[Secure-testing-commits] r12305 - data/CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Tue Jul 7 22:17:23 UTC 2009


Author: gilbert-guest
Date: 2009-07-07 22:17:22 +0000 (Tue, 07 Jul 2009)
New Revision: 12305

Modified:
   data/CVE/list
Log:
tracking bugs submitted against kernel


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-07-07 21:14:29 UTC (rev 12304)
+++ data/CVE/list	2009-07-07 22:17:22 UTC (rev 12305)
@@ -1460,9 +1460,10 @@
 	- ctorrent 1.3.4-dnh3.2-1.1 (medium; bug #530255)
 CVE-2009-1758 (The hypervisor_callback function in Xen, possibly before 3.4.0, as ...)
 	{DSA-1809-1}
-	- linux-2.6 <unfixed>
+	- linux-2.6 <unfixed> (low; bug #536148)
 	[squeeze] - linux-2.6 2.6.26-17
 	- linux-2.6.24 <removed>
+	NOTE: maximum impact is denial-of-service, so low-urgency
 CVE-2009-1757 (Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 ...)
 	- transmission 1.61-1 (low)
 	[lenny] - transmission <not-affected> (Vulnerable code not present, the web interface was introduced in 1.30)
@@ -8471,7 +8472,7 @@
 	- squirrelmail <not-affected> (RedHat-specific regression)
 CVE-2009-0029 (The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, ...)
 	{DSA-1794-1 DSA-1787-1 DSA-1749-1}
-	- linux-2.6 <unfixed> (medium)
+	- linux-2.6 <unfixed> (medium; bug #536147)
 	- linux-2.6.24 <removed>
 	[squeeze] - linux-2.6 2.6.26-13lenny1
 CVE-2009-0028 (The clone system call in the Linux kernel 2.6.28 and earlier allows ...)




More information about the Secure-testing-commits mailing list