[Secure-testing-commits] r5852 - data/CVE

seanius at alioth.debian.org seanius at alioth.debian.org
Wed May 16 21:29:41 UTC 2007


Author: seanius
Date: 2007-05-16 21:29:39 +0000 (Wed, 16 May 2007)
New Revision: 5852

Modified:
   data/CVE/list
Log:
nfu CVE-2007-1401

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2007-05-16 21:14:10 UTC (rev 5851)
+++ data/CVE/list	2007-05-16 21:29:39 UTC (rev 5852)
@@ -2720,8 +2720,7 @@
 CVE-2007-1402 (The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows ...)
 	NOT-FOR-US: Rediff Toolbar ActiveX control
 CVE-2007-1401 (Buffer overflow in the crack extension (CrackLib), as bundled with PHP ...)
-	- php4 <unfixed>
-	TODO: check php5
+	NOT-FOR-US: php doesn't ship with cracklib activated in debian.
 CVE-2007-1400 (Plash permits sandboxed processes to open /dev/tty, which allows local ...)
 	NOT-FOR-US: Plash
 CVE-2007-1399 (Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP ...)




More information about the Secure-testing-commits mailing list