[Secure-testing-commits] r2405 - data/CAN

Moritz Muehlenhoff jmm-guest at costa.debian.org
Thu Oct 13 13:09:29 UTC 2005


Author: jmm-guest
Date: 2005-10-13 13:09:25 +0000 (Thu, 13 Oct 2005)
New Revision: 2405

Modified:
   data/CAN/list
Log:
new issue in wget and curl, bugnum


Modified: data/CAN/list
===================================================================
--- data/CAN/list	2005-10-13 13:02:26 UTC (rev 2404)
+++ data/CAN/list	2005-10-13 13:09:25 UTC (rev 2405)
@@ -1,3 +1,6 @@
+CAN-2005-XXXX [Buffer overflow in curl's NTLM auth code]
+	- wget <unfixed> (medium)
+	- curl <unfixed> (bug filed; medium)
 CAN-2005-XXXX [Stack overflow in clamav's DOC processing]
 	- clamav <unfixed> (bug #333566)
 CAN-2005-XXXX [Local file inclusion in phpmyadmin]
@@ -629,7 +632,7 @@
 	- mozilla-thunderbird 1.0.6-4 (bug #329667; bug #329664; high)
 CAN-2005-2967 [Format string vulnerability in xine-libs CDDB code]
 	RESERVED
-	- xine-lib <unfixed> (bug #332919; medium)
+	- xine-lib <unfixed> (bug #332919; bug #333682; medium)
 CAN-2005-2965 [Insecure temp files in graphviz]
 	RESERVED
 	{DSA-857-1}




More information about the Secure-testing-commits mailing list