[Secure-testing-commits] r24168 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Fri Oct 25 07:33:16 UTC 2013


Author: carnil
Date: 2013-10-25 07:33:16 +0000 (Fri, 25 Oct 2013)
New Revision: 24168

Modified:
   data/CVE/list
Log:
Add CVE-2013-5823, part of external check, update todo

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-10-25 07:31:37 UTC (rev 24167)
+++ data/CVE/list	2013-10-25 07:33:16 UTC (rev 24168)
@@ -878,7 +878,10 @@
 	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5823 (Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE ...)
-	TODO: This issue was fixed in Oracle Java, but not in OpenJDK. Likely not-affected, but needs further check
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
+	NOTE: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/a7758faab30d
+	TODO: check (both openjdk-6 and openjdk-7)
 CVE-2013-5822 (Unspecified vulnerability in the Oracle iLearning component in Oracle ...)
 	NOT-FOR-US: Oracle iLearning
 CVE-2013-5821




More information about the Secure-testing-commits mailing list