[Secure-testing-commits] r23253 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Thu Aug 8 16:20:22 UTC 2013


Author: carnil
Date: 2013-08-08 16:20:21 +0000 (Thu, 08 Aug 2013)
New Revision: 23253

Modified:
   data/CVE/list
Log:
add more nova and cinder entries

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-08-08 16:16:11 UTC (rev 23252)
+++ data/CVE/list	2013-08-08 16:20:21 UTC (rev 23253)
@@ -1939,8 +1939,9 @@
 CVE-2013-4203 [Rgpg Ruby Gem Remote Command Injection]
 	RESERVED
 	NOT-FOR-US: Ruby Rgpg Gem
-CVE-2013-4202
+CVE-2013-4202 [Denial of Service using XML entities in Nova/Cinder extensions]
 	RESERVED
+	- cinder 2013.1.2-4
 CVE-2013-4201 [Katello: CLI - user without access can call "system remove_deletion" command]
 	RESERVED
 	NOT-FOR-US: Katello
@@ -1996,15 +1997,16 @@
 	- libdata-uuid-perl <unfixed> (low; bug #718949)
 CVE-2013-4183 [Cinder LVM volume driver does not support secure deletion]
 	RESERVED
-	- cinder <unfixed> (bug #719010)
+	- cinder 2013.1.2-4 (bug #719010)
 CVE-2013-4182
 	RESERVED
 CVE-2013-4181
 	RESERVED
 CVE-2013-4180
 	RESERVED
-CVE-2013-4179
+CVE-2013-4179 [Denial of Service using XML entities in Nova/Cinder extensions]
 	RESERVED
+	- nova <unfixed>
 CVE-2013-4178
 	RESERVED
 	NOT-FOR-US: GA Login Drupal contributed module




More information about the Secure-testing-commits mailing list