[Secure-testing-commits] r731 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Sun, 03 Apr 2005 14:14:08 +0000


Author: jmm-guest
Date: 2005-04-03 14:14:05 +0000 (Sun, 03 Apr 2005)
New Revision: 731

Modified:
   sarge-checks/CAN/list
Log:
limewire has been removed.
ISO9660 flaws/2.4 has been filed.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-04-03 10:37:52 UTC (rev 730)
+++ sarge-checks/CAN/list	2005-04-03 14:14:05 UTC (rev 731)
@@ -402,7 +402,7 @@
 	NOTE: not-for-us (Solaris)
 CAN-2005-0815 (Multiple "range checking flaws" in the ISO9660 filesystem handler in ...)
 	- kernel-source-2.6.8 2.6.8-16
-	NOTE: Seems to affect 2.4 as well, needs clarification
+	- kernel-source-2.4.27 (unfixed; bug #302864)
 CAN-2005-0814 (Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 ...)
 	- lsh-utils 2.0.1-1
 CAN-2005-0813 (Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and ...)
@@ -565,8 +565,7 @@
 CAN-2005-0789 (Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 ...)
 	NOTE: not-for-us (not part of Woody, has been removed from sarge/sid)	
 CAN-2005-0788 (LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary ...)
-	- limewire (unfixed; bug #300634)
-	NOTE: Seems like a candidate for removal from Sarge/sid
+	NOTE: not-for-us (Limewire has been removed from Sarge and sid, was never part of stable)
 CAN-2005-0787 (Wine 20050211 and earlier creates temp files with world readable ...)
 	- wine 0.0.20050310-1.1
 CAN-2005-0769 (Multiple buffer overflows in OpenSLP before 1.1.5 allow remote ...)