[Secure-testing-commits] r1073 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Mon, 16 May 2005 18:36:33 +0000


Author: jmm-guest
Date: 2005-05-16 18:36:30 +0000 (Mon, 16 May 2005)
New Revision: 1073

Modified:
   sarge-checks/CAN/list
Log:
new libotr buffer overflow
corrected elog entry


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-05-16 18:01:25 UTC (rev 1072)
+++ sarge-checks/CAN/list	2005-05-16 18:36:30 UTC (rev 1073)
@@ -1,3 +1,5 @@
+CAN-2005-XXXX [Buffer overflow in libotr]
+	- libotr 2.0.2-1
 CAN-2005-XXXX [vpnc: config file path security hole]
 	NOTE: no bug ever filed for this
 	- vpnc 0.3.2+SVN20050326-2
@@ -931,8 +933,7 @@
 	- eskuel 1.0.5-3.1
 CAN-2005-XXXX [eskuel: No authentication at all]
 	- eskuel (unfixed; bug #163653)
-CAN-2005-XXXX [48 new vulnerabilities in Ethereal]
-	TODO: um, why is this under an ethereal pseudo-CAN?
+CAN-2005-XXXX [Buffer overflow in elog]
 	NOTE: t-p-u fix approved but lacking a few builds
 	- elog 2.5.7+r1558-2
 CAN-2005-XXXX [Unspeficied security issue in ipsec-tool's single DES support]