[Secure-testing-commits] r20875 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Thu Jan 10 07:21:05 UTC 2013


Author: carnil
Date: 2013-01-10 07:21:05 +0000 (Thu, 10 Jan 2013)
New Revision: 20875

Modified:
   data/CVE/list
Log:
update entry for CVE-2013-0156

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-01-10 07:13:51 UTC (rev 20874)
+++ data/CVE/list	2013-01-10 07:21:05 UTC (rev 20875)
@@ -1826,12 +1826,14 @@
 	- mount <unfixed> (bug #697464; low)
 	[squeeze] - mount <no-dsa> (Minor issue)
 	NOTE: CVE request http://www.openwall.com/lists/oss-security/2013/01/06/1
-CVE-2013-0156
+CVE-2013-0156 [Multiple vulnerabilities in parameter parsing in ActionPack]
 	RESERVED
 	{DSA-2604-1}
 	- rails 2.3.14.1 (bug #697722; high)
 	- ruby-actionpack-3.2 <unfixed>
 	- ruby-actionpack-2.3 <unfixed>
+	- ruby-activesupport-2.3 2.3.14-5 (bug #697789)
+	- ruby-activesupport-3.2 3.2.6-5 (bug #697790)
 	NOTE: Starting with 2.3.14.1 rails is a transition package
 	NOTE: http://www.insinuator.net/2013/01/rails-yaml/
 	NOTE: http://www.openwall.com/lists/oss-security/2013/01/08/14




More information about the Secure-testing-commits mailing list