[Secure-testing-commits] r13839 - in data: . CVE

Michael Gilbert gilbert-guest at alioth.debian.org
Sat Jan 16 19:34:20 UTC 2010


Author: gilbert-guest
Date: 2010-01-16 19:34:18 +0000 (Sat, 16 Jan 2010)
New Revision: 13839

Modified:
   data/CVE/list
   data/embedded-code-copies
Log:
expat/wbxml2 fixed; gnome-screensaver issue does not affect etch/lenny

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2010-01-16 18:21:35 UTC (rev 13838)
+++ data/CVE/list	2010-01-16 19:34:18 UTC (rev 13839)
@@ -1535,8 +1535,8 @@
 	RESERVED
 CVE-2009-XXXX [gnome-screensaver inhibitor not removed when connection is closed]
 	- gnome-screensaver <unfixed> (low; bug #560895)
-	[etch] - gnome-screensaver <no-dsa> (minor issue)
-	[lenny] - gnome-screensaver <no-dsa> (minor issue)
+	[etch] - gnome-screensaver <not-affected> (vulnerable code introduced in 2.28)
+	[lenny] - gnome-screensaver <not-affected> (vulnerable code introduced in 2.28)
 	TODO: request CVE id
 	NOTE: the code in etch's version is more different but it seems to be affected
 	NOTE: http://git.gnome.org/browse/gnome-screensaver/commit/?id=284c9924969a49dbf2d5fae1d680d3310c4df4a3
@@ -3135,9 +3135,6 @@
 	[etch] - smart <no-dsa> (minor issue)
 	[lenny] - smart <no-dsa> (minor issue)
 	- tla 1.3.5+dfsg-15 (unimportant; bug #560940)
-	- wbxml2 <unfixed> (low; bug #560941)
-	[etch] - wbxml2 <no-dsa> (minor issue)
-	[lenny] - wbxml2 <no-dsa> (minor issue)
 	- xmlrpc-c <unfixed> (low; bug #560942)
 	[etch] - xmlrpc-c <no-dsa> (minor issue)
 	[lenny] - xmlrpc-c <no-dsa> (minor issue)
@@ -3620,9 +3617,6 @@
 	[etch] - smart <no-dsa> (minor issue)
 	[lenny] - smart <no-dsa> (minor issue)
 	- tla 1.3.5+dfsg-15 (unimportant; bug #560940)
-	- wbxml2 <unfixed> (low; bug #560941)
-	[etch] - wbxml2 <no-dsa> (minor issue)
-	[lenny] - wbxml2 <no-dsa> (minor issue)
 	- xmlrpc-c <unfixed> (low; bug #560942)
 	[etch] - xmlrpc-c <no-dsa> (minor issue)
 	[lenny] - xmlrpc-c <no-dsa> (minor issue)

Modified: data/embedded-code-copies
===================================================================
--- data/embedded-code-copies	2010-01-16 18:21:35 UTC (rev 13838)
+++ data/embedded-code-copies	2010-01-16 19:34:18 UTC (rev 13839)
@@ -1146,7 +1146,7 @@
 	- swish-e <not-affected> (Linked against libxml, which is used instead)
 	- tla 1.3.5+dfsg-15 (embed)
 	- vtk 4.1.20030227-1 (embed)
-	- wbxml2 <unfixed> (embed)
+	- wbxml2 0.9.2-3 (embed)
 	- xmlrpc-c <unfixed> (embed)
 	- iceweasel <unfixed> (embed)
 	- kompozer <unfixed> (embed)




More information about the Secure-testing-commits mailing list