[Secure-testing-commits] r24339 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Sat Nov 9 06:36:51 UTC 2013


Author: carnil
Date: 2013-11-09 06:36:51 +0000 (Sat, 09 Nov 2013)
New Revision: 24339

Modified:
   data/CVE/list
Log:
Add fixed version for CVE-2013-4407/libhttp-body-perl

Note: delayed the DSA for a further bit to get testing with this chance.
Upstream has still not implemented their desired solution:

https://rt.cpan.org/Public/Bug/Display.html?id=88342

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-11-09 06:24:30 UTC (rev 24338)
+++ data/CVE/list	2013-11-09 06:36:51 UTC (rev 24339)
@@ -5098,7 +5098,7 @@
 	RESERVED
 CVE-2013-4407 [remote command-injection]
 	RESERVED
-	- libhttp-body-perl <unfixed> (bug #721634)
+	- libhttp-body-perl 1.17-2 (bug #721634)
 	[squeeze] - libhttp-body-perl <not-affected> (Vulnerable code introduced in 1.08)
 CVE-2013-4406
 	RESERVED




More information about the Secure-testing-commits mailing list