[Secure-testing-commits] r1412 - data/CAN

Moritz Muehlenhoff jmm-guest at costa.debian.org
Sat Jul 16 17:48:38 UTC 2005


Author: jmm-guest
Date: 2005-07-16 17:48:35 +0000 (Sat, 16 Jul 2005)
New Revision: 1412

Modified:
   data/CAN/list
Log:
bugnums for tutos
new cve id fors ekg, not sure whether they are already fixed
  in the latest upload


Modified: data/CAN/list
===================================================================
--- data/CAN/list	2005-07-16 17:18:26 UTC (rev 1411)
+++ data/CAN/list	2005-07-16 17:48:35 UTC (rev 1412)
@@ -295,9 +295,9 @@
 CAN-2004-2163 (login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not ...)
 	NOTE: not-for-us (OpenBSD)
 CAN-2004-2162 (Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow ...)
-	- tutos (unfixed; bug filed; medium)
+	- tutos (unfixed; bug #318633; medium)
 CAN-2004-2161 (SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows ...)
-	- tutos (unfixed; bug filed; medium)
+	- tutos (unfixed; bug #318633; medium)
 CAN-2004-2160 (Format string vulnerability in xml_elem.c for XMLStarlet Command Line ...)
 	- xmlstarlet 1.0.0-1
 CAN-2004-2159 (Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 ...)
@@ -1780,10 +1780,12 @@
 	NOTE: reserved
 CAN-2005-1852
 	NOTE: reserved
-CAN-2005-1851
+CAN-2005-1851 [Potential shell command injection in ekg contrib script]
 	NOTE: reserved
-CAN-2005-1850
+	- ekg (unfixed; low)
+CAN-2005-1850 [Insecure tmpfile generation in ekg's contrib scripts]
 	NOTE: reserved
+	- ekg (unfixed; low)
 CAN-2005-1849
 	NOTE: reserved
 CAN-2005-1848 (The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause ...)




More information about the Secure-testing-commits mailing list