[Secure-testing-commits] r28071 - data/CVE

Henri Salo fgeek-guest at moszumanska.debian.org
Mon Aug 4 06:07:52 UTC 2014


Author: fgeek-guest
Date: 2014-08-04 06:07:52 +0000 (Mon, 04 Aug 2014)
New Revision: 28071

Modified:
   data/CVE/list
Log:
CVE-2014-5177/libvirt, NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-08-03 18:44:11 UTC (rev 28070)
+++ data/CVE/list	2014-08-04 06:07:52 UTC (rev 28071)
@@ -11,6 +11,9 @@
 	- ipython <unfixed>
 	[squeeze] - ipython <not-affected> (Affects versions <= 2.1 and >= 0.12)
 	NOTE: https://github.com/ipython/ipython/issues/6246
+CVE-2014-5177 [Unsafe parsing of XML documents allows arbitrary file read]
+	- libvirt <unfixed>
+	NOTE: http://security.libvirt.org/2014/0003.html
 CVE-2014-5170
 	RESERVED
 CVE-2014-5169
@@ -16945,10 +16948,13 @@
 	RESERVED
 CVE-2013-5758
 	RESERVED
+	NOT-FOR-US: Yealink VoIP Phone
 CVE-2013-5757
 	RESERVED
+	NOT-FOR-US: Yealink VoIP Phone
 CVE-2013-5756
 	RESERVED
+	NOT-FOR-US: Yealink VoIP Phone
 CVE-2013-5755 (config/.htpasswd in Yealink IP Phone SIP-T38G have a hardcoded ...)
 	NOT-FOR-US: Yealink IP Phone
 CVE-2013-5754 (The authorization implementation on Dahua DVR appliances accepts a ...)




More information about the Secure-testing-commits mailing list