[Secure-testing-commits] r28237 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Aug 12 15:57:42 UTC 2014


Author: carnil
Date: 2014-08-12 15:57:42 +0000 (Tue, 12 Aug 2014)
New Revision: 28237

Modified:
   data/CVE/list
Log:
Update entry for CVE-2014-3522/subversion

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-08-12 14:54:52 UTC (rev 28236)
+++ data/CVE/list	2014-08-12 15:57:42 UTC (rev 28237)
@@ -3927,7 +3927,7 @@
 CVE-2014-3522 [incorrect SSL certificate validation in Serf RA (repository access) layer]
 	RESERVED
 	- subversion <unfixed>
-	TODO: check, only affects subversion clients which use the Serf RA layer.
+	NOTE: https://subversion.apache.org/security/CVE-2014-3522-advisory.txt
 CVE-2014-3521
 	RESERVED
 CVE-2014-3520 [Keystone V2 trusts privilege escalation through user supplied project id]




More information about the Secure-testing-commits mailing list