[Secure-testing-commits] r22735 - data/CVE

Moritz Muehlenhoff jmm at alioth.debian.org
Tue Jun 25 09:28:13 UTC 2013


Author: jmm
Date: 2013-06-25 09:28:12 +0000 (Tue, 25 Jun 2013)
New Revision: 22735

Modified:
   data/CVE/list
Log:
php nonissue


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-06-25 09:20:04 UTC (rev 22734)
+++ data/CVE/list	2013-06-25 09:28:12 UTC (rev 22735)
@@ -5,8 +5,8 @@
 	- file <not-affected> (bug in code modified for PHP)
 	NOTE: Tested with the squeeze and wheezy versions
 CVE-2013-4635 (Integer overflow in the SdnToJewish function in jewish.c in the ...)
-	- php5 <unfixed>
-	TODO: check
+	- php5 5.5.0+dfsg-1 (unimportant)
+	NOTE: exploitable by malicious scripts only
 CVE-2012-6572 (Cross-site scripting (XSS) vulnerability in the ...)
 	NOT-FOR-US: Inf08 theme for Drupal
 CVE-2013-4634 (SQL injection vulnerability in the jQuery autocomplete for ...)




More information about the Secure-testing-commits mailing list