[Secure-testing-commits] r15396 - data/CVE

Raphael Geissert geissert at alioth.debian.org
Thu Sep 30 01:07:41 UTC 2010


Author: geissert
Date: 2010-09-30 01:07:37 +0000 (Thu, 30 Sep 2010)
New Revision: 15396

Modified:
   data/CVE/list
Log:
fix typo
4 pam issues
1 epiphany-browser


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2010-09-30 00:51:14 UTC (rev 15395)
+++ data/CVE/list	2010-09-30 01:07:37 UTC (rev 15396)
@@ -2,7 +2,7 @@
 	- bind9 <unfixed>
 	TODO: check
 	NOTE: http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.html
-	NOTE: ACL bypass claimed to only affect >9.7.2: https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
+	NOTE: ACL bypass claimed to only affect >=9.7.2: https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
 CVE-2010-XXXX [horde3 XSS and CSRF]
 	- horde3 <unfixed>
 	TODO: check
@@ -629,6 +629,9 @@
 	RESERVED
 CVE-2010-3435
 	RESERVED
+	- pam <unfixed>
+	TODO: check
+	NOTE: 20100924164823.GA21584 at openwall.com
 CVE-2010-3434 [clamav pdf]
 	RESERVED
 	- clamav 0.96.3+dfsg-1
@@ -641,8 +644,14 @@
 	- linux-2.6 2.6.32-24
 CVE-2010-3431
 	RESERVED
+	- pam <unfixed>
+	TODO: check
+	NOTE: 20100924164823.GA21584 at openwall.com
 CVE-2010-3430
 	RESERVED
+	- pam <unfixed>
+	TODO: check
+	NOTE: 20100924164823.GA21584 at openwall.com
 CVE-2010-3429
 	RESERVED
 	- ffmpeg <unfixed>
@@ -963,6 +972,10 @@
 	NOT-FOR-US: IBM Records Manager
 CVE-2010-3316
 	RESERVED
+	- pam <unfixed>
+	TODO: check
+	NOTE: partial fix http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commitdiff;h=06f882f30092a39a1db867c9744b2ca8d60e4ad6
+	NOTE: see 20100927201729.GB4485 at openwall.com
 CVE-2010-3315
 	RESERVED
 CVE-2010-3314 (Cross-site scripting (XSS) vulnerability in login.php in EGroupware ...)
@@ -975,6 +988,7 @@
 	[lenny] - egroupware 1.4.004-2.dfsg-4.2
 CVE-2010-3312
 	RESERVED
+	- epiphany-browser 2.29.91-1 (bug #564690)
 CVE-2010-3311
 	RESERVED
 CVE-2010-3310 [heap corruption in net/rose]




More information about the Secure-testing-commits mailing list