[Secure-testing-commits] r12562 - data/CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Tue Aug 11 16:19:09 UTC 2009


Author: gilbert-guest
Date: 2009-08-11 16:19:09 +0000 (Tue, 11 Aug 2009)
New Revision: 12562

Modified:
   data/CVE/list
Log:
- new kernel issue
- reassign port scanning flaw to xerces


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-08-11 15:25:32 UTC (rev 12561)
+++ data/CVE/list	2009-08-11 16:19:09 UTC (rev 12562)
@@ -1,7 +1,7 @@
-CVE-2009-XXXX [apache2: xml-based firewall bypass / port scanning]
-	- apache2 <unfixed> (low; bug #540862)
-	[etch] - apache2 <no-dsa> (minor issue)
-	[lenny] - apache2 <no-dsa> (minor issue)
+CVE-2009-XXXX [libxerces2-java: xml-based firewall bypass / port scanning]
+	- libxerces2-java <unfixed> (low; bug #540862)
+	[etch] - libxerces2-java <no-dsa> (minor issue)
+	[lenny] - libxerces2-java <no-dsa> (minor issue)
 	TODO: request cve it
 CVE-2009-XXXX [linux-2.6: parisc eisa underflow]
 	- linux-2.6 <unfixed> (low)
@@ -141,8 +141,10 @@
 	RESERVED
 CVE-2009-2692
 	RESERVED
-CVE-2009-2691
+CVE-2009-2691 [linux-2.6: /proc/$pid/maps exposed during initial setuid ELF loading]
 	RESERVED
+	- linux-2.6 <unfixed> (low)
+	- linux-2.6.24 <removed>
 CVE-2009-2690 [OpenJDK private variable information disclosure]
 	RESERVED
 	- sun-java6 6-15-1




More information about the Secure-testing-commits mailing list