[Secure-testing-commits] r21206 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Sat Feb 9 08:50:40 UTC 2013


Author: carnil
Date: 2013-02-09 08:50:40 +0000 (Sat, 09 Feb 2013)
New Revision: 21206

Modified:
   data/CVE/list
Log:
add CVE-2012-6120, check if Debian package is affected

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-02-09 08:46:45 UTC (rev 21205)
+++ data/CVE/list	2013-02-09 08:50:40 UTC (rev 21206)
@@ -4328,8 +4328,10 @@
 	- roundcube <unfixed>
 	NOTE: http://trac.roundcube.net/ticket/1488850
 	TODO: check and report
-CVE-2012-6120
+CVE-2012-6120 [Directory /var/log/puppet is world readable]
 	RESERVED
+	- puppet <unfixed>
+	TODO: check if Red Hat specific
 CVE-2012-6119
 	RESERVED
 CVE-2012-6118




More information about the Secure-testing-commits mailing list