[Secure-testing-commits] r12772 - data/CVE

Giuseppe Iuculano derevko-guest at alioth.debian.org
Wed Sep 9 08:25:51 UTC 2009


Author: derevko-guest
Date: 2009-09-09 08:25:51 +0000 (Wed, 09 Sep 2009)
New Revision: 12772

Modified:
   data/CVE/list
Log:
CVE-2009-2697: gdm redhat specific issue
CVE-2009-2700: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName (qt4-x11)


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2009-09-09 06:29:06 UTC (rev 12771)
+++ data/CVE/list	2009-09-09 08:25:51 UTC (rev 12772)
@@ -1511,7 +1511,8 @@
 CVE-2009-2701
 	RESERVED
 CVE-2009-2700 (src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not ...)
-	TODO: check
+	- qt4-x11 <unfixed> (medium; bug #545793)
+	[etch] - qt4-x11 <not-affected> (QSsl* classes were introduced in Qt 4.3)
 CVE-2009-2699
 	RESERVED
 CVE-2009-2698 (The udp_sendmsg function in the UDP implementation in (1) ...)
@@ -1519,7 +1520,7 @@
 	- linux-2.6 2.6.19-1 (high)
 	- linux-2.6.24 <not-affected> (Fixed before initial upload, 2.6.19)
 CVE-2009-2697 (The Red Hat build script for the GNOME Display Manager (GDM) before ...)
-	TODO: check
+	- gdm <not-affected> (TCP Wrappers support enabled correctly)
 CVE-2009-2696
 	RESERVED
 CVE-2009-2695 (The Linux kernel before 2.6.31-rc7 does not properly prevent mmap ...)




More information about the Secure-testing-commits mailing list