[Secure-testing-commits] r12364 - data/CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Fri Jul 17 07:23:26 UTC 2009


Author: gilbert-guest
Date: 2009-07-17 07:23:25 +0000 (Fri, 17 Jul 2009)
New Revision: 12364

Modified:
   data/CVE/list
Log:
new kernel issue is actually CVE-2009-1897


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-07-17 07:06:56 UTC (rev 12363)
+++ data/CVE/list	2009-07-17 07:23:25 UTC (rev 12364)
@@ -1,7 +1,3 @@
-CVE-2009-XXXX [linux-2.6: exploitable null pointer dereference bypass]
-	- linux-2.6 <unfixed> (high)
-	- linux-2.6.24 <removed>
-	NOTE: http://seclists.org/fulldisclosure/2009/Jul/0241.html
 CVE-2009-2491
 	NOT-FOR-US: Sun Ray Server Software
 CVE-2009-2490
@@ -1438,10 +1434,11 @@
 	NOTE: we don't support setups with register_globals enabled
 CVE-2009-1897 [linux-2.6: null pointer dereference in tun/tap]
 	RESERVED
-	- linux-2.6 2.6.30-3 (low)
+	- linux-2.6 2.6.30-3 (high)
 	[etch] - linux-2.6 <not-affected> (vulnerable code introduced in 2.6.29)
 	[lenny] - linux-2.6 <not-affected> (vulnerable code introduced in 2.6.29)
 	- linux-2.6.24 <not-affected> (vulnerable code introduced in 2.6.29)
+	NOTE: http://seclists.org/fulldisclosure/2009/Jul/0241.html
 CVE-2009-1896
 	RESERVED
 CVE-2009-1895 [linux-2.6: potential vulnerabilites in the personality subsystem]




More information about the Secure-testing-commits mailing list