[Secure-testing-commits] r23536 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Tue Sep 3 20:56:23 UTC 2013


Author: carnil
Date: 2013-09-03 20:56:22 +0000 (Tue, 03 Sep 2013)
New Revision: 23536

Modified:
   data/CVE/list
Log:
Mark one ansible issue not-affected

Code using /var/tmp/ansible only introduced in 1.2 upstream, with commit
https://github.com/ansible/ansible/commit/0d530f3bf02f0106adf16be975b348be478d783b

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-09-03 20:36:03 UTC (rev 23535)
+++ data/CVE/list	2013-09-03 20:56:22 UTC (rev 23536)
@@ -3048,8 +3048,7 @@
 	TODO: check details
 CVE-2013-4260 [predictible filename used for failed result in world writable directory]
 	RESERVED
-	- ansible <unfixed>
-	TODO: check
+	- ansible <not-affected> (affected code introduced with ansible 1.2)
 CVE-2013-4259 [insecure location for ssh ControlMaster socket]
 	RESERVED
 	- ansible <unfixed>




More information about the Secure-testing-commits mailing list