[Secure-testing-commits] r24576 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Wed Dec 4 12:44:19 UTC 2013
Author: carnil
Date: 2013-12-04 12:44:19 +0000 (Wed, 04 Dec 2013)
New Revision: 24576
Modified:
data/CVE/list
Log:
Add fixed version for rails-4.0 issues
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2013-12-04 12:41:52 UTC (rev 24575)
+++ data/CVE/list 2013-12-04 12:44:19 UTC (rev 24576)
@@ -1749,7 +1749,7 @@
RESERVED
CVE-2013-6417 [Unsafe Query Generation]
RESERVED
- - rails-4.0 <unfixed> (bug #731290)
+ - rails-4.0 4.0.2+dfsg-1 (bug #731290)
- ruby-actionpack-3.2 <unfixed> (bug #731288)
- ruby-actionpack-2.3 <not-affected> (vulnerable code not present)
- rails 2.3.14.1
@@ -1757,21 +1757,21 @@
NOTE: CVE for incomplete fix for CVE-2013-0155
CVE-2013-6416 [XSS]
RESERVED
- - rails-4.0 <unfixed> (bug #731290)
+ - rails-4.0 4.0.2+dfsg-1 (bug #731290)
- ruby-actionpack-3.2 <not-affected> (vulnerable code not present)
- ruby-actionpack-2.3 <not-affected> (vulnerable coee not present)
- rails 2.3.14.1
NOTE: Starting with 2.3.14.1 rails is a transition package
CVE-2013-6415 [XSS]
RESERVED
- - rails-4.0 <unfixed> (bug #731290)
+ - rails-4.0 4.0.2+dfsg-1 (bug #731290)
- ruby-actionpack-3.2 <unfixed> (bug #731288)
- ruby-actionpack-2.3 <unfixed> (bug #731289)
- rails 2.3.14.1
NOTE: Starting with 2.3.14.1 rails is a transition package
CVE-2013-6414 [Denial of Service Vulnerability]
RESERVED
- - rails-4.0 <unfixed> (bug #731290)
+ - rails-4.0 4.0.2+dfsg-1 (bug #731290)
- ruby-actionpack-3.2 <unfixed> (bug #731288)
- ruby-actionpack-2.3 <not-affected> (vulnerable code not present)
- rails 2.3.14.1
@@ -6334,7 +6334,7 @@
RESERVED
CVE-2013-4491 [Reflective XSS]
RESERVED
- - rails-4.0 <unfixed> (bug #731290)
+ - rails-4.0 4.0.2+dfsg-1 (bug #731290)
- ruby-actionpack-3.2 <unfixed> (bug #731288)
- ruby-actionpack-2.3 <not-affected> (vulnerable code not present)
- rails 2.3.14.1
More information about the Secure-testing-commits
mailing list