[Secure-testing-commits] r22755 - data/CVE

Moritz Muehlenhoff jmm at alioth.debian.org
Wed Jun 26 09:42:55 UTC 2013


Author: jmm
Date: 2013-06-26 09:42:55 +0000 (Wed, 26 Jun 2013)
New Revision: 22755

Modified:
   data/CVE/list
Log:
one java issue specific to oracle java, the rest confirmed in icedtea
qpid-python bugnum


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-06-26 09:14:22 UTC (rev 22754)
+++ data/CVE/list	2013-06-26 09:42:55 UTC (rev 22755)
@@ -4918,8 +4918,9 @@
 	- openjdk-6 <unfixed>
 	- openjdk-7 <unfixed>
 CVE-2013-2464 (Unspecified vulnerability in the Java Runtime Environment (JRE) ...)
-	- openjdk-6 <unfixed>
-	- openjdk-7 <unfixed>
+	- openjdk-6 <not-affected> (Specific to Oracle Java, not present in IcedTea)
+	- openjdk-7 <not-affected> (Specific to Oracle Java, not present in IcedTea)
+	NOTE: Due to the vague disclosure policy by Oracle the exact nature is unknown but since no patch landed in icedtea, we consider it not-affected
 CVE-2013-2463 (Unspecified vulnerability in the Java Runtime Environment (JRE) ...)
 	- openjdk-6 <unfixed>
 	- openjdk-7 <unfixed>
@@ -6624,7 +6625,7 @@
 	NOTE: Only used for bootstraps of chroots, see README.Debian
 CVE-2013-1909
 	RESERVED
-	- qpid-python <unfixed> (low)
+	- qpid-python <unfixed> (low; bug #714133)
 	[wheezy] - qpid-python <no-dsa> (Minor issue)
 CVE-2013-1908
 	RESERVED




More information about the Secure-testing-commits mailing list