[Secure-testing-commits] r12286 - data/CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Mon Jul 6 02:55:48 UTC 2009


Author: gilbert-guest
Date: 2009-07-06 02:55:48 +0000 (Mon, 06 Jul 2009)
New Revision: 12286

Modified:
   data/CVE/list
Log:
syncing some kernel info from kernel-sec tracker


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-07-06 02:32:39 UTC (rev 12285)
+++ data/CVE/list	2009-07-06 02:55:48 UTC (rev 12286)
@@ -4616,7 +4616,7 @@
 	NOTE: CONFIG_SECCOMP has only been enabled in 2.6.26
 CVE-2009-0834 (The audit_syscall_entry function in the Linux kernel 2.6.28.7 and ...)
 	{DSA-1800-1 DSA-1794-1 DSA-1787-1}
-	- linux-2.6 2.6.30-1 (low)
+	- linux-2.6 2.6.29-1 (low)
 	[squeeze] - linux-2.6 2.6.26-17
 	- linux-2.6.24 <removed>
 CVE-2009-0833 (Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 ...)
@@ -6120,9 +6120,8 @@
 CVE-2008-6108 (Cross-site scripting (XSS) vulnerability in result.php in Galatolo ...)
 	NOT-FOR-US: Galatolo WebManager
 CVE-2008-6107 (The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, ...)
-	- linux-2.6 <unfixed> (low)
+	- linux-2.6 2.6.25-4 (low)
 	- linux-2.6.24 <removed>
-	NOTE: should this be considered a problem in lenny/squeeze/sid since description says that the problem applies to kernels before 2.6.25.4?
 CVE-2008-6106 (Cross-site request forgery (CSRF) vulnerability in IBM Workplace for ...)
 	NOT-FOR-US: IBM Workplace for Business Controls
 CVE-2008-6105 (Cross-site scripting (XSS) vulnerability in IBM Workplace for Business ...)




More information about the Secure-testing-commits mailing list