[Secure-testing-commits] r28339 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Aug 18 20:27:07 UTC 2014


Author: carnil
Date: 2014-08-18 20:27:07 +0000 (Mon, 18 Aug 2014)
New Revision: 28339

Modified:
   data/CVE/list
Log:
Update CVE-2012-6153/commns-httpclient

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-08-18 17:37:50 UTC (rev 28338)
+++ data/CVE/list	2014-08-18 20:27:07 UTC (rev 28339)
@@ -33460,7 +33460,9 @@
 	RESERVED
 CVE-2012-6153 [Hostname verification susceptible to MITM attack]
 	RESERVED
-	- commons-httpclient <unfixed> (bug #758086)
+	- commons-httpclient 3.1-10.2 (bug #758086)
+	NOTE: See https://bugs.debian.org/692442#56 and ff.
+	NOTE: https://svn.apache.org/viewvc?view=revision&revision=1411705
 CVE-2012-6152 (The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does ...)
 	- pidgin 2.10.8-1
 	[squeeze] - pidgin <end-of-life> (Support in oldstable is limited to IRC, Jabber/XMPP, Sametime and SIMPLE)




More information about the Secure-testing-commits mailing list