[Secure-testing-commits] r8575 - data/CVE

nion at alioth.debian.org nion at alioth.debian.org
Sat Apr 19 13:16:09 UTC 2008


Author: nion
Date: 2008-04-19 13:16:07 +0000 (Sat, 19 Apr 2008)
New Revision: 8575

Modified:
   data/CVE/list
Log:
aptlinex issues fixed in aptlinex 0.91-1

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-04-19 12:58:00 UTC (rev 8574)
+++ data/CVE/list	2008-04-19 13:16:07 UTC (rev 8575)
@@ -89,10 +89,11 @@
 CVE-2008-1878 [nsf buffer overflow in xine]
 	- xine-lib <unfixed>
 CVE-2008-XXXX [insecure tmp file handling in aptlinex]
-	- aptlinex <unfixed> (low; bug #476588)
+	- aptlinex 0.91-1 (medium; bug #476588)
+	NOTE: code execution via /tmp/gambas-apt-exec is also possible, maintainer confirmed this
 	NOTE: CVE id requested
 CVE-2008-XXXX [remove/install packages via crafted links or run]
-	- aptlinex <unfixed> (low; bug #476572)
+	- aptlinex 0.91-1 (low; bug #476572)
 	NOTE: the user gets a confirmation dialog
 	NOTE: CVE id requested
 CVE-2008-1831 (Multiple unspecified vulnerabilities in the Siebel SimBuilder ...)




More information about the Secure-testing-commits mailing list