[Secure-testing-commits] r7823 - data/CVE

white at alioth.debian.org white at alioth.debian.org
Fri Jan 4 11:47:36 UTC 2008


Author: white
Date: 2008-01-04 11:47:36 +0000 (Fri, 04 Jan 2008)
New Revision: 7823

Modified:
   data/CVE/list
Log:
XSS in adobe flash; bug filled against flashplugin-nonfree

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-01-04 11:22:45 UTC (rev 7822)
+++ data/CVE/list	2008-01-04 11:47:36 UTC (rev 7823)
@@ -181,7 +181,8 @@
 CVE-2007-6638 (March Networks DVR 3204 stores sensitive information under the web ...)
 	NOT-FOR-US: March Networks
 CVE-2007-6637 (Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash ...)
-	TODO: check
+	- flashplugin-nonfree <unfixed> (bug #459071)
+	NOTE: http://www.adobe.com/support/security/advisories/apsa07-06.html
 CVE-2007-6636 (Unspecified vulnerability in the StorageFarabDb module in Bitflu ...)
 	NOT-FOR-US: Bitflu
 CVE-2007-6635 (FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in ...)




More information about the Secure-testing-commits mailing list