[Secure-testing-commits] r9348 - data/CVE

nion at alioth.debian.org nion at alioth.debian.org
Wed Jul 16 14:43:49 UTC 2008


Author: nion
Date: 2008-07-16 14:43:48 +0000 (Wed, 16 Jul 2008)
New Revision: 9348

Modified:
   data/CVE/list
Log:
CVE-2008-1026 not affecting qt4-x11

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-07-16 14:17:20 UTC (rev 9347)
+++ data/CVE/list	2008-07-16 14:43:48 UTC (rev 9348)
@@ -5004,6 +5004,8 @@
 	NOT-FOR-US: Apple Mac OS
 CVE-2008-1026 (Integer overflow in the PCRE regular expression compiler ...)
 	- webkit 0~svn31841-1
+	- qt4-x11 <not-affected> (vulnerable code not present referring to upstream)
+	NOTE: for qt, referring to upstream this only applies to optimized code in safari 3.1 branch and qt 4.4 is based on safari 3.0
 	TODO: check qt4-x11
 CVE-2008-1025 (Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in ...)
 	- qt4-x11 <not-affected> (QUrl handles URLs and is not vulnerable to this CVE, see bug #479644)




More information about the Secure-testing-commits mailing list