[Secure-testing-commits] r17401 - data/CVE

Luciano Bello luciano at alioth.debian.org
Mon Oct 10 15:40:49 UTC 2011


Author: luciano
Date: 2011-10-10 15:40:49 +0000 (Mon, 10 Oct 2011)
New Revision: 17401

Modified:
   data/CVE/list
Log:
NOT-FOR-US issues in kexec-tools

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2011-10-10 07:45:04 UTC (rev 17400)
+++ data/CVE/list	2011-10-10 15:40:49 UTC (rev 17401)
@@ -1051,12 +1051,21 @@
 	- phpmyadmin 4:3.4.5-1
 	[squeeze] - phpmyadmin <not-affected> (Vulnerable code not present)
 	[lenny] - phpmyadmin <not-affected> (Vulnerable code not present)
-CVE-2011-3590
+CVE-2011-3590 [mkdumprd utility created the final initial ramdisk image with...]
 	RESERVED
-CVE-2011-3589
+	NOT-FOR-US: RHEL and Fedora.
+	NOTE: The flaw exists in kdump.init and mkdumprd scrits, shipped with Red Hat and Fedora.
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=716439
+CVE-2011-3589 [mkdumprd utility copied content of certain directories into newly...]
 	RESERVED
-CVE-2011-3588
+	NOT-FOR-US: RHEL and Fedora.
+	NOTE: The flaw exists in kdump.init and mkdumprd scrits, shipped with Red Hat and Fedora.
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=716439
+CVE-2011-3588 [kdump/mkdumprd: the default value of "StrictHostKeyChecking=no"]
 	RESERVED
+	NOT-FOR-US: RHEL and Fedora.
+	NOTE: The flaw exists in kdump.init and mkdumprd scrits, shipped with Red Hat and Fedora.
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=716439
 CVE-2011-3587
 	RESERVED
 CVE-2011-3586




More information about the Secure-testing-commits mailing list