[Secure-testing-commits] r19092 - data/CVE

Michael Gilbert mgilbert at alioth.debian.org
Sun Apr 29 04:05:08 UTC 2012


Author: mgilbert
Date: 2012-04-29 04:05:08 +0000 (Sun, 29 Apr 2012)
New Revision: 19092

Modified:
   data/CVE/list
Log:
util-linux issue has been fixed for a long time now

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-04-29 04:04:21 UTC (rev 19091)
+++ data/CVE/list	2012-04-29 04:05:08 UTC (rev 19092)
@@ -78726,8 +78726,8 @@
 CVE-2007-1161 (Cross-site scripting (XSS) vulnerability in call_entry.php in Call ...)
 	NOT-FOR-US: Call Center Software
 CVE-2006-7108 (login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when ...)
-	- util-linux <unfixed> (unimportant)
-	NOTE: Expected behaviour; pam_acct_mgmt() requires prior pam_authenticate()
+	- util-linux 2.17.2-9 (unimportant)
+	NOTE: likely fixed far before this, which is the version in squeeze that was checked
 CVE-2006-7107 (PHP remote file inclusion vulnerability in upgrade.php in Coalescent ...)
 	NOT-FOR-US: freePBX
 CVE-2006-7106 (PHP remote file inclusion vulnerability in config.inc.php3 in Power ...)




More information about the Secure-testing-commits mailing list