[Secure-testing-commits] r1455 - data/CAN

Moritz Muehlenhoff jmm-guest at costa.debian.org
Fri Jul 22 06:00:49 UTC 2005


Author: jmm-guest
Date: 2005-07-22 06:00:41 +0000 (Fri, 22 Jul 2005)
New Revision: 1455

Modified:
   data/CAN/list
Log:
remove old provisional ekg entry (already CANified)

ekg int overflow affects kopete only if no libgadu
is installed, i.e. only on broken setups. should still
be fixed IMO.


Modified: data/CAN/list
===================================================================
--- data/CAN/list	2005-07-22 01:25:55 UTC (rev 1454)
+++ data/CAN/list	2005-07-22 06:00:41 UTC (rev 1455)
@@ -852,8 +852,6 @@
 	NOTE: reserved
 CAN-2004-2154 (CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as ...)
 	- cupsys 1.1.20final+rc1-1 (low)
-CAN-2005-XXXX [Insecure tempfile generation in ekg]
-	- ekg 1:1.5+20050411-4 (bug #318059; medium)
 CAN-2005-2116
 	NOTE: rejected
 	{DSA-745-1}
@@ -2203,7 +2201,11 @@
 	NOTE: reserved
 CAN-2005-1852 [Integer overflow in ekg]
 	NOTE: reserved
+	NOTE: It seems as if Kopete is not directly affected if a local copy of the lib
+	NOTE: is installed, but this could this be an issue in systems were libgadu has
+	NOTE: been removed with --force-depends
 	- ekg 1:1.5+20050712+1.6rc3-1 (medium)
+	- kopete (unfixed; bug filed; low)
 CAN-2005-1851 [Potential shell command injection in ekg contrib script]
 	NOTE: reserved
 	- ekg 1:1.5+20050712+1.6rc2-1 (low)




More information about the Secure-testing-commits mailing list