[Secure-testing-commits] r651 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Fri, 25 Mar 2005 12:39:09 +0000


Author: jmm-guest
Date: 2005-03-25 12:39:06 +0000 (Fri, 25 Mar 2005)
New Revision: 651

Modified:
   sarge-checks/CAN/list
Log:
Bug# for mathopd.
kernel-source-2.6.8 is affected by N_MOUSE line disciple vuln.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-03-25 12:23:50 UTC (rev 650)
+++ sarge-checks/CAN/list	2005-03-25 12:39:06 UTC (rev 651)
@@ -15,7 +15,7 @@
 CAN-2005-0840
 	NOTE: rejected
 CAN-2005-0839 (Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE ...)
-	TODO: check
+	- kernel-source-2.6.8 (unfixed; bug pending)
 CAN-2005-0838 (Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow ...)
 	- icecast2 (unfixed; bug pending)
 CAN-2005-0837 (IceCast 2.20 allows remote attackers to bypass the XSL parser and ...)
@@ -45,7 +45,7 @@
 CAN-2005-0825 (Buffer overflow in LTris before 1.0.10 allows local users to execute ...)
 	- ltris 1.0.6-1.1
 CAN-2005-0824 (The internal_dump function in Mathopd before 1.5p5, and 1.6x before ...)
-	- mathopd (unfixed; bug pending)
+	- mathopd (unfixed; bug #301366)
 CAN-2001-1433 (Cherokee web server before 0.2.7 does not properly drop root ...)
 	NOTE: not-for-us (Cherokee not in Debian)
 CAN-2001-1432 (Directory traversal vulnerability in Cherokee Web Server allows remote ...)