[Secure-testing-commits] r24115 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Tue Oct 22 07:12:10 UTC 2013


Author: carnil
Date: 2013-10-22 07:12:10 +0000 (Tue, 22 Oct 2013)
New Revision: 24115

Modified:
   data/CVE/list
Log:
Add CVE-2013-4400 from external check

TODO: verify the version, report  and remove todo item.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-10-22 07:09:40 UTC (rev 24114)
+++ data/CVE/list	2013-10-22 07:12:10 UTC (rev 24115)
@@ -3877,8 +3877,12 @@
 	NOTE: introduced in libvirt 1.1.0
 	NOTE: http://libvirt.org/git/?p=libvirt.git;a=commit;h=57687fd6bf7f6e1b3662c52f3f26c06ab19dc96c
 	TODO: check
-CVE-2013-4400
+CVE-2013-4400 [virt-login-shell arbitrary file overwrites vulnerability]
 	RESERVED
+	- libvirt <unfixed>
+	NOTE: introduced in libvirt 1.1.2
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1015228#c3
+	TODO: check
 CVE-2013-4399 [unprivileged user can crash libvirtd when ACLs are enabled]
 	RESERVED
 	- libvirt <unfixed>




More information about the Secure-testing-commits mailing list