[Secure-testing-commits] r850 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Mon, 18 Apr 2005 19:39:07 +0000


Author: jmm-guest
Date: 2005-04-18 19:39:04 +0000 (Mon, 18 Apr 2005)
New Revision: 850

Modified:
   sarge-checks/CAN/list
Log:
Found a confirmation that CAN-2005-0596 is fixed.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-04-18 19:31:01 UTC (rev 849)
+++ sarge-checks/CAN/list	2005-04-18 19:39:04 UTC (rev 850)
@@ -1515,8 +1515,8 @@
 CAN-2005-0597 (Cisco devices running Application and Content Networking System (ACNS) ...)
 	NOTE: not-for-us (Cisco)
 CAN-2005-0596 (PHP 4 (PHP4) allows attackers to cause a denial of service (daemon ...)
-	NOTE: couldn't find enough info to verify or reproduce
-	TODO: check
+	NOTE: Fixed in CVS after 4.3.4 release; see http://bugs.php.net/bug.php?id=27037
+	- php4 4.3.8-1
 CAN-2005-0595 (Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers ...)
 	NOTE: not-for-us (BadBlue)
 CAN-2005-0594