[Secure-testing-commits] r17151 - data/CVE

Moritz Muehlenhoff jmm at alioth.debian.org
Wed Aug 31 20:48:09 UTC 2011


Author: jmm
Date: 2011-08-31 20:48:08 +0000 (Wed, 31 Aug 2011)
New Revision: 17151

Modified:
   data/CVE/list
Log:
one rails issue doesn't affect Debian


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2011-08-31 20:29:48 UTC (rev 17150)
+++ data/CVE/list	2011-08-31 20:48:08 UTC (rev 17151)
@@ -2808,8 +2808,7 @@
 	[squeeze] - dbus 1.2.24-4+squeeze1
 	[lenny] - dbus <no-dsa> (Minor issue)
 CVE-2011-2197 (The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...)
-	- rails <unfixed> (bug #634990)
-	NOTE: likely affected since sid is < 2.3.12
+	- rails <not-affected> (Affected plugin not installed, see bug #634990)
 CVE-2011-2196 (jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as ...)
 	NOT-FOR-US: JBoss Seam
 CVE-2011-2195




More information about the Secure-testing-commits mailing list