[Git][security-tracker-team/security-tracker] Deleted branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package

2024-10-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist deleted branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker -- You're receiving this email because of your account on salsa.debian.org. ___ debian-security-tracker-commits

[Git][security-tracker-team/security-tracker][master] CVE-2024-32020 for git ignored

2024-10-17 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 3374e388 by Ola Lundqvist at 2024-10-16T22:13:55+02:00 CVE-2024-32020 for git ignored - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] Adding some more information for git.

2024-10-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fe2f871f by Ola Lundqvist at 2024-10-13T00:12:25+02:00 Adding some more information for git. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/d

[Git][security-tracker-team/security-tracker][master] Claimed git for LTS.

2024-10-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d52a7433 by Ola Lundqvist at 2024-10-07T22:09:00+02:00 Claimed git for LTS. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt ===

[Git][security-tracker-team/security-tracker][30-improve-gen-dsa-by-checking-cve-s-are-related-to-package] Print a warning in gen-DSA if the package cannot be found for a given CVE

2024-08-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker Commits: 95106bb6 by Ola Lundqvist at 2024-08-30T23:48:09+02:00 Print a warning in gen-DSA if the package cannot be found for a given CVE Introduced a ne

[Git][security-tracker-team/security-tracker] Pushed new branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package

2024-08-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed new branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/tree/30-improve-gen-dsa-by-checking-cve-s-are-related-to-package Y

[Git][security-tracker-team/security-tracker] Deleted branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package

2024-08-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist deleted branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker -- You're receiving this email because of your account on salsa.debian.org. ___ debian-security-tracker-commits

[Git][security-tracker-team/security-tracker][30-improve-gen-dsa-by-checking-cve-s-are-related-to-package] Print a warning if the package cannot be found for a given CVE

2024-08-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker Commits: 39492470 by Ola Lundqvist at 2024-08-30T23:08:55+02:00 Print a warning if the package cannot be found for a given CVE Introduced a new bin/check

[Git][security-tracker-team/security-tracker] Pushed new branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package

2024-08-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed new branch 30-improve-gen-dsa-by-checking-cve-s-are-related-to-package at Debian Security Tracker / security-tracker -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/tree/30-improve-gen-dsa-by-checking-cve-s-are-related-to-package Y

[Git][security-tracker-team/security-tracker][master] Print a warning if the package cannot be found for a given CVE.

2024-08-26 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d2285307 by Ola Lundqvist at 2024-08-26T23:49:15+02:00 Print a warning if the package cannot be found for a given CVE. This should help against simple mistakes such as typing the wrong CVE or the

[Git][security-tracker-team/security-tracker][master] Marked CVE-2024-6387 as not affected for buster.

2024-07-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d19eb14c by Ola Lundqvist at 2024-07-01T11:53:01+02:00 Marked CVE-2024-6387 as not affected for buster. See also https://lists.debian.org/debian-lts/2024/07/msg4.html - - - - - 1 changed file

[Git][security-tracker-team/security-tracker][master] Marked CVE-2024-30156 as ignored for buster following decision for bookworm and bullseye.

2024-06-30 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 1d65e99e by Ola Lundqvist at 2024-07-01T08:40:09+02:00 Marked CVE-2024-30156 as ignored for buster following decision for bookworm and bullseye. See also this thread https://lists.debian.org/debian

[Git][security-tracker-team/security-tracker][master] Patch prepared for bind9 and unclaim to allow someone else to complete it.

2024-04-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 17e946dc by Ola Lundqvist at 2024-04-18T20:48:30+02:00 Patch prepared for bind9 and unclaim to allow someone else to complete it. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] Added more information about bind9 work.

2024-04-17 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 808ec670 by Ola Lundqvist at 2024-04-17T23:41:03+02:00 Added more information about bind9 work. - - - - - 1 changed file: - data/dla-needed.txt Changes: = dat

[Git][security-tracker-team/security-tracker][master] CVE-2019-12214 update for openjpeg and freeimage

2024-04-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 08bd7be3 by Ola Lundqvist at 2024-04-14T13:48:42+02:00 CVE-2019-12214 update for openjpeg and freeimage Updated the information for CVE-2019-12214 based on information in https://lists.debian.org/

[Git][security-tracker-team/security-tracker][master] Claim bind9

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8d2ce1cd by Ola Lundqvist at 2024-04-13T00:26:56+02:00 Claim bind9 - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Minor date correction.

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4325ceef by Ola Lundqvist at 2024-04-13T00:25:56+02:00 Minor date correction. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt =

[Git][security-tracker-team/security-tracker][master] Added some notes about freeimage.

2024-04-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 98b77fac by Ola Lundqvist at 2024-04-12T10:37:34+02:00 Added some notes about freeimage. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-n

[Git][security-tracker-team/security-tracker][master] Removing claim since I will likely not have the time to work on the package for a few days.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b2c0ac9 by Ola Lundqvist at 2024-04-11T23:15:47+02:00 Removing claim since I will likely not have the time to work on the package for a few days. Do not want to prevent anyone from doing useful wo

[Git][security-tracker-team/security-tracker][master] 2 commits: Changed wording since the term tool can be misunderstood.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2f1d2047 by Ola Lundqvist at 2024-04-11T22:34:48+02:00 Changed wording since the term tool can be misunderstood. - - - - - 4a0e4e2a by Ola Lundqvist at 2024-04-11T22:34:50+02:00 Changed a some CVEs fr

[Git][security-tracker-team/security-tracker][master] Removed postpone tag for buster freeimage CVEs since patches are available in fedora.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 7d965e06 by Ola Lundqvist at 2024-04-11T22:26:16+02:00 Removed postpone tag for buster freeimage CVEs since patches are available in fedora. The postpone tag should probably be removed for later r

[Git][security-tracker-team/security-tracker][master] Removed postpone tag for buster freeimage CVE since patch is available in fedora.

2024-04-11 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 30068ece by Ola Lundqvist at 2024-04-11T22:11:20+02:00 Removed postpone tag for buster freeimage CVE since patch is available in fedora. The postpone tag should probably be removed for later releas

[Git][security-tracker-team/security-tracker][master] Tagged a few CVEs for freeimage as postponed.

2024-04-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d20822ee by Ola Lundqvist at 2024-04-10T22:19:21+02:00 Tagged a few CVEs for freeimage as postponed. Postponed because they are of DoS class and all reverse dependencies are tools used by a human that

[Git][security-tracker-team/security-tracker][master] Claim freeimage for buster.

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 51ecda99 by Ola Lundqvist at 2024-04-08T00:06:53+02:00 Claim freeimage for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.

[Git][security-tracker-team/security-tracker][master] Remove runc from dla-needed

2024-04-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6c41e578 by Ola Lundqvist at 2024-04-07T23:50:33+02:00 Remove runc from dla-needed - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Tinymce is not affected in buster, removing from dla-needed.

2024-03-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 21503da9 by Ola Lundqvist at 2024-03-14T23:21:32+01:00 Tinymce is not affected in buster, removing from dla-needed. Checked the version difference for each CVE where the issue is claimed to be impl

[Git][security-tracker-team/security-tracker][master] Claim tinymce.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4df8d8a9 by Ola Lundqvist at 2024-03-12T20:49:26+01:00 Claim tinymce. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt =

[Git][security-tracker-team/security-tracker][master] Reverted decision to remove from dla-needed since four CVEs has been fixed in bullseye.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ed2cc5c0 by Ola Lundqvist at 2024-03-12T20:44:33+01:00 Reverted decision to remove from dla-needed since four CVEs has been fixed in bullseye. - - - - - 1 changed file: - data/dla-needed.txt Cha

[Git][security-tracker-team/security-tracker][master] Noted reason for a few revert decisions in dla-needed for buster.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 3e1a0971 by Ola Lundqvist at 2024-03-12T20:40:41+01:00 Noted reason for a few revert decisions in dla-needed for buster. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reverted decision to remove python-os-brick from dla-needed since...

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: b945d184 by Ola Lundqvist at 2024-03-12T20:36:42+01:00 Reverted decision to remove python-os-brick from dla-needed since CVE-2020-10755 is fixed in bullseye. - - - - - 1 changed file: - data/dla-n

[Git][security-tracker-team/security-tracker][master] Reverted the decision to remove docker.io from dla-needed while keeping the...

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 58e9fdae by Ola Lundqvist at 2024-03-12T20:30:53+01:00 Reverted the decision to remove docker.io from dla-needed while keeping the no-dsa note for some CVEs. - - - - - 1 changed file: - data/dla-n

[Git][security-tracker-team/security-tracker][master] Reverted the decision to remove cinder from dla-needed.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: cc51d2ec by Ola Lundqvist at 2024-03-12T20:25:02+01:00 Reverted the decision to remove cinder from dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] Reverted nvidia-cuda-toolkit removal from dla-needed.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a60f675a by Ola Lundqvist at 2024-03-12T20:22:03+01:00 Reverted nvidia-cuda-toolkit removal from dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] Reverted decision to mark CVEs as ignored back to no-dsa for buster.

2024-03-12 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 9aadc7a2 by Ola Lundqvist at 2024-03-12T20:07:38+01:00 Reverted decision to mark CVEs as ignored back to no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f95d3ce8 by Ola Lundqvist at 2024-03-10T23:20:12+01:00 Removed sendmail from dla-needed since there is no CVE marked as need for a fix for buster. - - - - - 1 changed file: - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed runc from dla-needed since no CVEs remain to be fixed.

2024-03-10 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f20876c2 by Ola Lundqvist at 2024-03-10T23:07:51+01:00 Removed runc from dla-needed since no CVEs remain to be fixed. - - - - - e722a127 by Ola Lundqvist at 2024-03-10T23:09:22+01:00 Reverted decision

[Git][security-tracker-team/security-tracker][master] Removed qemu from dla-needed. Ignored one CVE instead of no-dsa.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 40854a51 by Ola Lundqvist at 2024-03-10T00:26:32+01:00 Removed qemu from dla-needed. Ignored one CVE instead of no-dsa. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed python-glance-store when marking CVE-2024-1141 as no-dsa following buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 542ce46a by Ola Lundqvist at 2024-03-10T00:21:35+01:00 Removed python-glance-store when marking CVE-2024-1141 as no-dsa following buster. - - - - - 37959a54 by Ola Lundqvist at 2024-03-10T00:24:10+01

[Git][security-tracker-team/security-tracker][master] Removed nvidia-cuda-toolkit from dla-needed since there were no CVEs...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: baecd314 by Ola Lundqvist at 2024-03-10T00:13:02+01:00 Removed nvidia-cuda-toolkit from dla-needed since there were no CVEs indicating that a fix is needed. - - - - - 1 changed file: - data/dla-ne

[Git][security-tracker-team/security-tracker][master] 2 commits: Removed knot-resolver from dla-needed and marked CVEs as either no-dsa or...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 0d002f8b by Ola Lundqvist at 2024-03-10T00:05:39+01:00 Removed knot-resolver from dla-needed and marked CVEs as either no-dsa or ignored following bullseye. - - - - - 039a4be0 by Ola Lundqvist at 202

[Git][security-tracker-team/security-tracker][master] Removed golang-go.crypto from dla-needed and marked one CVE as no-dsa for...

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: dbde6826 by Ola Lundqvist at 2024-03-10T00:00:28+01:00 Removed golang-go.crypto from dla-needed and marked one CVE as no-dsa for buster following bullseye. - - - - - 2 changed files: - data/CVE/li

[Git][security-tracker-team/security-tracker][master] Removed freeimage from dla-needed and marked its CVEs as postponed for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b7eb714 by Ola Lundqvist at 2024-03-09T23:57:45+01:00 Removed freeimage from dla-needed and marked its CVEs as postponed for buster following bullseye. - - - - - 2 changed files: - data/CVE/list

[Git][security-tracker-team/security-tracker][master] Removed exiftags from dla-needed and marked one CVE as no-dsa for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e215b731 by Ola Lundqvist at 2024-03-09T23:55:05+01:00 Removed exiftags from dla-needed and marked one CVE as no-dsa for buster following bullseye. - - - - - 2 changed files: - data/CVE/list - dat

[Git][security-tracker-team/security-tracker][master] Marked most CVEs for edk2 as no-dsa for buster following bullseye.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: bf6cd7b0 by Ola Lundqvist at 2024-03-09T23:52:46+01:00 Marked most CVEs for edk2 as no-dsa for buster following bullseye. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Marked CVEs for docker.io as no-dsa for buster and removed from dla-needed.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ebad433e by Ola Lundqvist at 2024-03-09T23:46:43+01:00 Marked CVEs for docker.io as no-dsa for buster and removed from dla-needed. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt

[Git][security-tracker-team/security-tracker][master] Removed cinder from dla-needed since all CVEs are no-dsa.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 202d1034 by Ola Lundqvist at 2024-03-09T23:31:58+01:00 Removed cinder from dla-needed since all CVEs are no-dsa. - - - - - 2 changed files: - data/CVE/list - data/dla-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] Removed cairosvg from dla-needed since CVE-2023-27586 is too intrusive to fix in buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4414c335 by Ola Lundqvist at 2024-03-09T23:27:28+01:00 Removed cairosvg from dla-needed since CVE-2023-27586 is too intrusive to fix in buster. - - - - - 2 changed files: - data/CVE/list - data/dl

[Git][security-tracker-team/security-tracker][master] Removed cpio from dla-needed since there is no CVE to fix.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 38b460a8 by Ola Lundqvist at 2024-03-09T23:20:12+01:00 Removed cpio from dla-needed since there is no CVE to fix. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-46426 and CVE-2023-46427 end-of-life for buster.

2024-03-09 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d882f249 by Ola Lundqvist at 2024-03-09T23:14:28+01:00 Marked CVE-2023-46426 and CVE-2023-46427 end-of-life for buster. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Ignore CVE-2023-52322 instead of no-dsa in buster even if fixed in bullseye.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c2265f4e by Ola Lundqvist at 2024-03-08T23:02:02+01:00 Ignore CVE-2023-52322 instead of no-dsa in buster even if fixed in bullseye. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] 5 commits: Added libpgjava to dla-needed. Better to be safe than sorrow.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4309d77c by Ola Lundqvist at 2024-03-08T22:59:25+01:00 Added libpgjava to dla-needed. Better to be safe than sorrow. - - - - - 2c8bb864 by Ola Lundqvist at 2024-03-08T22:59:27+01:00 Ignore CVE-2023-08

[Git][security-tracker-team/security-tracker][master] 3 commits: Marked CVE-2014-7250 (kfreebsd-10) as end-of-life for buster.

2024-03-08 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ea883b0b by Ola Lundqvist at 2024-03-08T22:35:57+01:00 Marked CVE-2014-7250 (kfreebsd-10) as end-of-life for buster. - - - - - a3bbeff1 by Ola Lundqvist at 2024-03-08T22:35:58+01:00 CVE-2015-1554 conc

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked CVEs for nvidia-graphics-drivers-legacy-340xx as ignored for buster.

2024-03-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: fc30ba59 by Ola Lundqvist at 2024-03-07T23:54:31+01:00 Marked CVEs for nvidia-graphics-drivers-legacy-340xx as ignored for buster. - - - - - c7598151 by Ola Lundqvist at 2024-03-07T23:54:32+01:00 Anal

[Git][security-tracker-team/security-tracker][master] Marked CVE-2024-2236 as no-dsa following bullseye.

2024-03-07 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 3264f217 by Ola Lundqvist at 2024-03-07T22:57:54+01:00 Marked CVE-2024-2236 as no-dsa following bullseye. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 2 commits: Treat CVE-2024-2002 as minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 256a9424 by Ola Lundqvist at 2024-03-06T21:56:38+01:00 Treat CVE-2024-2002 as minor issue for buster. - - - - - 9cc8914a by Ola Lundqvist at 2024-03-06T21:56:38+01:00 Added expat to dla-needed. - - -

[Git][security-tracker-team/security-tracker][master] 2 commits: Treat CVE-2024-27351 as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6b498faf by Ola Lundqvist at 2024-03-06T21:51:53+01:00 Treat CVE-2024-27351 as a minor issue for buster. - - - - - 73dedb18 by Ola Lundqvist at 2024-03-06T21:51:53+01:00 Added ruby-rack to dla-needed.

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked three CVEs for suricata as minor issues for buster following bullseye.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: caf78ea3 by Ola Lundqvist at 2024-03-06T21:37:13+01:00 Marked three CVEs for suricata as minor issues for buster following bullseye. - - - - - 233c5ee0 by Ola Lundqvist at 2024-03-06T21:37:14+01:00 Ma

[Git][security-tracker-team/security-tracker][master] Treat CVE-2024-25269 as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c1ad0d65 by Ola Lundqvist at 2024-03-06T21:29:21+01:00 Treat CVE-2024-25269 as a minor issue for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Treat CVE-2023-5685 as minor issue in buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d6e6b82e by Ola Lundqvist at 2024-03-06T21:24:02+01:00 Treat CVE-2023-5685 as minor issue in buster. - - - - - 1 changed file: - data/CVE/list Changes: = data

[Git][security-tracker-team/security-tracker][master] Added thunderbird to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4e85cf6c by Ola Lundqvist at 2024-03-06T21:19:02+01:00 Added thunderbird to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-ne

[Git][security-tracker-team/security-tracker][master] Added wordpress to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8446e86f by Ola Lundqvist at 2024-03-06T21:17:01+01:00 Added wordpress to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-need

[Git][security-tracker-team/security-tracker][master] 2 commits: Added iwd to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d22028c4 by Ola Lundqvist at 2024-03-06T21:03:48+01:00 Added iwd to dla-needed. - - - - - ccb877a4 by Ola Lundqvist at 2024-03-06T21:09:22+01:00 Added pdns-recursor to dla-needed. - - - - - 1 chang

[Git][security-tracker-team/security-tracker][master] Added shim to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e44b0e5e by Ola Lundqvist at 2024-03-06T21:00:57+01:00 Added shim to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.tx

[Git][security-tracker-team/security-tracker][master] CVE-2024-27507 concluded as a minor issue for buster.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 560f20fe by Ola Lundqvist at 2024-03-06T20:48:52+01:00 CVE-2024-27507 concluded as a minor issue for buster. - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] Marked CVEs for golang-1.11 as postponed with limited support.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ba3d969f by Ola Lundqvist at 2024-03-06T20:45:06+01:00 Marked CVEs for golang-1.11 as postponed with limited support. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] 3 commits: Added fontforge to dla-needed.

2024-03-06 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 42024d4f by Ola Lundqvist at 2024-03-06T20:42:23+01:00 Added fontforge to dla-needed. Arbitrary command execution is tricky even if this is an "editor" application and you should not load untrust

[Git][security-tracker-team/security-tracker][master] Added libapache2-mod-auth-openidc to dla-needed.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: cebf4215 by Ola Lundqvist at 2024-03-05T00:19:10+01:00 Added libapache2-mod-auth-openidc to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: =

[Git][security-tracker-team/security-tracker][master] Concluded that CVE-2024-25768 is a minor issue.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 4da981b2 by Ola Lundqvist at 2024-03-05T00:08:30+01:00 Concluded that CVE-2024-25768 is a minor issue. The issue occurs if a null list buffer is provided but a non-zero length of that buffer is pr

[Git][security-tracker-team/security-tracker][master] Marked two CVEs for wireshark as no-dsa for buster following bookworm and bullseye.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a623b0d4 by Ola Lundqvist at 2024-03-04T23:48:05+01:00 Marked two CVEs for wireshark as no-dsa for buster following bookworm and bullseye. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-6917 as no-dsa for buster following bookworm and bullseye.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: aa87e4a0 by Ola Lundqvist at 2024-03-04T23:46:11+01:00 Marked CVE-2023-6917 as no-dsa for buster following bookworm and bullseye. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Marked CVE-2020-36774 as no-dsa for buster.

2024-03-04 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a684666c by Ola Lundqvist at 2024-03-04T23:40:54+01:00 Marked CVE-2020-36774 as no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes: = data/C

[Git][security-tracker-team/security-tracker][master] Postponed CVEs for buster just as for bullseye.

2023-11-24 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a7dd83b1 by Ola Lundqvist at 2023-11-24T20:12:29+00:00 Postponed CVEs for buster just as for bullseye. - - - - - 1 changed file: - data/CVE/list Changes: = da

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-49208 as not affected for buster.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f4a918a4 by Ola Lundqvist at 2023-11-23T21:50:05+00:00 Marked CVE-2023-49208 as not affected for buster. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Added tinymce to dla-needed.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 8905071c by Ola Lundqvist at 2023-11-23T21:44:06+00:00 Added tinymce to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-40030 as no-dsa for buster following bullseye.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: ffc07270 by Ola Lundqvist at 2023-11-23T21:41:14+00:00 Marked CVE-2023-40030 as no-dsa for buster following bullseye. - - - - - 1 changed file: - data/CVE/list Changes: =

[Git][security-tracker-team/security-tracker][master] Marked CVE-2023-20246 as not affected for buster.

2023-11-23 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 6e7dc086 by Ola Lundqvist at 2023-11-23T21:29:24+00:00 Marked CVE-2023-20246 as not affected for buster. It should be marked as not affected for all versions since the vulnerability is only in sno

[Git][security-tracker-team/security-tracker][master] Added notes for httpie CVE-2023-48052.

2023-11-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 916163b2 by Ola Lundqvist at 2023-11-22T23:27:47+00:00 Added notes for httpie CVE-2023-48052. - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/li

[Git][security-tracker-team/security-tracker][master] 8 commits: Added firefox-esr to dla-needed. Already fixed in bullseye.

2023-11-22 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 68cf3b09 by Ola Lundqvist at 2023-11-22T22:32:12+00:00 Added firefox-esr to dla-needed. Already fixed in bullseye. - - - - - bcdde0f6 by Ola Lundqvist at 2023-11-22T22:32:12+00:00 Added thunderbird to

[Git][security-tracker-team/security-tracker][master] Added strongswan to be fixed for LTS.

2023-11-21 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: deb0f964 by Ola Lundqvist at 2023-11-21T10:50:56+00:00 Added strongswan to be fixed for LTS. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/d

[Git][security-tracker-team/security-tracker][master] Marked composer CVE-2023-43655 as minor issue.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: c196dbfe by Ola Lundqvist at 2023-10-01T19:52:12+00:00 Marked composer CVE-2023-43655 as minor issue. This is only a vulnerability on an improper configuration. - - - - - 1 changed file: - data/CV

[Git][security-tracker-team/security-tracker][master] Marked golang-golang-x-image CVEs as no-dsa for buster.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 76ca393a by Ola Lundqvist at 2023-10-01T19:46:41+00:00 Marked golang-golang-x-image CVEs as no-dsa for buster. it is a DoS vulnerability, rather minor and the package has limited support. - - - - -

[Git][security-tracker-team/security-tracker][master] 3 commits: Buster no-dsa for gcc-7 and gcc-8 following bullseye decision.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: aee2a5c4 by Ola Lundqvist at 2023-10-01T19:31:36+00:00 Buster no-dsa for gcc-7 and gcc-8 following bullseye decision. - - - - - 4a2dfb1a by Ola Lundqvist at 2023-10-01T19:38:24+00:00 Marked CVE-2023-3

[Git][security-tracker-team/security-tracker][master] 2 commits: Added a note about the work needed after upgrade of borgbackup.

2023-10-01 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 345ff70f by Ola Lundqvist at 2023-10-01T19:18:20+00:00 Added a note about the work needed after upgrade of borgbackup. - - - - - 66bd8cb9 by Ola Lundqvist at 2023-10-01T19:28:31+00:00 Marked a few CVE

[Git][security-tracker-team/security-tracker][master] Marked a few CVEs as end-of-life for buster.

2023-09-29 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 56490f6a by Ola Lundqvist at 2023-09-29T18:46:49+00:00 Marked a few CVEs as end-of-life for buster. - - - - - 1 changed file: - data/CVE/list Changes: = data/

[Git][security-tracker-team/security-tracker][master] Added gst-plugins-bad1.0 to dla-needed following decision for bookworm.

2023-09-28 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 55bc8f67 by Ola Lundqvist at 2023-09-28T21:12:17+00:00 Added gst-plugins-bad1.0 to dla-needed following decision for bookworm. - - - - - 1 changed file: - data/dla-needed.txt Changes: ==

[Git][security-tracker-team/security-tracker][master] Added exim4 to dla-needed following decision for bookworm.

2023-09-28 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: e8e75c4c by Ola Lundqvist at 2023-09-28T20:54:35+00:00 Added exim4 to dla-needed following decision for bookworm. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] Added python-reportlab to dla-needed since it has been fixed in all later...

2023-09-26 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: a978d068 by Ola Lundqvist at 2023-09-26T14:24:52+00:00 Added python-reportlab to dla-needed since it has been fixed in all later releases and seems to be important. - - - - - 1 changed file: - dat

[Git][security-tracker-team/security-tracker][master] 2 commits: Added trafficserver to dla-needed with a note about low prio due to few users.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: abd42ec2 by Ola Lundqvist at 2023-06-19T07:17:24+02:00 Added trafficserver to dla-needed with a note about low prio due to few users. - - - - - c6fd8a48 by Ola Lundqvist at 2023-06-19T07:17:24+02:00 M

[Git][security-tracker-team/security-tracker][master] Added php-dompdf to dla-needed with a note about low prio.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 15d8fb71 by Ola Lundqvist at 2023-06-18T22:25:11+02:00 Added php-dompdf to dla-needed with a note about low prio. - - - - - 1 changed file: - data/dla-needed.txt Changes: ===

[Git][security-tracker-team/security-tracker][master] 3 commits: Added sabnzbdplus to dla-needed.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 61a98063 by Ola Lundqvist at 2023-06-18T22:06:32+02:00 Added sabnzbdplus to dla-needed. - - - - - 75065857 by Ola Lundqvist at 2023-06-18T22:10:18+02:00 Added ruby-doorkeeper to dla-needed. - - - - -

[Git][security-tracker-team/security-tracker][master] 4 commits: Marked golang-1.11 CVEs as no-dsa for buster following bullseye.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 2bc45273 by Ola Lundqvist at 2023-06-18T21:46:34+02:00 Marked golang-1.11 CVEs as no-dsa for buster following bullseye. - - - - - 22287c80 by Ola Lundqvist at 2023-06-18T21:49:11+02:00 Marked golang-1

[Git][security-tracker-team/security-tracker][master] Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 00d9ac0a by Ola Lundqvist at 2023-06-18T21:41:44+02:00 Marked golang-golang-x-net-dev CVE-2022-41717 and CVE-2022-27664 as postponed. Following the decision for golang-1.11 package. - - - - - 1 cha

[Git][security-tracker-team/security-tracker][master] 5 commits: Marked gpac CVE-2023-3291 end-of-life.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 08297450 by Ola Lundqvist at 2023-06-18T21:34:53+02:00 Marked gpac CVE-2023-3291 end-of-life. - - - - - f19d2d30 by Ola Lundqvist at 2023-06-18T21:34:54+02:00 Marked librabbitmq CVE-2023-35789 no-dsa

[Git][security-tracker-team/security-tracker][master] Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: f871edfc by Ola Lundqvist at 2023-06-18T10:30:15+02:00 Marked qtsvg-opensource-src CVE-2023-32573 as no-dsa for buster. - - - - - 1 changed file: - data/CVE/list Changes: ===

[Git][security-tracker-team/security-tracker][master] 2 commits: Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm.

2023-06-18 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 1497f27f by Ola Lundqvist at 2023-06-18T10:26:21+02:00 Marked qtbase-opensource-src CVEs as no-dsa following decision for bullseye or bookworm. CVE-2023-34410 CVE-2023-33285 and CVE-2023-32763 - - -

[Git][security-tracker-team/security-tracker][master] 3 commits: Marked nagvis CVE-2022-46945 as no-dsa following bullseye decision.

2023-06-16 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 618740db by Ola Lundqvist at 2023-06-16T23:42:14+02:00 Marked nagvis CVE-2022-46945 as no-dsa following bullseye decision. - - - - - 3682307e by Ola Lundqvist at 2023-06-16T23:42:16+02:00 Marked wires

[Git][security-tracker-team/security-tracker][master] Added libx11 to dla-needed.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 944fcbc4 by Ola Lundqvist at 2023-06-15T22:45:06+02:00 Added libx11 to dla-needed. - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.

[Git][security-tracker-team/security-tracker][master] Marked golang-gihub-gib-gonic-gin CVE-2023-29401 as no-dsa (minor issue) for buster.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: d2ec5a05 by Ola Lundqvist at 2023-06-15T22:36:50+02:00 Marked golang-gihub-gib-gonic-gin CVE-2023-29401 as no-dsa (minor issue) for buster. - - - - - 1 changed file: - data/CVE/list Changes: ==

[Git][security-tracker-team/security-tracker][master] 3 commits: Added python-mechanize to dla-needed.

2023-06-15 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: 01c88224 by Ola Lundqvist at 2023-06-15T22:23:45+02:00 Added python-mechanize to dla-needed. - - - - - 1b93beb5 by Ola Lundqvist at 2023-06-15T22:23:46+02:00 Marked rust-h2 CVE-2023-26964 as no-dsa (m

[Git][security-tracker-team/security-tracker][master] Marked yajl CVE-2023-33460 as postponed.

2023-06-14 Thread Ola Lundqvist (@opal)
Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker Commits: defddfbb by Ola Lundqvist at 2023-06-14T23:19:29+02:00 Marked yajl CVE-2023-33460 as postponed. - - - - - 1 changed file: - data/CVE/list Changes: = data/CVE/

  1   2   3   >