[Secure-testing-commits] r22617 - data/CVE

Moritz Muehlenhoff jmm at alioth.debian.org
Sun Jun 16 12:34:39 UTC 2013


Author: jmm
Date: 2013-06-16 12:34:39 +0000 (Sun, 16 Jun 2013)
New Revision: 22617

Modified:
   data/CVE/list
Log:
mark non-sec wireshark issues as unimportant as the rest


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-06-16 12:33:20 UTC (rev 22616)
+++ data/CVE/list	2013-06-16 12:34:39 UTC (rev 22617)
@@ -1052,13 +1052,13 @@
 	NOTE: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8733
 	NOTE: Not suitable for code injection
 CVE-2013-4080 (The dissect_r3_upstreamcommand_queryconfig function in ...)
-	- wireshark <unfixed> (bug #711918)
-	[wheezy] - wireshark <no-dsa> (infinite loop)
+	- wireshark <unfixed> (unimportant; bug #711918)
+	NOTE: no code injection, not treated as a security issue, see README.Debian.security
 	[squeeze] - wireshark <not-affected> (Only affects 1.8+)
 	NOTE: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8764
 CVE-2013-4079 (The dissect_schedule_message function in ...)
-	- wireshark <unfixed> (bug #711918)
-	[wheezy] - wireshark <no-dsa> (infinite loop)
+	- wireshark <unfixed> (unimportant; bug #711918)
+	NOTE: no code injection, not treated as a security issue, see README.Debian.security
 	[squeeze] - wireshark <not-affected> (Only affects 1.8+)
 	NOTE: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8730
 CVE-2013-4078 (epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x ...)




More information about the Secure-testing-commits mailing list