[Secure-testing-commits] r11292 - data/CVE

white at alioth.debian.org white at alioth.debian.org
Sun Mar 1 09:50:24 UTC 2009


Author: white
Date: 2009-03-01 09:50:23 +0000 (Sun, 01 Mar 2009)
New Revision: 11292

Modified:
   data/CVE/list
Log:
tor issue unimportant

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-03-01 09:39:24 UTC (rev 11291)
+++ data/CVE/list	2009-03-01 09:50:23 UTC (rev 11292)
@@ -180,7 +180,8 @@
 CVE-2009-0655 (Lenovo Veriface III allows physically proximate attackers to login to ...)
 	NOT-FOR-US: Lenovo Veriface
 CVE-2009-0654 (Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote ...)
-	TODO: check
+	- tor <unfixed> (unimportant)
+	NOTE: attacker already controls entry and exit node at this stage
 CVE-2009-0653 (OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an ...)
 	TODO: check
 CVE-2009-0652 (Mozilla Firefox 3.0.6 does not properly prevent the literal rendering ...)




More information about the Secure-testing-commits mailing list