[Secure-testing-commits] r5069 - data/CVE

Stefan Fritsch stef-guest at alioth.debian.org
Tue Dec 5 17:42:05 CET 2006


Author: stef-guest
Date: 2006-12-05 17:42:02 +0100 (Tue, 05 Dec 2006)
New Revision: 5069

Modified:
   data/CVE/list
Log:
- CVE-2006-6172: new xine issue (medium)
- new l2tpns issue (medium)


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2006-12-05 08:14:17 UTC (rev 5068)
+++ data/CVE/list	2006-12-05 16:42:02 UTC (rev 5069)
@@ -1,3 +1,5 @@
+CVE-2006-XXXX [l2tpns Heartbeat Packets Buffer Overflow Vulnerability]
+	- l2tpns <unfixed> (medium; bug filed)
 CVE-2006-XXXX [squirrelmail XSS on MSIE <=5]
 	- squirrelmail 2:1.4.9a-1 (unimportant)
 CVE-2006-XXXX [DoS in ruby cgi.rb]
@@ -216,7 +218,8 @@
 CVE-2006-6173 (Buffer overflow in the shared_region_make_private_np function in ...)
 	NOT-FOR-US: Mac OS X 
 CVE-2006-6172 (Buffer overflow in the asmrp_eval function for Real Media input plugin ...)
-	TODO: check xine, etc
+	- xine-lib <unfixed> (medium; bug filed)
+	TODO: check usual suspects (ffmpeg, ...)
 CVE-2006-6171 (** DISPUTED ** ...)
 	{DSA-1218}
 	- proftpd-dfsg 1.3.0-13 (low; bug #399070)




More information about the Secure-testing-commits mailing list