[Secure-testing-commits] r20261 - data/CVE

Henri Salo fgeek-guest at alioth.debian.org
Mon Oct 1 05:51:09 UTC 2012


Author: fgeek-guest
Date: 2012-10-01 05:51:09 +0000 (Mon, 01 Oct 2012)
New Revision: 20261

Modified:
   data/CVE/list
Log:
drupal7 CVE-2012-2153

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2012-09-30 12:12:47 UTC (rev 20260)
+++ data/CVE/list	2012-10-01 05:51:09 UTC (rev 20261)
@@ -7612,8 +7612,11 @@
 	NOT-FOR-US: Drupal addon not packaged
 CVE-2012-2154 (Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x ...)
 	NOT-FOR-US: Drupal addon not packaged
-CVE-2012-2153
+CVE-2012-2153 [drupal7 access bypass]
 	RESERVED
+	- drupal7 <unfixed>
+	TODO: check if this has been handled in #671402
+	NOTE: http://drupal.org/node/1557938
 CVE-2012-2152 (Stack-based buffer overflow in the get_packet method in socket.c in ...)
 	{DSA-2498-1}
 	- dhcpcd 1:3.2.3-11 (bug #671265)




More information about the Secure-testing-commits mailing list