[Secure-testing-commits] r19135 - data/CVE

Thijs Kinkhorst thijs at alioth.debian.org
Fri May 4 12:02:10 UTC 2012


Author: thijs
Date: 2012-05-04 12:02:10 +0000 (Fri, 04 May 2012)
New Revision: 19135

Modified:
   data/CVE/list
Log:
incomplete fix uploaded


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-05-04 11:59:42 UTC (rev 19134)
+++ data/CVE/list	2012-05-04 12:02:10 UTC (rev 19135)
@@ -387,7 +387,7 @@
 CVE-2012-2311
 	RESERVED
 	- php5 <unfixed>
-	NOTE: This CVE ID is for the initial incomplete fix for CVE-2012-1823, so strictly speaking Debian is not affected since we never applied the broken patch
+	NOTE: This CVE ID is for the initial incomplete fix for CVE-2012-1823
 CVE-2012-2310
 	RESERVED
 CVE-2012-2309
@@ -1522,6 +1522,7 @@
 	RESERVED
 	- php5 <unfixed>
 	NOTE: http://ompldr.org/vZGxxaQ https://bugs.php.net/bug.php?id=61910
+	NOTE: 5.4.2-1 'fixed' this, but fix is incomplete: CVE-2012-2311
 CVE-2012-1822
 	RESERVED
 CVE-2012-1821




More information about the Secure-testing-commits mailing list