[Secure-testing-commits] r1204 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Mon, 06 Jun 2005 06:57:56 +0000


Author: jmm-guest
Date: 2005-06-06 06:57:54 +0000 (Mon, 06 Jun 2005)
New Revision: 1204

Modified:
   sarge-checks/CAN/list
Log:
alsa stack protection bypass fixed


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-06-06 06:47:53 UTC (rev 1203)
+++ sarge-checks/CAN/list	2005-06-06 06:57:54 UTC (rev 1204)
@@ -6115,7 +6115,8 @@
 	{DSA-689-1}
 	- libapache2-mod-python 3.1.3-3
 CAN-2005-0087 (The alsa-lib package in Red Hat Linux 4 disables stack protection for ...)
-	NOTE: debian does not have stack protection
+	NOTE: debian does not have stack protection, but it's fixed anyway since 1.0.9
+	- alsa-lib 1.0.9-1
 CAN-2005-0086 (Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 ...)
 	NOTE: not-for-us (redhat specific less bug)
 CAN-2005-0085 (Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before ...)