[Secure-testing-commits] r10244 - data/CVE

nion at alioth.debian.org nion at alioth.debian.org
Sun Nov 2 12:31:44 UTC 2008


Author: nion
Date: 2008-11-02 12:31:43 +0000 (Sun, 02 Nov 2008)
New Revision: 10244

Modified:
   data/CVE/list
Log:
CVE-2008-4640 non-issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-11-02 12:24:36 UTC (rev 10243)
+++ data/CVE/list	2008-11-02 12:31:43 UTC (rev 10244)
@@ -365,7 +365,8 @@
 CVE-2008-4641 (The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and ...)
 	- jhead 2.84-2 (low; bug #503645)
 CVE-2008-4640 (The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and ...)
-	- jhead <unfixed> (low; bug #504194)
+	- jhead <unfixed> (unimportant; bug #504194)
+	NOTE: no issue, jhead is just unlinking the output file if it already exists, this is not following symlinks
 CVE-2008-4639 (jhead.c in Matthias Wandel jhead before 2.84 allows local users to ...)
 	- jhead 2.84-1 (low)
 CVE-2008-4638 (qioadmin in the Quick I/O for Database feature in Symantec Veritas ...)




More information about the Secure-testing-commits mailing list