[Secure-testing-commits] r24035 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Wed Oct 16 20:03:37 UTC 2013


Author: carnil
Date: 2013-10-16 20:03:36 +0000 (Wed, 16 Oct 2013)
New Revision: 24035

Modified:
   data/CVE/list
Log:
Add also ruby-actionmailer-2.3 entry

Furthermore rails is a transitional package since 2.3.14.1, try to mark
the tracker entry accordingly.

This commit needs a second look/review for correctness/completness

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-10-16 19:51:56 UTC (rev 24034)
+++ data/CVE/list	2013-10-16 20:03:36 UTC (rev 24035)
@@ -3859,7 +3859,10 @@
 	RESERVED
 CVE-2013-4389
 	RESERVED
-  - ruby-actionmailer-3.2 <unfixed>
+	- ruby-actionmailer-3.2 <unfixed>
+	- ruby-actionmailer-2.3 <not-affected> (2.3.x not affected)
+	- rails 2.3.14.1
+	NOTE: Starting with 2.3.14.1 rails is a transition package
 CVE-2013-4388 [buffer overflow in the mp4a packetizer]
 	RESERVED
 	- vlc <unfixed> (bug #726528)




More information about the Secure-testing-commits mailing list