[Secure-testing-commits] r9499 - data/CVE

thomasbl-guest at alioth.debian.org thomasbl-guest at alioth.debian.org
Sun Aug 3 09:25:19 UTC 2008


Author: thomasbl-guest
Date: 2008-08-03 09:25:17 +0000 (Sun, 03 Aug 2008)
New Revision: 9499

Modified:
   data/CVE/list
Log:
fckeditor note changed again...



Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-08-03 02:58:23 UTC (rev 9498)
+++ data/CVE/list	2008-08-03 09:25:17 UTC (rev 9499)
@@ -214,8 +214,8 @@
 	NOT-FOR-US: CreaCMS
 CVE-2008-3312 (Directory traversal vulnerability in ...)
 	- fckeditor <not-affected> (Vulnerable code not present)
-	NOTE: I guess it is lemon CMS specific (although it uses fckeditor) and the
-	NOTE: fckeditor package is not-affected
+	NOTE: lemon cms patched sources, vulnerable code not present in plain fckeditor in no version.
+	NOTE: if in doubt contact the fsckeditor people.
 CVE-2008-3311 (PHP remote file inclusion vulnerability in config.php in Adam ...)
 	NOT-FOR-US: Adam Scheinberg Flip
 CVE-2008-3310 (SQL injection vulnerability in default.asp in Pre Survey Poll allows ...)




More information about the Secure-testing-commits mailing list