[Secure-testing-commits] r24801 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Dec 18 12:02:21 UTC 2013


Author: jmm
Date: 2013-12-18 12:02:21 +0000 (Wed, 18 Dec 2013)
New Revision: 24801

Modified:
   data/CVE/list
Log:
nova fixed


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-12-18 09:33:08 UTC (rev 24800)
+++ data/CVE/list	2013-12-18 12:02:21 UTC (rev 24801)
@@ -185,7 +185,7 @@
 	NOT-FOR-US: FiSH Plugin for ZNC IRC Bouncer
 CVE-2013-7048 [Nova live snapshots use an insecure local directory]
 	RESERVED
-	- nova <unfixed> (bug #732022)
+	- nova 2013.2.1-1 (bug #732022)
 	[wheezy] - nova <not-affected> (Support for live snapshots added later)
 	NOTE: https://bugs.launchpad.net/nova/+bug/1227027
 CVE-2013-7050 [uscan: arbitrary code execution]
@@ -2405,9 +2405,8 @@
 CVE-2013-6419 [Metadata queries from Neutron to Nova are not restricted by tenant]
 	RESERVED
 	- neutron <unfixed>
-	- nova <unfixed>
+	- nova 2013.2.1-1
 	NOTE: https://launchpad.net/bugs/1235450
-	TODO: check
 CVE-2013-6418
 	RESERVED
 CVE-2013-6417 (actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before ...)




More information about the Secure-testing-commits mailing list