[Secure-testing-commits] r2776 - data/CVE

Florian Weimer fw at costa.debian.org
Thu Nov 17 20:42:29 UTC 2005


Author: fw
Date: 2005-11-17 20:42:25 +0000 (Thu, 17 Nov 2005)
New Revision: 2776

Modified:
   data/CVE/list
Log:
synaesthesia is not setuid since version 2.1-3.


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2005-11-17 14:58:04 UTC (rev 2775)
+++ data/CVE/list	2005-11-17 20:42:25 UTC (rev 2776)
@@ -12382,6 +12382,7 @@
 	- vdr 1.2.6-6
 CVE-2005-0070 (Synaesthesia 2.1 and earlier, and possibly other versions, when ...)
 	{DSA-681-1}
+	- synaesthesia 2.1-3
 	NOTE: does not apply for sarge, program is not setuid anymore
 CVE-2005-0069 (The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local ...)
 	- vim 1:6.3-058+1
@@ -18906,8 +18907,8 @@
 	NOT-FOR-US: os x
 CVE-2004-0160 (Synaesthesia 2.2 and earlier allows local users to execute arbitrary ...)
 	{DSA-446}
-	TODO: synaesthesia is no longer setuid.
-	TODO: Maintainer has been contacted to get the exact version.
+	- synaesthesia 2.1-3
+	NOTE: synaesthesia is no longer setuid in Debian.
 CVE-2004-0159 (Format string vulnerability in hsftp 1.11 allows remote authenticated ...)
 	{DSA-447}
 	- hsftp 1.15-1




More information about the Secure-testing-commits mailing list