[Secure-testing-commits] r11598 - data/CVE

Nico Golde nion at alioth.debian.org
Thu Apr 9 14:05:23 UTC 2009


Author: nion
Date: 2009-04-09 14:05:17 +0000 (Thu, 09 Apr 2009)
New Revision: 11598

Modified:
   data/CVE/list
Log:
update status for destar, CVE-2008-6538 doesnt affect us

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-04-09 12:05:15 UTC (rev 11597)
+++ data/CVE/list	2009-04-09 14:05:17 UTC (rev 11598)
@@ -600,9 +600,10 @@
 CVE-2008-6540 (DotNetNuke before 4.8.2, during installation or upgrade, does not warn ...)
 	NOT-FOR-US: DotNetNuke 
 CVE-2008-6539 (Static code injection vulnerability in user/settings/ in DeStar ...)
-	- destar <unfixed> (bug filed)
+	- destar <unfixed> (bug #522123)
 CVE-2008-6538 (DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a ...)
-	- destar <unfixed> (bug filed)
+	- destar <not-affected> (bug #522123)
+	NOTE: we include a default configuration user which can be changed with instructions in README.Debian
 CVE-2008-6537 (LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows ...)
 	NOT-FOR-US: LightNEasy No database
 CVE-2008-6536 (Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and ...)




More information about the Secure-testing-commits mailing list