[Secure-testing-commits] r28120 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Thu Aug 7 05:54:18 UTC 2014
Author: carnil
Date: 2014-08-07 05:54:18 +0000 (Thu, 07 Aug 2014)
New Revision: 28120
Modified:
data/CVE/list
Log:
Add bugreference for wordpress issues
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2014-08-07 05:32:31 UTC (rev 28119)
+++ data/CVE/list 2014-08-07 05:54:18 UTC (rev 28120)
@@ -1,23 +1,23 @@
CVE-2014-XXXX [cross-site scripting]
- - wordpress <unfixed>
+ - wordpress <unfixed> (bug #757312)
NOTE: XSS: https://core.trac.wordpress.org/changeset/29398
- TODO: check
+ TODO: check wheezy
CVE-2014-XXXX [protections against brute attacks against CSRF tokens]
- - wordpress <unfixed>
+ - wordpress <unfixed> (bug #757312)
NOTE: https://core.trac.wordpress.org/changeset/29384
NOTE: https://core.trac.wordpress.org/changeset/29408
- TODO: check
+ TODO: check wheezy
CVE-2014-XXXX [unsafe serialization vulnerability]
- - wordpress <unfixed>
+ - wordpress <unfixed> (bug #757312)
NOTE: https://core.trac.wordpress.org/changeset/29389
- TODO: check
+ TODO: check wheezy
CVE-2014-XXXX [XML entity expansion attack related to xmlrpc.php]
- - wordpress <unfixed>
+ - wordpress <unfixed> (bug #757312)
NOTE: https://core.trac.wordpress.org/changeset/29405/branches/3.9
- drupal7 7.31-1
- drupal6 <removed>
NOTE: https://www.drupal.org/SA-CORE-2014-004
- TODO: check
+ TODO: check wheezy
CVE-2014-XXXX [vulnerabilities in Keystone revocation events]
- keystone <unfixed>
[wheezy] - keystone <not-affected> (Affects 2014.1 versions up to 2014.1.1)
@@ -7817,9 +7817,9 @@
[squeeze] - php-getid3 <not-affected> (Vulnerable code not present)
NOTE: owncloud advisory does not mention details for GetID3
NOTE: http://owncloud.org/about/security/advisories/oC-SA-2014-006/
- - wordpress <undetermined>
+ - wordpress <unfixed> (bug #757312)
NOTE: https://core.trac.wordpress.org/changeset/29390
- TODO: check if relevant for wordpress in Debian
+ TODO: check wheezy
CVE-2014-2052
RESERVED
- owncloud 6.0.2+dfsg-1
More information about the Secure-testing-commits
mailing list