[Secure-testing-commits] r87 - sarge-checks/CAN

Paul Dwerryhouse pdwerryh-guest@haydn.debian.org
Sat, 06 Nov 2004 05:49:50 -0700


Author: pdwerryh-guest
Date: 2004-11-06 05:49:43 -0700 (Sat, 06 Nov 2004)
New Revision: 87

Modified:
   sarge-checks/CAN/list
Log:
handled minor openslp issue.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2004-11-06 12:17:00 UTC (rev 86)
+++ sarge-checks/CAN/list	2004-11-06 12:49:43 UTC (rev 87)
@@ -2388,8 +2388,10 @@
 CAN-2003-0876
 	NOTE: not-for-us (Apple)
 CAN-2003-0875
-	TODO: slpd.all_init not used in Debian
-	TODO: but source package still distributes it.
+	NOTE: openslp: slpd.all_init symlink vuln
+	NOTE: this file is not used in Debian, so it's not a problem for us.
+	NOTE: source package still distributes the file, however.
+	TODO: submitted to BTS.
 CAN-2003-0874
 	NOTE: not-for-us (Deskpro)
 CAN-2003-0873