[Secure-testing-commits] r4311 - data/CVE

Alec Berryman alec-guest at costa.debian.org
Wed Jun 28 01:08:28 UTC 2006


Author: alec-guest
Date: 2006-06-28 01:08:24 +0000 (Wed, 28 Jun 2006)
New Revision: 4311

Modified:
   data/CVE/list
Log:
* CVE-2006-3178 (chmlib): fixed (unimportant; vulnerability in uncompiled sample program)


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2006-06-28 01:04:03 UTC (rev 4310)
+++ data/CVE/list	2006-06-28 01:08:24 UTC (rev 4311)
@@ -97,7 +97,9 @@
 CVE-2006-3179 (Cross-site scripting (XSS) vulnerability in tools_ftp_pwaendern.php in ...)
 	NOT-FOR-US: Confixx Pro
 CVE-2006-3178 (Directory traversal vulnerability in extract_chmLib example program in ...)
-	TODO: check
+	NOTE: not a security bug in the library, but rather in one of the uncompiled
+	NOTE: sample programs distributed in /usr/share/doc/libchm-dev/examples
+	- chmlib 0.38-1 (bug #374085; unimportant)
 CVE-2006-3177 (PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The ...)
 	NOT-FOR-US: The Bible Portal Project
 CVE-2006-3176 (SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 ...)




More information about the Secure-testing-commits mailing list