[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Update krb5 in dla-needed.txt

2018-02-11 Thread Brian May
Brian May pushed to branch master at Debian Security Tracker / security-tracker Commits: cafc63f7 by Brian May at 2018-02-12T17:41:02+11:00 Update krb5 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt =

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Revert unimportant status for CVE-2018-1000024

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 4220b50f by Salvatore Bonaccorso at 2018-02-12T06:38:48+01:00 Revert unimportant status for CVE-2018-124 Both the libxml2 and expat parser are available, but in the default configuration the

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Reserve DLA-1277-1 for audacity

2018-02-11 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 1c0d00ff by Roberto C. Sánchez at 2018-02-11T23:08:34-05:00 Reserve DLA-1277-1 for audacity - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: =

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Remove additional questionable commit (that also doesn't apply) from CVE-2016-2540/audacity.

2018-02-11 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 6f54fba4 by Roberto C. Sánchez at 2018-02-11T22:35:41-05:00 Remove additional questionable commit (that also doesn't apply) from CVE-2016-2540/audacity. - - - - - 1 changed file: - data/CVE/lis

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Annotate another commit related to CVE-2016-2540/audacity

2018-02-11 Thread Roberto C . Sánchez
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker Commits: 935a7fef by Roberto C. Sánchez at 2018-02-11T21:18:00-05:00 Annotate another commit related to CVE-2016-2540/audacity - - - - - 1 changed file: - data/CVE/list Changes: ==

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Claim librsvg in data/dla-needed.txt

2018-02-11 Thread Chris Lamb
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: c63f347f by Chris Lamb at 2018-02-11T22:28:56+00:00 Claim librsvg in data/dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Process one NFU

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bcec2b31 by Salvatore Bonaccorso at 2018-02-11T22:35:17+01:00 Process one NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Mark CVE-2018-1000027/squid3 as no-dsa

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8026006f by Salvatore Bonaccorso at 2018-02-11T22:33:00+01:00 Mark CVE-2018-127/squid3 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: =

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Update information for CVE-2018-1000024/squid3

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 8168e9ce by Salvatore Bonaccorso at 2018-02-11T22:22:58+01:00 Update information for CVE-2018-124/squid3 The Debian builds do Build-Depends on libexpat1-dev and libxml2-dev for ESI support si

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] automatic update

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e6f50f47 by security tracker role at 2018-02-11T21:10:23+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Mark CVE-2018-6869 as no-dsa

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e832a04c by Salvatore Bonaccorso at 2018-02-11T21:32:36+01:00 Mark CVE-2018-6869 as no-dsa - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add CVE-2017-18174

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: fcf09679 by Salvatore Bonaccorso at 2018-02-11T21:13:17+01:00 Add CVE-2017-18174 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Update status for CVE-2018-6406 and CVE-2018-6548

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: baec1b7b by Salvatore Bonaccorso at 2018-02-11T20:35:55+01:00 Update status for CVE-2018-6406 and CVE-2018-6548 Update status to match the following: If source is affected but since the resulting

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Update notes for CVE-2018-1000061/mbedtls

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: aedc16d9 by Salvatore Bonaccorso at 2018-02-11T20:30:59+01:00 Update notes for CVE-2018-161/mbedtls Futher analysis by upstream and the original reporter showed that the thought issue leading

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add suricata to dla-needed.txt.

2018-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 4a368ae6 by Markus Koschany at 2018-02-11T19:41:25+01:00 Add suricata to dla-needed.txt. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-n

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] CVE-2018-6836, wireshark: Mark as no-dsa for Wheezy.

2018-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 944452ba by Markus Koschany at 2018-02-11T19:18:12+01:00 CVE-2018-6836, wireshark: Mark as no-dsa for Wheezy. - - - - - 1 changed file: - data/CVE/list Changes: =

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add librsvg to dla-needed.txt

2018-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: f8aa9d3d by Markus Koschany at 2018-02-11T19:16:41+01:00 Add librsvg to dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-nee

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Reserve DLA-1276-1 for tomcat-native

2018-02-11 Thread Markus Koschany
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: e0e46b3a by Markus Koschany at 2018-02-11T18:42:26+01:00 Reserve DLA-1276-1 for tomcat-native - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes: ==

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Demote CVE-2018-6353 severity to unimportant

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e8f2066d by Salvatore Bonaccorso at 2018-02-11T15:48:25+01:00 Demote CVE-2018-6353 severity to unimportant - - - - - 1 changed file: - data/CVE/list Changes: ===

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] libreoffice DSA

2018-02-11 Thread Moritz Muehlenhoff
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ee8d7d1 by Moritz Muehlenhoff at 2018-02-11T15:19:09+01:00 libreoffice DSA - - - - - 2 changed files: - data/DSA/list - data/dsa-needed.txt Changes: = dat

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add CVE-2018-1287/jakarta-jmeter

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: bd154da5 by Salvatore Bonaccorso at 2018-02-11T13:46:43+01:00 Add CVE-2018-1287/jakarta-jmeter - - - - - 1 changed file: - data/CVE/list Changes: = data/

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Associate CVE-2018-1297 with jakarta-jmeter

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0bd6c2f8 by Salvatore Bonaccorso at 2018-02-11T13:43:42+01:00 Associate CVE-2018-1297 with jakarta-jmeter - - - - - 1 changed file: - data/CVE/list Changes:

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Record proposed jessie-pu update for uwsgi

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 0075e3dd by Salvatore Bonaccorso at 2018-02-11T13:05:40+01:00 Record proposed jessie-pu update for uwsgi - - - - - 1 changed file: - data/next-oldstable-point-update.txt Changes: ==

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Schedule uwsgi via point releases

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 661e6d8e by Salvatore Bonaccorso at 2018-02-11T11:12:48+01:00 Schedule uwsgi via point releases - - - - - 1 changed file: - data/CVE/list Changes: = data

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Record proposed update for CVE-2018-6758 via stretch-pu

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 85c6ee21 by Salvatore Bonaccorso at 2018-02-11T11:13:14+01:00 Record proposed update for CVE-2018-6758 via stretch-pu - - - - - 1 changed file: - data/next-point-update.txt Changes: ===

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Drop two entries for dosfstools

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: e7c75f1a by Salvatore Bonaccorso at 2018-02-11T10:46:51+01:00 Drop two entries for dosfstools They will not be included in a jessie point release, cf. discussion in https://bugs.debian.org/827160

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Mark CVE-2018-6891 as NFU

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 6638dc91 by Salvatore Bonaccorso at 2018-02-11T10:45:37+01:00 Mark CVE-2018-6891 as NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Reference patches for CVE-2017-837{2, 3, 4}

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c213386 by Salvatore Bonaccorso at 2018-02-11T10:40:21+01:00 Reference patches for CVE-2017-837{2,3,4} Unfortunately libmad does not have a VCS yet were it is maintained, so need to reference th

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Update information for CVE-2016-2541

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 91a58716 by Salvatore Bonaccorso at 2018-02-11T10:16:56+01:00 Update information for CVE-2016-2541 Mark jessie as not-affected as the embedded source copy is not contained in 2.0.6 (yet). Mark w

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] automatic update

2018-02-11 Thread Salvatore Bonaccorso
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 2b4e7260 by security tracker role at 2018-02-11T09:10:19+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list ==

[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] NFU

2018-02-11 Thread Henri Salo
Henri Salo pushed to branch master at Debian Security Tracker / security-tracker Commits: 570030b4 by Henri Salo at 2018-02-11T11:04:12+02:00 NFU - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list = ---