[Secure-testing-commits] r18591 - data/CVE

Yves-Alexis Perez corsac at alioth.debian.org
Mon Mar 5 20:27:07 UTC 2012


Author: corsac
Date: 2012-03-05 20:27:06 +0000 (Mon, 05 Mar 2012)
New Revision: 18591

Modified:
   data/CVE/list
Log:
some kernel issues and some NOT-FOR-US


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-03-05 12:58:51 UTC (rev 18590)
+++ data/CVE/list	2012-03-05 20:27:06 UTC (rev 18591)
@@ -799,10 +799,12 @@
 	RESERVED
 CVE-2012-1106
 	RESERVED
+	NOT-FOR-US: abrt is Red Hat / Fedora specific
 CVE-2012-1105
 	RESERVED
 CVE-2012-1104
 	RESERVED
+	NOT-FOR-US: phpCAS library from Jasig project, not in Debian
 CVE-2012-1103
 	RESERVED
 	{DSA-2416-1}
@@ -5299,6 +5301,9 @@
 	- colord 0.1.15-1 (medium; bug #650021)
 CVE-2011-4348
 	RESERVED
+	- linux-2.6 <unfixed>
+	NOTE: incomplete fix for CVE-2011-2482
+	NOTE: CVE-2011-2482 was RHEL-specific so I guess it's the same here
 CVE-2011-4347
 	RESERVED
 	- linux-2.6 <unfixed>
@@ -7757,6 +7762,7 @@
 	NOTE: relatively obscure client crash
 CVE-2011-3593
 	RESERVED
+	- linux-2.6 <not-affected> (RHEL6 only because of badly backported patches)
 CVE-2011-3592 [phpMyAdmin did not properly sanitize the content of db, table, and column names prior use of their values.]
 	RESERVED
 	- phpmyadmin 4:3.4.5-1




More information about the Secure-testing-commits mailing list