[Secure-testing-commits] r23264 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Fri Aug 9 08:28:36 UTC 2013


Author: carnil
Date: 2013-08-09 08:28:36 +0000 (Fri, 09 Aug 2013)
New Revision: 23264

Modified:
   data/CVE/list
Log:
add two chrony issues

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-08-09 08:17:20 UTC (rev 23263)
+++ data/CVE/list	2013-08-09 08:28:36 UTC (rev 23264)
@@ -18553,10 +18553,12 @@
 CVE-2012-4504 (Stack-based buffer overflow in the url::get_pac function in url.cpp in ...)
 	- libproxy <not-affected> (Vulnerable code not present)
 	NOTE: 0.4-only issue, fixed in newest upstream 0.4.9
-CVE-2012-4503
+CVE-2012-4503 [Uninitialized data in command replies]
 	RESERVED
-CVE-2012-4502
+	- chrony <unfixed>
+CVE-2012-4502 [Buffer overflow when processing crafted command packets]
 	RESERVED
+	- chrony <unfixed>
 CVE-2012-4501 (Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows ...)
 	NOT-FOR-US: CloudStack
 CVE-2012-4500 (The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows ...)




More information about the Secure-testing-commits mailing list