[Secure-testing-commits] r24300 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Mon Nov 4 21:22:18 UTC 2013


Author: carnil
Date: 2013-11-04 21:22:18 +0000 (Mon, 04 Nov 2013)
New Revision: 24300

Modified:
   data/CVE/list
Log:
Add CVE-2013-4512/linux

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-11-04 21:14:55 UTC (rev 24299)
+++ data/CVE/list	2013-11-04 21:22:18 UTC (rev 24300)
@@ -4135,14 +4135,20 @@
 	RESERVED
 CVE-2013-4513
 	RESERVED
-CVE-2013-4512
+CVE-2013-4512 [buffer overflow in write syscall]
 	RESERVED
+	- linux <unfixed>
+	- linux-2.6 <removed>
+	NOTE: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=201f99f170df14ba52ea4c52847779042b7a623b
+	NOTE: linux/3.12 contains the fix
+	TODO: check, only arch/um/kernel/exitcode.c
 CVE-2013-4511
 	RESERVED
 	- linux <unfixed>
 	- linux-2.6 <removed>
 	NOTE: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7314e613d
-	NOTE: linux/v3.12 contains the fix (not yet in unstable)
+	NOTE: linux/3.12 contains the fix (not yet in unstable)
+	TODO: check
 CVE-2013-4510 [File extension not santized]
 	RESERVED
 	{DSA-2791-1}




More information about the Secure-testing-commits mailing list