[Secure-testing-commits] r58670 - data/CVE

2017-12-17 Thread Raphael Geissert
Author: geissert Date: 2017-12-18 07:09:46 + (Mon, 18 Dec 2017) New Revision: 58670 Modified: data/CVE/list Log: some NFUs Modified: data/CVE/list === --- data/CVE/list 2017-12-18 06:27:05 UTC (rev 58669) +++ data/CVE/l

[Secure-testing-commits] r58669 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-18 06:27:05 + (Mon, 18 Dec 2017) New Revision: 58669 Modified: data/CVE/list Log: Add fixing version for CVE-2017-13098/bouncycastle Modified: data/CVE/list === --- data/CVE/list 2017-12-17 2

[Secure-testing-commits] r58668 - data/CVE

2017-12-17 Thread Raphael Geissert
Author: geissert Date: 2017-12-17 23:15:58 + (Sun, 17 Dec 2017) New Revision: 58668 Modified: data/CVE/list Log: gitlab, nexus NFU, ruby-net-ldap issues Modified: data/CVE/list === --- data/CVE/list 2017-12-17 21:10:12

[Secure-testing-commits] r58667 - data/CVE

2017-12-17 Thread security tracker role
Author: sectracker Date: 2017-12-17 21:10:12 + (Sun, 17 Dec 2017) New Revision: 58667 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2017-12-17 21:03:38 UTC (rev 58666) +++ da

[Secure-testing-commits] r58666 - in data: . DSA

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 21:03:38 + (Sun, 17 Dec 2017) New Revision: 58666 Modified: data/DSA/list data/dsa-needed.txt Log: Reserve DSA number for rsync Modified: data/DSA/list === --- data/DSA/list 2017-12-17

[Secure-testing-commits] r58665 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:20:50 + (Sun, 17 Dec 2017) New Revision: 58665 Modified: data/CVE/list Log: mark geomview as unimportant, arguments to browser are not validated, but only trusted input is passed to ui_manual_browser and accessing the documentation Modified: data/CVE/lis

[Secure-testing-commits] r58664 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:17:36 + (Sun, 17 Dec 2017) New Revision: 58664 Modified: data/CVE/list Log: Mark CVE-2017-17528/scummvm as unimportant Negligible security impact Modified: data/CVE/list === --- data/CVE/lis

[Secure-testing-commits] r58663 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:16:09 + (Sun, 17 Dec 2017) New Revision: 58663 Modified: data/CVE/list Log: Mark CVE-2017-17526/giac as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 20:14:46 UTC

[Secure-testing-commits] r58662 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:14:46 + (Sun, 17 Dec 2017) New Revision: 58662 Modified: data/CVE/list Log: Mark CVE-2017-17525 as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 20:05:35 UTC (rev

[Secure-testing-commits] r58661 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:05:35 + (Sun, 17 Dec 2017) New Revision: 58661 Modified: data/CVE/list Log: Mark CVE-2017-17517 as unimportant Negligible security impact. Furthermore the Debian packaging fixes DEFAULT_BROWSER_CMD to "sensible-browser '%s'". Modified: data/CVE/list

[Secure-testing-commits] r58660 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 20:00:05 + (Sun, 17 Dec 2017) New Revision: 58660 Modified: data/CVE/list Log: Mark CVE-2017-17516/rtv as unimportant The problematic script, and with negligible impact, is only in source and not installed in the binary package. Modified: data/CVE/list

[Secure-testing-commits] r58659 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 19:54:57 + (Sun, 17 Dec 2017) New Revision: 58659 Modified: data/CVE/list Log: Mark CVE-2017-17515 as unimportant The problematic part is commented out in the ObjectList file. Modified: data/CVE/list =

[Secure-testing-commits] r58658 - data

2017-12-17 Thread Moritz Muehlenhoff
Author: jmm Date: 2017-12-17 19:53:46 + (Sun, 17 Dec 2017) New Revision: 58658 Modified: data/dsa-needed.txt Log: openafs DSA Modified: data/dsa-needed.txt === --- data/dsa-needed.txt 2017-12-17 19:51:11 UTC (rev 58657) +++ d

[Secure-testing-commits] r58657 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 19:51:11 + (Sun, 17 Dec 2017) New Revision: 58657 Modified: data/CVE/list Log: Mark CVE-2017-17513, negligible security impact A user needs to open a scpecially crafted url via the problematik mtxrun programms. Modified: data/CVE/list ==

[Secure-testing-commits] r58654 - in data: CVE DSA

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 19:43:07 + (Sun, 17 Dec 2017) New Revision: 58654 Modified: data/CVE/list data/DSA/list Log: Record changes for DSA-4067-1 Modified: data/CVE/list === --- data/CVE/list 2017-12-17 19:33

[Secure-testing-commits] r58655 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 19:43:19 + (Sun, 17 Dec 2017) New Revision: 58655 Modified: data/CVE/list Log: Wrap long note Modified: data/CVE/list === --- data/CVE/list 2017-12-17 19:43:07 UTC (rev 58654) +++ data/CVE

[Secure-testing-commits] r58656 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 19:43:30 + (Sun, 17 Dec 2017) New Revision: 58656 Modified: data/CVE/list Log: Annotate CVE-2017-17426 to mention the fix to experimental Add it as note since it ever only affected the experimental version and unstable was . Still keep sort of record of the

[Secure-testing-commits] r58653 - data/CVE

2017-12-17 Thread Ola Lundqvist
Author: opal Date: 2017-12-17 19:33:23 + (Sun, 17 Dec 2017) New Revision: 58653 Modified: data/CVE/list Log: Adjustment. Modified: data/CVE/list === --- data/CVE/list 2017-12-17 19:05:40 UTC (rev 58652) +++ data/CVE/list

[Secure-testing-commits] r58652 - org

2017-12-17 Thread Thorsten Alteholz
Author: alteholz Date: 2017-12-17 19:05:40 + (Sun, 17 Dec 2017) New Revision: 58652 Modified: org/lts-frontdesk.2018.txt Log: my frontdessk 2018 Modified: org/lts-frontdesk.2018.txt === --- org/lts-frontdesk.2018.txt 2017-12-

[Secure-testing-commits] r58651 - data

2017-12-17 Thread Thorsten Alteholz
Author: alteholz Date: 2017-12-17 19:02:27 + (Sun, 17 Dec 2017) New Revision: 58651 Modified: data/dla-needed.txt Log: claim openafs Modified: data/dla-needed.txt === --- data/dla-needed.txt 2017-12-17 18:47:01 UTC (rev 58650)

[Secure-testing-commits] r58650 - data/CVE

2017-12-17 Thread Moritz Muehlenhoff
Author: jmm Date: 2017-12-17 18:47:01 + (Sun, 17 Dec 2017) New Revision: 58650 Modified: data/CVE/list Log: two imagemagick no-dsa ruby n/a Modified: data/CVE/list === --- data/CVE/list 2017-12-17 18:01:45 UTC (rev 5864

[Secure-testing-commits] r58649 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 18:01:45 + (Sun, 17 Dec 2017) New Revision: 58649 Modified: data/CVE/list Log: Adjust entry for CVE-2017-16997 Modified: data/CVE/list === --- data/CVE/list 2017-12-17 17:41:48 UTC (rev 58

[Secure-testing-commits] r58648 - data/CVE

2017-12-17 Thread Aurelien Jarno
Author: aurel32 Date: 2017-12-17 17:41:48 + (Sun, 17 Dec 2017) New Revision: 58648 Modified: data/CVE/list Log: Add details about CVE-2017-16997 Modified: data/CVE/list === --- data/CVE/list 2017-12-17 17:16:33 UTC (rev

[Secure-testing-commits] r58647 - data/CVE

2017-12-17 Thread Ola Lundqvist
Author: opal Date: 2017-12-17 17:16:33 + (Sun, 17 Dec 2017) New Revision: 58647 Modified: data/CVE/list Log: Triage result. Modified: data/CVE/list === --- data/CVE/list 2017-12-17 15:04:51 UTC (rev 58646) +++ data/CVE/l

[Secure-testing-commits] r58646 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 15:04:51 + (Sun, 17 Dec 2017) New Revision: 58646 Modified: data/CVE/list Log: Mark kildclient as no-dsa Modified: data/CVE/list === --- data/CVE/list 2017-12-17 14:47:35 UTC (rev 58645) +

[Secure-testing-commits] r58645 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 14:47:35 + (Sun, 17 Dec 2017) New Revision: 58645 Modified: data/CVE/list Log: Add fixing version for CVE-2017-15127 via unstable Modified: data/CVE/list === --- data/CVE/list 2017-12-17 1

[Secure-testing-commits] r58644 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 14:43:25 + (Sun, 17 Dec 2017) New Revision: 58644 Modified: data/CVE/list Log: CVE-2017-15126: already fixed in unstable, linux/4.13.10-1 Modified: data/CVE/list === --- data/CVE/list 2017

[Secure-testing-commits] r58643 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 14:38:49 + (Sun, 17 Dec 2017) New Revision: 58643 Modified: data/CVE/list Log: Add three new linux issues Modified: data/CVE/list === --- data/CVE/list 2017-12-17 14:10:06 UTC (rev 58642)

[Secure-testing-commits] r58642 - in data: . DSA

2017-12-17 Thread Moritz Muehlenhoff
Author: jmm Date: 2017-12-17 14:10:06 + (Sun, 17 Dec 2017) New Revision: 58642 Modified: data/DSA/list data/dsa-needed.txt Log: otrs DSA Modified: data/DSA/list === --- data/DSA/list 2017-12-17 13:47:56 UTC (rev 5864

[Secure-testing-commits] r58641 - in data: . DSA

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 13:47:56 + (Sun, 17 Dec 2017) New Revision: 58641 Modified: data/DSA/list data/dsa-needed.txt Log: Reserve DSA number for openssl1.0 update Modified: data/DSA/list === --- data/DSA/list

[Secure-testing-commits] r58640 - data

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 10:47:50 + (Sun, 17 Dec 2017) New Revision: 58640 Modified: data/dsa-needed.txt Log: Take openssl1.0 from dsa-needed list Modified: data/dsa-needed.txt === --- data/dsa-needed.txt 2017-12-17 09

[Secure-testing-commits] r58639 - data/CVE

2017-12-17 Thread security tracker role
Author: sectracker Date: 2017-12-17 09:10:16 + (Sun, 17 Dec 2017) New Revision: 58639 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:30:31 UTC (rev 58638) +++ da

[Secure-testing-commits] r58638 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:30:31 + (Sun, 17 Dec 2017) New Revision: 58638 Modified: data/CVE/list Log: Process NFUs Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:28:00 UTC (rev 58637) +++ data/CVE/l

[Secure-testing-commits] r58637 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:28:00 + (Sun, 17 Dec 2017) New Revision: 58637 Modified: data/CVE/list Log: Mark CVE-2017-17712 as not-affected for jessie and wheezy Modified: data/CVE/list === --- data/CVE/list 2017-

[Secure-testing-commits] r58636 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:27:16 + (Sun, 17 Dec 2017) New Revision: 58636 Modified: data/CVE/list Log: Mark CVE-2017-14184 as NFU Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:19:44 UTC (rev 58635)

[Secure-testing-commits] r58635 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:19:44 + (Sun, 17 Dec 2017) New Revision: 58635 Modified: data/CVE/list Log: CVE-2017-17522: sort entries by source package Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:16

[Secure-testing-commits] r58634 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:16:50 + (Sun, 17 Dec 2017) New Revision: 58634 Modified: data/CVE/list Log: Add CVE-2017-17712/linux Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:13:27 UTC (rev 58633) ++

[Secure-testing-commits] r58630 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:12:53 + (Sun, 17 Dec 2017) New Revision: 58630 Modified: data/CVE/list Log: Sort entries by source package Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:12:42 UTC (rev 586

[Secure-testing-commits] r58632 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:13:16 + (Sun, 17 Dec 2017) New Revision: 58632 Modified: data/CVE/list Log: Mark CVE-2017-17534 as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:13:04 UTC (rev

[Secure-testing-commits] r58633 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:13:27 + (Sun, 17 Dec 2017) New Revision: 58633 Modified: data/CVE/list Log: Mark CVE-2017-17519 as uniportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:13:16 UTC (rev

[Secure-testing-commits] r58631 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:13:04 + (Sun, 17 Dec 2017) New Revision: 58631 Modified: data/CVE/list Log: Mark CVE-2017-17531 as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:12:53 UTC (rev

[Secure-testing-commits] r58629 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:12:42 + (Sun, 17 Dec 2017) New Revision: 58629 Modified: data/CVE/list Log: Mark CVE-2017-17535 as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-17 08:12:30 UTC (rev

[Secure-testing-commits] r58628 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:12:30 + (Sun, 17 Dec 2017) New Revision: 58628 Modified: data/CVE/list Log: Remove no-dsa entry for entry which is marked already unimportant Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r58627 - data/CVE

2017-12-17 Thread Salvatore Bonaccorso
Author: carnil Date: 2017-12-17 08:12:10 + (Sun, 17 Dec 2017) New Revision: 58627 Modified: data/CVE/list Log: Mark fontforge issue as unimportant Modified: data/CVE/list === --- data/CVE/list 2017-12-16 23:49:40 UTC (re