[Secure-testing-commits] r23232 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Wed Aug 7 18:46:46 UTC 2013


Author: carnil
Date: 2013-08-07 18:46:45 +0000 (Wed, 07 Aug 2013)
New Revision: 23232

Modified:
   data/CVE/list
Log:
add reference for CVE-2013-4208

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-08-07 18:45:30 UTC (rev 23231)
+++ data/CVE/list	2013-08-07 18:46:45 UTC (rev 23232)
@@ -1791,10 +1791,11 @@
 	RESERVED
 CVE-2013-4209
 	RESERVED
-CVE-2013-4208
+CVE-2013-4208 [Private keys left in memory after being used by PuTTY tools]
 	RESERVED
 	- putty 0.63-1
 	- filezilla <unfixed>
+	NOTE: http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/private-key-not-wiped.html
 	TODO: check filezilla
 CVE-2013-4207 [non-coprime values in DSA signatures can cause buffer overflow in modular inverse]
 	RESERVED




More information about the Secure-testing-commits mailing list