[Secure-testing-commits] r12465 - data/CVE

Nico Golde nion at alioth.debian.org
Mon Aug 3 15:55:15 UTC 2009


Author: nion
Date: 2009-08-03 15:55:15 +0000 (Mon, 03 Aug 2009)
New Revision: 12465

Modified:
   data/CVE/list
Log:
CVE-2009-0841 non-issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-08-03 14:57:27 UTC (rev 12464)
+++ data/CVE/list	2009-08-03 15:55:15 UTC (rev 12465)
@@ -5465,7 +5465,8 @@
 CVE-2009-0842 (mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows ...)
 	- mapserver 5.2.2-1 (low; bug #523027)
 CVE-2009-0841 (Directory traversal vulnerability in mapserv.c in mapserv in MapServer ...)
-	- mapserver 5.2.2-1 (low; bug #523027)
+	- mapserver 5.2.2-1 (unimportant; bug #523027)
+	NOTE: this doesn't work under linux as the root from the directory traversal needs to exist
 CVE-2009-0840 (Heap-based buffer underflow in the readPostBody function in cgiutil.c ...)
 	- mapserver 5.2.2-1 (medium; bug #523027)
 	NOTE: http://www.openwall.com/lists/oss-security/2009/06/22/2




More information about the Secure-testing-commits mailing list