[Secure-testing-commits] r995 - sarge-checks/CAN

Joey Hess joeyh@costa.debian.org
Thu, 05 May 2005 20:25:41 +0000


Author: joeyh
Date: 2005-05-05 20:25:38 +0000 (Thu, 05 May 2005)
New Revision: 995

Modified:
   sarge-checks/CAN/list
Log:
krb4 is also vulnerable to CAN-2005-0468; tracking in same bug as other
hole


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-05-05 20:18:09 UTC (rev 994)
+++ sarge-checks/CAN/list	2005-05-05 20:25:38 UTC (rev 995)
@@ -3025,6 +3025,7 @@
 CAN-2005-0468 (Heap-based buffer overflow in the env_opt_add function in telnet.c for ...)
 	{DSA-703-1}
 	- krb5 1.3.6-2
+	- krb4 (unfixed; bug #306141)
 	TODO: check netkit-telnet, netkit-telnet, netkit-telnet-ssl
 CAN-2005-0467 (Multiple integer overflows in the (1) sftp_pkt_getstring and (2) ...)
 	- putty 0.57-1