[Secure-testing-commits] r19410 - data/CVE

Yves-Alexis Perez corsac at alioth.debian.org
Sat Jun 2 07:20:20 UTC 2012


Author: corsac
Date: 2012-06-02 07:20:19 +0000 (Sat, 02 Jun 2012)
New Revision: 19410

Modified:
   data/CVE/list
Log:
add note/todo for the DES crypt() issue


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-06-02 07:16:38 UTC (rev 19409)
+++ data/CVE/list	2012-06-02 07:20:19 UTC (rev 19410)
@@ -2275,6 +2275,8 @@
 	- horizon 2012.1-4 (bug #671604)
 CVE-2012-2143
 	RESERVED
+	NOTE: DES weakness in crypt() when using unicode encoding
+	TODO: check who's affected (php? postgre?)
 CVE-2012-2142
 	RESERVED
 CVE-2012-2141 [Array index error, leading to out-of heap-based buffer read (snmpd crash)]




More information about the Secure-testing-commits mailing list