[Secure-testing-commits] r19826 - data/CVE

Yves-Alexis Perez corsac at alioth.debian.org
Mon Jul 30 15:13:03 UTC 2012


Author: corsac
Date: 2012-07-30 15:13:03 +0000 (Mon, 30 Jul 2012)
New Revision: 19826

Modified:
   data/CVE/list
Log:
add CVEs for RT extensions


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-07-30 14:23:06 UTC (rev 19825)
+++ data/CVE/list	2012-07-30 15:13:03 UTC (rev 19826)
@@ -2846,12 +2846,18 @@
 	RESERVED
 CVE-2012-2771
 	RESERVED
-CVE-2012-2770
+CVE-2012-2770 [privilege escalation in Request Tracker external auth extension]
 	RESERVED
+	- rt-authen-externalauth <unfixed> (bug #683288)
 CVE-2012-2769
 	RESERVED
-CVE-2012-2768
+	- request-tracker4 4.0.6-1
+	NOTE: bundled in RT4
+CVE-2012-2768 [multiple XSS in RTFM, Request Tracker FAQ manager]
 	RESERVED
+	- rt3.8-rtfm <unfixed> (bug #683290)
+	- request-tracker4 4.0.6-1
+	NOTE: bundled in RT4
 CVE-2012-2767
 	RESERVED
 CVE-2012-2766




More information about the Secure-testing-commits mailing list