[Secure-testing-commits] r15077 - data/CVE

Stefan Fritsch sf at alioth.debian.org
Sat Jul 31 10:10:12 UTC 2010


Author: sf
Date: 2010-07-31 10:10:04 +0000 (Sat, 31 Jul 2010)
New Revision: 15077

Modified:
   data/CVE/list
Log:
- new old apache2 issue
- apache2 no-dsa


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2010-07-30 21:14:52 UTC (rev 15076)
+++ data/CVE/list	2010-07-31 10:10:04 UTC (rev 15077)
@@ -293,8 +293,9 @@
 	RESERVED
 CVE-2010-2792
 	RESERVED
-CVE-2010-2791
+CVE-2010-2791 [apache2 mod_proxy information leak]
 	RESERVED
+	- apache2 2.2.10-1 (low)
 CVE-2010-2790 [zabbix XSS via formatQuery() of class.curl.php]
 	RESERVED
 	- zabbix <unfixed>
@@ -3841,7 +3842,8 @@
 CVE-2010-1453 (Cross-site scripting (XSS) vulnerability in the Login form in Piwik ...)
 	- piwik <itp> (bug #506933)
 CVE-2010-1452 (The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server ...)
-	- apache2 2.2.16-1
+	- apache2 2.2.16-1 (low)
+	[lenny] - apache2 <no-dsa> (mod_cache not affected and mod_dav is easy to DoS anyway)
 CVE-2010-1451 (The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the ...)
 	{DSA-2053-1}
 	- linux-2.6 2.6.32-10




More information about the Secure-testing-commits mailing list