[Secure-testing-commits] r23859 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Wed Oct 2 21:19:54 UTC 2013


Author: carnil
Date: 2013-10-02 21:19:54 +0000 (Wed, 02 Oct 2013)
New Revision: 23859

Modified:
   data/CVE/list
Log:
Mark CVE-2013-4326/rtkit as no-dsa for wheezy

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-10-02 21:14:47 UTC (rev 23858)
+++ data/CVE/list	2013-10-02 21:19:54 UTC (rev 23859)
@@ -3683,6 +3683,7 @@
 CVE-2013-4326 [use of insecure polkit DBUS API]
 	RESERVED
 	- rtkit 0.10-3 (bug #723714)
+	[wheezy] - rtkit <no-dsa> (user can get realtime scheduling privileges)
 CVE-2013-4325 (The check_permission_v1 function in base/pkit.py in HP Linux Imaging ...)
 	- hplip 3.13.9-1 (bug #723716)
 CVE-2013-4324 [Insecure calling of polkit via polkit_unix_process_new()]




More information about the Secure-testing-commits mailing list