May 2020 Archives by date
Starting: Fri May 1 06:18:59 BST 2020
Ending: Sun May 31 22:12:14 BST 2020
Messages: 730
- [Git][security-tracker-team/security-tracker][master] autocomplete=off is browser dependent.
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2198-1 for otrs2
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10728/NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2019-10169 as NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Cleanup trailing whitespaces
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-18823/condor
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track proposed fixes for gosa for CVE-2019-14466 via {stretch,buster}-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Adjust accepted python-oslo.utils version for buster-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11020/ruby-faye
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add basic Unicode support to the web framework
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] ATS DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Could not find anything that change the Security Team decision in regards to...
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] 2 commits: Triage result for jquery. CVE-2020-11023 and CVE-2020-11023 are fixed with the...
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] 4 commits: Reference followup commit needed for CVE-2020-11651
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add back note on regression caused by typo and reference known issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for wordpress issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-11020
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Wordpress triage result. Some issues not affecting jessie. Found a few issues...
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] EOL entries for vlc in jessie.
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] Claim wordpress
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Adding apache2 to DLA needed as a response of bug #60251.
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] Claim apache2
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Following Debian Security decision marking CVE-2020-11721 for libsixel with no-dsa for jessie.
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] 3 commits: Reference branch for commit
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reference master commit for CVE-2020-11029 and add tagged version to help isolate fix
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add upstream commit for CVE-2020-11028/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add changeset for CVE-2020-11030 as svn is the master respository for wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track wordpress fixes via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Isolate commit for CVE-2020-11029/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add SVN changeset for CVE-2020-11028/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Isolate commit for CVE-2020-11027/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Isolate commit for CVE-2020-11026/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add upstream changeset and isolated commit for CVE-2020-11025/wordpress
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add and claim wordpress
Sebastien Delafond
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla-needed.txt: Add various dates and attributions to notes.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Add separator for list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Fix for CVE-2019-11236/python-urllib3 moved to unstable with 1.25.6-4
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixing commit for CVE-2019-11324
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim salt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2019-11324/python-urllib3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DLA: update notes regarding libntlm
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Update xcftools entry
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Maintainer proposed to prepare updates for squid
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2199-1 for openldap
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-12105/openconnect
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-12105/openconnect as not-affected for Jessie
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for openexr issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-11888/python-markdown2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12430/libvirt
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-1774/otrs2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-9488/apache-log4j2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12114/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information for CVE-2020-12114/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 3 commits: Decided that condor is worth fixing even though it is not that popular.
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] LTS: claim percona-xtrabackup and condor in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] CVE-2019-10206/ansible: jessie not-affected
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] CVE-2019-14904,CVE-2019-14905/ansible: fix affected versions
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] LTS: unclaim condor, update notes
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] LTS: annotate CVE-2020-10997/percona-xtrabackup as not affecting jessie
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-10997
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2200-1 for mailman
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] mailman removed from unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add for evaluation apache-log4j1.2 to dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DLA: fix years in notes
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] 3 commits: Mark CVE-2020-12268/jbig2dec as no-dsa for Jessie
Dylan Aïssi
- [Git][security-tracker-team/security-tracker][master] dla-needed: update note
Dylan Aïssi
- [Git][security-tracker-team/security-tracker][master] pspp was removed from unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reference regression reports for CVE-2020-11651/salt
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add and tentatively take salt from dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: add another commit to really fix CVE-2016-10711
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] tomcat8 DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: Gpac is not affected by CVE-2020-11558 in jessie.
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] 2 commits: dla: still ongoing
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-1165{1,2}/salt
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add newly assigned CVEs for roundcube issues
Sebastien Delafond
- [Git][security-tracker-team/security-tracker][master] jquery issues also affect node-jquery
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim ntp.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity
Holger Levsen
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim sqlite3.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] dla: reclaim ansible, status update
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] CVE-2020-1774/otrs2 fixed via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reference report for CVE-2020-12114
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10717/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-10717/qemu: Add information on introducing commit
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-10717/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2018-7574
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12639/phplist
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] It looks like the stretch bluez update can be applied as is. Should be...
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] Only one issue CVE-2020-11647 marked for fixing for wireshark. However the...
Ola Lundqvist
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10729/ansible
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12652/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12653/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add tag information for CVE-2020-12653
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12655/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12656/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12657/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12659/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla-needed.txt: Re-add the historical notes for ansible dropped in 45efdd996b,...
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Add four more CVEs adressed in 10.4 point release and 4.19.118-1 update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] node-jquery fixed
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] dla-needed.txt: Add some brief remarks on CVE-2020-11724 in nginx.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2201-1 for ntp
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Add note for mumble in dla-needed.txt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] 2 commits: dla: ansible: don't clutter the package status with obsolete notes
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Reserve DSA-4674-1 for roundcube (CVE-2020-12625, CVE-2020-12626)
Sebastien Delafond
- [Git][security-tracker-team/security-tracker][master] CVE-2020-10729/ansible: jessie not-affected
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2202-1 for ansible
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Remove one no-dsa tagged entry which got an update in DLA 2202-1
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DLA: Claim xfctools (trying to write a patch)
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add firefox issues from mfsa2020-16
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Cleanup four rejected CVEs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add firefox-esr issues from mfsa2020-17
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add firefox-esr to dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2203-1 for sqlite3
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for graphicsmagick update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] take firefox, squid, teeworlds
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new roundcube issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new chromium issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] LTS: add and claim firefox-esr
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-1264{0,1}/roundcube
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixes for firefox-esr for mfsa2020-17
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixes for firefox for mfsa2020-16
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for salt update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10732/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA-4677-1 for wordpress
Sebastien Delafond
- [Git][security-tracker-team/security-tracker][master] Slightly detangle CVE list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new thunderbird issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12672/graphicsmagick
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] thunderbird fixed
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage ansible for jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] dla: varnish: update status
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] LTS: claim thunderbird in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-1264{0,1}/roundcube as unimporant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new linux issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new telegram issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new ruby-doorkeeper issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Sync CVE-2020-0110 with kernel-sec
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove two unspecific entries (only addition of the CVE plus general releases lists)
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add new keystone issue, #959900
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12108/mailman issue
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-10187/ruby-doorkeeper
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] firefox, keystone, tomcat9 DSAs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add tracking for keystone fix via DSA 4679-1
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10693
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track assigned CVEs for keystone
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] All four new CVEs covered by DSA 4679-1 update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage keystone for jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage mailman for jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] webkit2gtk DSA-4681-1
Alberto Garcia
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2204-1 for mailman
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Correct CVE reference for DLA-2204-1.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Add DSA reservation for salt update (followup for stretch to DSA 4676-1)
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12448/gitlab
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add new glpi issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10933/ruby
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update notes for ansible
Brian May
- [Git][security-tracker-team/security-tracker][master] Correct typo in dla-needed.txt.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Mark keystone as being unsupported in jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] CVE-2020-10933/ruby2.7 fixed with the newest upstream version 2.7.1
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark ruby2.5 as removed
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12672/graphicsmagick
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add four new FreeRDP issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11526/FreeRDP
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11047/FreeRDP
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11049/FreeRDP
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11048/FreeRDP
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFU for Keycloak
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10719/undertow
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-19699/centreon-web
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Fix pending version for haproxy, the update is pending but will not be in 10.4
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Put updates with no update for buster 10.4 to end of list to ease review
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2205-1 for firefox-esr
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Associate #959900 as well with CVE-2020-1269{0,1,2}/keystone
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] thunderbird, squid DSAs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12740/tcpreplay
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixed version for keystone issues in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 5 commits: libperlspeak-perl removed from buster in 10.4
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10737/oddjob
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-10737/oddjob
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Mark CVE-2020-12690, CVE-2020-12691 & CVE-2020-12690 as unspported in jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2206-1 for thunderbird
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-20794/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] ansible fixed in sid
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12761/imlib2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-12761/imlib2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-9488 as <no-dsa> for jessie
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Remove apache-log4j2 from dla-needed.txt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12771/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12770/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12769/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12768/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-20795/iproute2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2019-20795 as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12767/libexif
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Triage freerdp for jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Triage CVE-2020-12741 in tcpreplay in jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Claim freerdp
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add Debian bug reference for CVE-2020-10704/samba
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-11713/wolfssl
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12761/imlib2
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Claim imlib2 in dla-needed.txt
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12767/libexif
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark libexif issue as no-dsa for buster and stretch
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2207-1 for libntlm
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-9489/tika as no-dsa
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2208-1 for wordpress
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Add note for apache2
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Drop tika from dla-needed
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Remove listing of CVE-2020-11025 in DLA 2208-1
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove no-dsa for CVE-2019-17455 (jessie)
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Revert "Remove no-dsa for CVE-2019-17455 (jessie)"
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entry which got update in DLA 2207-1/libntlm
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2019-19221/libarchive fixed with 3.4.2-1 upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla: still ongoing
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] Claim mumble, again
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] update note
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add attributes to recent notes.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] one systemd issue unimportant
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new json-c issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity
Holger Levsen
- [Git][security-tracker-team/security-tracker][master] new qutebrowser issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Fix typo to actually mark CVE-2020-11025/wordpress as not-affected in Jessie
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-9489/tika as ignored instead of no-dsa
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] 3 commits: Add new exim4 issue (AUTH bypass in SPA authentication method)
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Remove imlib2 from dla-needed.txt
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] Remove no-dsa flag from Tomcat 8 / Jessie in CVE list.
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] Claim imagemagick in dla-needed.txt
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] new kio-extras issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add tracking for CVE-2018-1285/log4net
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12755/kio-extras
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: claim libdatetime-timezone-perl and tzdata in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12762/json-c
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2020-11713/wolfssl
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some more NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1186{3,4,5,6}/libemf
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fix via experimental for openexr issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] php-horde-data got reintroduced in Debian
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-12761,imlib2: Fixed in unstable
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] NFU
Henri Salo
- [Git][security-tracker-team/security-tracker][master] new libreswan issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track proposed update for libyang via buster-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2020-3810/apt
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new linux issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] dla: varnish: update status
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Add information on CVE-2020-1763/libreswan
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1763/libreswan
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2019-19847/libspiro
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10741/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12826/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 3 commits: Add apt to dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update dla-needed.txt notes for bluez
Brian May
- [Git][security-tracker-team/security-tracker][master] LTS: add and claim exim4 in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Revert "LTS: add and claim exim4 in dla-needed.txt"
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1758 as NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process two more NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new libcroco issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Clear notes on CVE-2020-10741
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12823/openconnect
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11058/freerdp
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1106{0,2}/glpi
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] qemu fixed in unstable
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] CVE-2019-20637/varnish: test case is now published
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12825/libcroco
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-12656/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for libreswan update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2019-20637/varnish: one vector not-affected for jessie
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Add reference to commit for CVE-2020-3810
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-3810/apt fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for apt update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Clarlify temporary description for CVE-2020-3810
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add exim4, claimed by Roberto on request via IRC.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add apt and ping maintainers.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add graphicsmagick.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add json-c.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim json-c
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/CVE/list: Tag CVE-2020-12825 in libcroco/jessie as <ignored>.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add libexif and claim it.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: re-claim nginx
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add log4net.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add openconnect.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add tomcat8.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add cups.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] LTS: claim cups
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12831
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10742/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] libvirt fixed
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fix for CVE-2020-12430/libvirt
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Claim openconnect
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Claim apt
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim log4net.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] LTS: claim graphicsmagick in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] LTS: unclaim and update notes on libdatetime-timezone-perl tzdata
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1945/ant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1941/activemq
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2018-8006/activemq
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new clamav issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12823/openconnect
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Proces some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2210-1 for apt
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2211-1 for openconnect
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Revert "Reserve DLA-2211-1 for openconnect"
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Handover openconnect to Mika as requested over IRC
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] new libspring-security-2.0-java, glpi issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-1945/ant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-0093 (possibly affecting libexif upstream)
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new ansible issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new ruby-actionpack-page-caching issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new QT issue (n/a)
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2019-20637/varnish: jessie not-affected
Sylvain Beucler
- [Git][security-tracker-team/security-tracker][master] Add notes for CVE-2020-10744
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-8159/ruby-actionpack-page-caching
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2211-1 for log4net
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Correct version number for DLA-2211-1 prior to upload.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-12823/openconnect via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12888/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update notes for CVE-2020-12762/json-c
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update notes for CVE-2020-12762/json-c
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add new FreeRDP issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for apache-log4j1.2 update
Salvatore Bonaccorso
- Processing 9a29b8b0666d29c2c23598c7d3ca4cf02ab86dae failed
security tracker role
- [Git][security-tracker-team/security-tracker][master] podman entered the archive, move from itp status to unfixed for further checks
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] Correct source package name: podman -> libpod
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] Add information for CVE-2020-1726/libpod
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update status for three older libpod CVES
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-14900
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Associate exim4 for DSA
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2212-1 for openconnect
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Add three CVEs fixed in 4.19.118-1 to buster in 10.4
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DSA-4687-1 exim4
Florian Weimer
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-0093/libexif
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2020-12767/libexif
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-3341 and CVE-2020-3327 via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2213-1 for exim4
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] LTS: claim tomcat8 in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add note on DLA reservation
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-8608 and CVE-2020-1983
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add tracking of fixed version for qemu and slirp4netns switching to use system libslirp library
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process two NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: claim bluez in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla: work is ongoing
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] dla-needed.txt: Ongoing work on squid3 to incorporate latest CVE.
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2214-1 for libexif
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entries which got an update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DLA: add note about xcftools
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-1945/ant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] update salt note
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2019-6477/bind9 for stretch
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity
Holger Levsen
- [Git][security-tracker-team/security-tracker][master] Drop libsixel as CVE-2020-11721 is no-dsa
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2020-1945 as no-dsa for Jessie
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Claim clamav
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] new prboom issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new yaws issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new postgres issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: LTS: unclaim tomcat8 (the work was already done by apo, just needs an upload and DLA publish)
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] new dpdk issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] dpdk DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add three new dovecot issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark dovecot for older suites as not-affected
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-5407/libspring-security-2.0-java does not affect jessie
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2020-5408/libspring-security-2.0-java does not affect jessie
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for dovecot issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for dpdk issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13143/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: Update notes for bluez
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10736/ceph
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] Add commit references for CVE-2020-10736
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2018-10756/transmission
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new libreoffice issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 3 commits: mark CVE-2020-12872 as no-dsa for Jessie
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-861{6,7}/bind9
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] add bind9
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Add two unbound issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12667/knot-resolver
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new pdns-recursor issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add new pdns-recursor issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove no-dsa tagged entry for CVE-2019-6477, will be updated with next DSA
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add bind9 and pdns-recursor to dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Assign pdns-recursor to jmm
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-381{1,2}/netqmail
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] openconnect unimportant
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-381{1,2}/netqmail
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update severity for CVE-2020-12768
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for bind9 update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-1266{2,3}/unbound fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] pdns-recursor issues fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12667/knot-resolver
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2215-1 for clamav
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10738/moodle
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10135/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] picolibc issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] fix two non issues into mere NOTEs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13225/phpipam
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] bluetooth protocol issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13164/wireshark
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: data/CVE/list: add commits that mitigate NXMSattack in knot-resolver
Santiago R.R.
- [Git][security-tracker-team/security-tracker][master] wireshark fixed in sid and postponed for stable
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] buster/stretch triage
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12399/nss
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for dovecot update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add netqmail association with CVE-2005-151{3,4,5}
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2020-12440
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-4461
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2020-13246/gitea
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1323{0,1}/cacti
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13226 (NFU)
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add netqmail to dsa-needed list
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add new chromium CVEs from 83.0.4103.61 release
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-9484/tomcat* issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-8161/ruby-rack
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1727 as NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-11048/php*
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Unclaim freerdp
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Update note for condor in jessie LTS.
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] Track fixed versions for netqmail via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] one chromium issue n/a
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Move not-affected entry to CVE-2020-6477/chromium
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1955/couchdb
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-9484/tomcat9
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update CVE-2020-10736/ceph
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update note for netqmail
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-0093/libexif fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-9484/tomcat9 via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: update notes on tomcat8
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1311{2,3,4}/libexif issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track proposed update for libexif via buster-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixes for libexif update via stretch-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] pdns-recursor DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] fix typo in DSA list
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] LTS: update notes on bluez
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12693/slurm-llnl
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-8161/ruby-rack via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-12693 as no-dsa for buster and stretch
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13253/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2019-6292/yaml-cpp
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 7 commits: mark CVE-2020-13164 as postponed for Jessie
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Claim tomcat and netqmail
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Three asterisk issues fixed via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: add unbound
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2216-1 for ruby-rack
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] DLA: claim unbound
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2019-9211/pspp via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-13253/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process two NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add three new FreeRDP issues (CVE-2020-1339{6,7,8})
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13252/centreon-web, itp'ed
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2018-21234/jodd
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2018-21234/jodd
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update notes for CVE-2020-8161/ruby-rack
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2019-16782/ruby-rack as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-1763/libreswan via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-1286{1,2,3,4,5,6,7}/sane-backends
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla: Hand over tomcat7 to Chris as requested
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Mark 5.6.14-1 as released in unstable and update CVE information
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2217-1 for tomcat7
Chris Lamb
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-13152 as upimportant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DSA number for netqmail update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update TODO for CVE-2018-18405
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] prboom bug
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12693/slurm-llnl
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug references for CVE-2020-1311{2,3,4}/libexif
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for symfony issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11656/sqlite3 fixed version in unstable
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-12872
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-1726/libpod
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: add sane-backends
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2218-1 for transmission
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2219-1 for feh
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2017-7875 has been fixed
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12829/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add researcher report on CVE-2018-10756/transmission
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2018-10756/transmission
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-6096/glibc
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13430/grafana
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla: still ongoing
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] semi-automatic unclaim after 2 weeks of inactivity
Holger Levsen
- [Git][security-tracker-team/security-tracker][master] Re-claim apache2
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Add fix for CVE-2019-18823
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Add note for condor
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Reference upstream commits for the three ticket for CVE-2019-18823
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-10187/ruby-doorkeeper via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10936/sympa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new mariadb issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: Mark mariadb-10.1 as removed
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add sqlite3 and sympa
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Claim sympa
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] buster/stretch triage
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Claim sqlite3
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add commits for CVE-2020-13435/sqlite3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-1343{4,5}/sqlite3 fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-8866/php-horde-form as unfixed
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-13435/sqlite3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 2 commits: Sync CVE-2020-13435 affected version with upper suite
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add four new MariaDB 10.3 issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add three new MariaDB 10.1 issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] mark latest libreoffice as ignored after checking with maintainer
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add notes for sympa
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2221-1 for sqlite3
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim cacti
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10751/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version via unstable for CVE-2020-10751/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] 2 commits: new puma issues
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] sane-backends fixed in experimental
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Mark jquery as removed, got replaced with src:node-jquery
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Associate CVE-2018-18405 with jquery but mark it as unimporant
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] embedded-code-copies: add libdvdread and libdvdnav
Sebastian Ramacher
- [Git][security-tracker-team/security-tracker][master] php-horde-trean re-introduced to Debian, re-mark it as unfixed
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] drupal7 DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] unbound DSA
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-8151/rails
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-8034/php-horde-gollem
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-8034/php-horde-gollem
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13614/axel
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] unbound eol for stretch
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] new vlc issue (already fixed in stable/oldstable)
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Update fixed information on CVE-2019-19721 via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add reference to launchpad bug for qemu for CVE-2020-13253
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove todo item for CVE-2020-10933
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-8161/ruby-rack as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-20806/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Five xen issues fixed via unstable upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add note that Santiago is working on update for knot-resolver
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13632/sqlite3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13631/sqlite3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13630/sqlite3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] buster/stretch triage
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add more references for CVE-2020-10936
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixed version for various CVEs with unstable upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Three symfony issues fixed in unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark freerdp2/freerdp issues as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] SSL/TLS implementation with openSSL is from version 2.10. Hence
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] CVE-2019-19721 vlc eol
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13361/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13362/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update salt note in dla-needed.txt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] new python-httplib2 issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add reference to fixing commit for CVE-2018-17076
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-10742
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2222-1 for libexif
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/CVE/list: Drop <no-dsa> tags for CVE-2020-1311{2, 3, 4}/jessie. A fix has been uploaded.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim freerdp
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add php-horde-gollem and claim it (with new maintainer's hat on)
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Add fixed version for libexif issues via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove tomcat8 from dla-needed.txt, add CVE-2020-9484 to DLA/list. CVE is fixed
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] new ntp issue
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Cleanup notes for CVE-2018-8956
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-8035/php-horde
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-0110/linux
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Sync status for some linux CVEs with kernel-sec triage
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add upstream fixing commit for CVE-2020-12399/nss
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-12399/nss
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2019-20637/varnish as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-20807/vim
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-13645/glib-networking
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-13645/glib-networking
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-13662 assigned for SA-CORE-2020-0003/drupal
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla: take
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2018-10756/transmission via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-1726/libpod via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Remove doubled space between CVE id and temporary description
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process one NFU
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] vim no-dsa
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Add note on CVE-2020-13645/glib-networking with regard of src:balsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2019-20808/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update affected version for qemu issue
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for qemu issue
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-10754/network-manager
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2223-1 for salt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add note for cacti in dla-needed.txt
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add vim and drupal7
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] LTS: claim vim in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] php-horde shows up frequently, CVE-2020-8035 can be fixed in future
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Process some new freerdp2 issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add new freerdp2 issues
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: triage CVE-2019-20807/vim for jessie as no-dsa, minor issue
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] LTS: unclaim graphicsmagick in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add and claim sqlite3, python-httplib2
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-9794/sqlite3
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark for now CVE-2020-9794 as undetermined as there is no ifnormation to trackle
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-7656/jquery
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-11082/ruby-kaminari
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-11082/ruby-kaminari
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for mariadb-10.3
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2016-4804 will be fixed
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2016-10198 will be fixed
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2017-5846 will be fixed
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Add CVE-2020-12672/graphicsmagick fixed version in unstable
László Böszörményi
- [Git][security-tracker-team/security-tracker][master] Mark gst-plugins-good0.10 as removed from unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Mark gst-plugins-ugly0.10 as removed from unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2227-1 for bind9
Thorsten Alteholz
- [Git][security-tracker-team/security-tracker][master] Update status for CVE-2020-13249
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-13362/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-13361/qemu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2020-12399/nss via unstable
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-10684/ansible fixed in 2.9.7
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-10685/ansible fixed with 2.9.7+dfsg-1 upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Update information on CVE-2020-1735/ansible
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] CVE-2020-1746/ansible fixed in unstable via 2.9.7 upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] DLA: update notes for xcftools
Anton Gladky
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2228-1 for json-c
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Add notes for packages
Utkarsh Gupta
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-8034/php-horde-gollem as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2229-1 for php-horde-gollem
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2228-2 for json-c
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] gollem fixed in sid
Moritz Muehlenhoff
- [Git][security-tracker-team/security-tracker][master] Mark CVE-2020-11082 <no-dsa> for jessie
Abhijith PA
- [Git][security-tracker-team/security-tracker][master] Several nethack issues fixed via unstable upload
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] Track proposed update for php-horde-gollem via {buster,stretch}-pu
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla-needed: update notes
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] 3 commits: Mark ssvnc issues as no-dsa
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] sane-backends: The epsonds backend is not in jessie
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] Add Debian bug reference for CVE-2020-861{6,7}/bind9
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] LTS: claim graphicsmagick in dla-needed.txt
Roberto C. Sánchez
- [Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
- [Git][security-tracker-team/security-tracker][master] dla-needed.txt: Final version for Stretch and Jessie this week but will ask for
Markus Koschany
- [Git][security-tracker-team/security-tracker][master] 2 commits: data/CVE/list: Drop [postponed] tag from CVE-2020-8035/php-horde.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] dla: update and give back condor
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] data/CVE/list: Mark freerdp2/CVE-2020-110{17, 18} as no-dsa issues as discussed with Salvatore.
Mike Gabriel
- [Git][security-tracker-team/security-tracker][master] Reserve DLA-2231-1 for sane-backends
Adrian Bunk
- [Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: Add note to freerdp
Mike Gabriel
Last message date:
Sun May 31 22:12:14 BST 2020
Archived on: Sun May 31 22:12:17 BST 2020
This archive was generated by
Pipermail 0.09 (Mailman edition).