Secure-testing-commits] r58121 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 19:15:27 + (Wed, 29 Nov 2017) New Revision: 58121 Modified: data/CVE/list Log: Add fixing version for CVE-2017-16944/exim4 Modified: data/CVE/list === --- data/CVE/list 2017-11-29 15:39:30

[Secure-testing-commits] r58122 - in data: . DSA

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 19:50:37 + (Wed, 29 Nov 2017) New Revision: 58122 Modified: data/DSA/list data/dsa-needed.txt Log: Reserve DSA number for bzr update Modified: data/DSA/list === --- data/DSA/list 2017-1

[Secure-testing-commits] r58123 - data/CVE

2017-11-29 Thread security tracker role
Author: sectracker Date: 2017-11-29 21:10:19 + (Wed, 29 Nov 2017) New Revision: 58123 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2017-11-29 19:50:37 UTC (rev 58122) +++ da

[Secure-testing-commits] r58124 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 21:25:13 + (Wed, 29 Nov 2017) New Revision: 58124 Modified: data/CVE/list Log: CVE-2017-8807/varnish fixed in unstable Modified: data/CVE/list === --- data/CVE/list 2017-11-29 21:10:19 UTC

[Secure-testing-commits] r58125 - bin

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 21:38:11 + (Wed, 29 Nov 2017) New Revision: 58125 Modified: bin/report-vuln Log: report-vuln: Support generation of mail headers Modified: bin/report-vuln === --- bin/report-vuln 2017-11-29 21:

[Secure-testing-commits] r58127 - /

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 21:38:29 + (Wed, 29 Nov 2017) New Revision: 58127 Modified: .gitignore Log: gitignore stamps dir Modified: .gitignore === --- .gitignore 2017-11-29 21:38:26 UTC (rev 58126) +++ .gitignore 2017-11

[Secure-testing-commits] r58126 - data/CVE

2017-11-29 Thread Guido Guenther
Author: agx Date: 2017-11-29 21:38:26 + (Wed, 29 Nov 2017) New Revision: 58126 Modified: data/CVE/list Log: lts: mark CVE-2017-14989 as postponed Modified: data/CVE/list === --- data/CVE/list 2017-11-29 21:38:11 UTC (rev

[Secure-testing-commits] r58128 - / stamps

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 21:50:07 + (Wed, 29 Nov 2017) New Revision: 58128 Added: stamps/.gitignore Modified: .gitignore Log: Don't ignore (when using git) stamps directory Reasoning, on git clean the directory will be removed. But the security tracker needs the stamps dir (e.g.

[Secure-testing-commits] r58129 - data

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-29 23:01:01 + (Wed, 29 Nov 2017) New Revision: 58129 Modified: data/next-point-update.txt Log: add proposed update for golang-github-go-ldap-ldap Modified: data/next-point-update.txt === --- data/n

[Secure-testing-commits] r58130 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-30 05:44:05 + (Thu, 30 Nov 2017) New Revision: 58130 Modified: data/CVE/list Log: Add CVE-2017-1000405/linux Modified: data/CVE/list === --- data/CVE/list 2017-11-29 23:01:01 UTC (rev 58129)

[Secure-testing-commits] r58131 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-30 06:02:20 + (Thu, 30 Nov 2017) New Revision: 58131 Modified: data/CVE/list Log: Add source package breezy as well for the CVE-2017-14176 (since "identical" code and so same CVE should apply) Modified: data/CVE/list ===

[Secure-testing-commits] r58132 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-30 06:13:37 + (Thu, 30 Nov 2017) New Revision: 58132 Modified: data/CVE/list Log: Add CVE-2017-15108/spice-vdagent Modified: data/CVE/list === --- data/CVE/list 2017-11-30 06:02:20 UTC (rev 5

[Secure-testing-commits] r58133 - data/CVE

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-30 06:18:11 + (Thu, 30 Nov 2017) New Revision: 58133 Modified: data/CVE/list Log: Add commit fixing CVE-2017-15108/spice-vdagent Modified: data/CVE/list === --- data/CVE/list 2017-11-30 06:13

[Secure-testing-commits] r58134 - in data: . DSA

2017-11-29 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-11-30 07:48:36 + (Thu, 30 Nov 2017) New Revision: 58134 Modified: data/DSA/list data/dsa-needed.txt Log: Reserve DSA number for exim4 update Modified: data/DSA/list === --- data/DSA/list 2017