[Secure-testing-commits] r9718 - data/CVE

nion at alioth.debian.org nion at alioth.debian.org
Mon Sep 1 10:18:32 UTC 2008


Author: nion
Date: 2008-09-01 10:18:30 +0000 (Mon, 01 Sep 2008)
New Revision: 9718

Modified:
   data/CVE/list
Log:
new newsbeuter issue fixed in 1.1-1

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2008-08-31 21:14:11 UTC (rev 9717)
+++ data/CVE/list	2008-09-01 10:18:30 UTC (rev 9718)
@@ -1,3 +1,8 @@
+CVE-2008-XXXX [code execution in newsbeuter via crafted url when opened in external browser]
+	- newsbeuter 1.1-1 (medium)
+	NOTE: medium as versions < 1.0-1 didn't include a patch to wrap long article URLs so the
+	NOTE: crafted part of the URL can be hidden. This of course only affects people not reading
+	NOTE: articles in the built-in reader.
 begin claimed by white
 CVE-2008-XXXX [NULL pointer reference]
 	- bitlbee 1.2.2-1




More information about the Secure-testing-commits mailing list