[Secure-testing-commits] r8851 - data/CVE

white at alioth.debian.org white at alioth.debian.org
Tue May 20 13:53:45 UTC 2008


Author: white
Date: 2008-05-20 13:53:44 +0000 (Tue, 20 May 2008)
New Revision: 8851

Modified:
   data/CVE/list
Log:
libqt4-webkit not vulnerable to CVE-2008-1025

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-05-20 13:05:09 UTC (rev 8850)
+++ data/CVE/list	2008-05-20 13:53:44 UTC (rev 8851)
@@ -2887,7 +2887,7 @@
 	- webkit 0~svn31841-1
 	TODO: check qt4-x11
 CVE-2008-1025 (Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in ...)
-	- qt4-x11 <unfixed> (medium; bug #479644)
+	- qt4-x11 <not-affected> (QUrl handles URLs and is not vulnerable to this CVE, see bug #479644)
 	- webkit 0~svn31841-1 (medium)
 CVE-2008-1024 (Apple Safari before 3.1.1, when running on Windows XP or Vista, allows ...)
 	NOT-FOR-US: Apple Safari




More information about the Secure-testing-commits mailing list