[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim ruby-sinatra.

2023-01-01 Thread Chris Lamb (@lamby)
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker Commits: 9707578c by Chris Lamb at 2023-01-02T07:10:09+00:00 data/dla-needed.txt: Claim ruby-sinatra. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-n

[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim smarty3.

2023-01-01 Thread Chris Lamb (@lamby)
-needed.txt = @@ -292,7 +292,7 @@ samba NOTE: 20220904: Special attention: High popcon! Used in many servers. NOTE: 20220904: Many postponed or open CVE in general. (apo) -- -smarty3 +smarty3 (Chris Lamb) NOTE: 20230101: Programming language: PHP

[Git][security-tracker-team/security-tracker][master] Add additionally git tag information for two upstream commits

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: f13c457b by Salvatore Bonaccorso at 2023-01-02T07:36:18+01:00 Add additionally git tag information for two upstream commits - - - - - 1 changed file: - data/CVE/list Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-47952/lxc

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: ee621025 by Salvatore Bonaccorso at 2023-01-02T07:32:30+01:00 Add CVE-2022-47952/lxc - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Add CVE-2023-0030/linux

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 3ebdc0cf by Salvatore Bonaccorso at 2023-01-02T07:29:01+01:00 Add CVE-2023-0030/linux - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/lis

[Git][security-tracker-team/security-tracker][master] CVE-2021-37136, CVE-2021-37137, CVE-2021-43797, CVE-2022-41881, CVE-2022-41915, netty

2023-01-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: 9dcadd10 by Markus Koschany at 2023-01-01T23:16:55+01:00 CVE-2021-37136,CVE-2021-37137,CVE-2021-43797,CVE-2022-41881,CVE-2022-41915,netty fixed in unstable - - - - - 1 changed file: - data/CVE/l

[Git][security-tracker-team/security-tracker][master] buster isn't affected by CVE-2020-27839

2023-01-01 Thread Stefano Rivera (@stefanor)
Stefano Rivera pushed to branch master at Debian Security Tracker / security-tracker Commits: 9871529d by Stefano Rivera at 2023-01-01T18:00:10-04:00 buster isn't affected by CVE-2020-27839 - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: c1d1e9a7 by Salvatore Bonaccorso at 2023-01-01T21:16:01+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] automatic update

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: eca7adfc by security tracker role at 2023-01-01T20:10:35+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2022-46175/node-json5

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1ced87e7 by Salvatore Bonaccorso at 2023-01-01T21:08:30+01:00 Track fixed version via unstable for CVE-2022-46175/node-json5 - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for CVE-2018-109{8,9}/etcd

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 95d4d60c by Salvatore Bonaccorso at 2023-01-01T20:53:42+01:00 Track fixed version via unstable for CVE-2018-109{8,9}/etcd - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2022-41881,netty: Link to fixing commit

2023-01-01 Thread Markus Koschany (@apo)
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker Commits: c4a685e5 by Markus Koschany at 2023-01-01T19:07:24+01:00 CVE-2022-41881,netty: Link to fixing commit - - - - - 18eefb99 by Markus Koschany at 2023-01-01T19:10:06+01:00 CVE-2022-41915,netty: Link to

[Git][security-tracker-team/security-tracker][master] Process some NFUs

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 1b6534f1 by Salvatore Bonaccorso at 2023-01-01T17:59:02+01:00 Process some NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3260-1 for node-xmldom

2023-01-01 Thread Guilhem Moulin (@guilhem)
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker Commits: ffcb381a by Guilhem Moulin at 2023-01-01T17:49:36+01:00 Reserve DLA-3260-1 for node-xmldom - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3341/ffmpeg

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 661a7231 by Salvatore Bonaccorso at 2023-01-01T17:21:07+01:00 Add CVE-2022-3341/ffmpeg - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked CVE-2022-39209 and CVE-2022-24724 as no-dsa for buster following the...

2023-01-01 Thread Ola Lundqvist (@opal)
inor issue) = data/dla-needed.txt = @@ -297,6 +297,9 @@ samba NOTE: 20220904: Special attention: High popcon! Used in many servers. NOTE: 20220904: Many postponed or open CVE in general. (apo) -- +smarty3 + NOTE: 20230101: Programming language: PHP. +--

[Git][security-tracker-team/security-tracker][master] LTS: add nheko to dla-needed.txt

2023-01-01 Thread Ola Lundqvist (@opal)
-needed.txt = @@ -163,6 +163,9 @@ nextcloud-desktop NOTE: 20221128: VCS: https://salsa.debian.org/owncloud-team/nextcloud-desktop NOTE: 20221128: Please coordinate with maintainer the usage of their git-repo (gladk). -- +nheko + NOTE: 20230101: Programming

[Git][security-tracker-team/security-tracker][master] 2 commits: Reverted d2c2b240ffcc27edbc1008b66866fe49a62457dd since it is unclear whether...

2023-01-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fb87e8e5 by Ola Lundqvist at 2023-01-01T15:04:54+01:00 Reverted d2c2b240ffcc27edbc1008b66866fe49a62457dd since it is unclear whether nvidia drivers are supported in buster or not. - - - - - f1f6f5eb

[Git][security-tracker-team/security-tracker][master] LTS: add snakeyaml to dla-needed.txt

2023-01-01 Thread Ola Lundqvist (@opal)
/dla-needed.txt = @@ -294,6 +294,9 @@ samba NOTE: 20220904: Special attention: High popcon! Used in many servers. NOTE: 20220904: Many postponed or open CVE in general. (apo) -- +snakeyaml + NOTE: 20230101: Programming language: Java. +-- snort NOTE

[Git][security-tracker-team/security-tracker][master] Drop some TODO items for CVEs meant to be REJECTED

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: b6ea994f by Salvatore Bonaccorso at 2023-01-01T10:30:20+01:00 Drop some TODO items for CVEs meant to be REJECTED The assigning CNA (Altassian) has only updated the description for some reason b

[Git][security-tracker-team/security-tracker][master] Process two NFUs

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: a99f561e by Salvatore Bonaccorso at 2023-01-01T10:23:36+01:00 Process two NFUs - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list =

[Git][security-tracker-team/security-tracker][master] automatic update

2023-01-01 Thread Salvatore Bonaccorso (@carnil)
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker Commits: 51e35d25 by security tracker role at 2023-01-01T08:10:11+00:00 automatic update - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/list