[Secure-testing-commits] r12496 - data/CVE
Giuseppe Iuculano
derevko-guest at alioth.debian.org
Thu Aug 6 10:09:21 UTC 2009
Author: derevko-guest
Date: 2009-08-06 10:09:21 +0000 (Thu, 06 Aug 2009)
New Revision: 12496
Modified:
data/CVE/list
Log:
webkit related issues fixed in kde4libs 4:4.3.0-1
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2009-08-06 09:14:23 UTC (rev 12495)
+++ data/CVE/list 2009-08-06 10:09:21 UTC (rev 12496)
@@ -2475,7 +2475,7 @@
- webkit <unfixed> (medium; bug #538346)
- qt4-x11 <unfixed> (medium; bug #538347)
- kdelibs <unfixed> (medium; bug #538350)
- - kde4libs <unfixed> (medium; bug #538349)
+ - kde4libs 4:4.3.0-1 (medium; bug #538349)
NOTE: patch http://trac.webkit.org/changeset/44799/
NOTE: PoC https://cevans-app.appspot.com/static/webkitentityoffbyone.html
CVE-2009-1724 (Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari ...)
@@ -2557,7 +2557,7 @@
- webkit 1.1.5-1 (medium; bug #534946)
NOTE: http://trac.webkit.org/changeset/42081
- kdelibs <unfixed> (medium; bug #534952)
- - kde4libs <unfixed> (medium; bug #534949)
+ - kde4libs 4:4.3.0-1 (medium; bug #534949)
- qt4-x11 4:4.5.2-1 (medium; bug #534947)
CVE-2009-1697 (CRLF injection vulnerability in WebKit in Apple Safari before 4.0, ...)
- webkit <unfixed> (medium; bug #535793)
@@ -2585,7 +2585,7 @@
- webkit 1.1.5-1 (medium; bug #534946)
NOTE: http://trac.webkit.org/changeset/42532
- kdelibs <unfixed> (medium; bug #534952)
- - kde4libs <unfixed> (medium; bug #534949)
+ - kde4libs 4:4.3.0-1 (medium; bug #534949)
NOTE: http://websvn.kde.org/?view=rev&revision=983316
- qt4-x11 4:4.5.2-1 (medium; bug #534947)
CVE-2009-1689 (Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari ...)
@@ -5224,7 +5224,7 @@
- qt4-x11 4:4.5.2-1 (medium; bug #532718)
- webkit 1.1.5-1 (medium; bug #532724; bug #532725)
NOTE: http://trac.webkit.org/changeset/43590
- - kde4libs <unfixed> (medium; bug #534917)
+ - kde4libs 4:4.3.0-1 (medium; bug #534917)
[lenny] - kde4libs <not-affected> (khtml doesn't have SVG support)
NOTE: http://websvn.kde.org/?view=rev&revision=983302
- kdegraphics 4:4.0 (medium; bug #534918)
More information about the Secure-testing-commits
mailing list