[Secure-testing-commits] r23508 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Sun Sep 1 19:30:36 UTC 2013


Author: carnil
Date: 2013-09-01 19:30:36 +0000 (Sun, 01 Sep 2013)
New Revision: 23508

Modified:
   data/CVE/list
Log:
Add CVE-2013-4277/subversion, part of external check

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-09-01 19:21:02 UTC (rev 23507)
+++ data/CVE/list	2013-09-01 19:30:36 UTC (rev 23508)
@@ -2980,8 +2980,12 @@
 	- nova <unfixed> (bug #720602)
 	[wheezy] - nova <not-affected> (Affected code not present)
 	NOTE: incomplete fix for CVE-2013-2256
-CVE-2013-4277
+CVE-2013-4277 [local privilege escalation vulnerability via symlink attack]
 	RESERVED
+	- subversion <unfixed> (low)
+	[squeeze] - subversion <no-dsa> (Minor issue, PID file not created by default)
+	[wheezy] - subversion <no-dsa> (Minor issue, PID file not created by default)
+	NOTE: http://subversion.apache.org/security/CVE-2013-4277-advisory.txt
 CVE-2013-4276 [liblcms1 buffer overflows]
 	RESERVED
 	- lcms <unfixed> (low; bug #718682)




More information about the Secure-testing-commits mailing list