[Secure-testing-commits] r30543 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Thu Dec 4 15:23:13 UTC 2014


Author: jmm
Date: 2014-12-04 15:23:13 +0000 (Thu, 04 Dec 2014)
New Revision: 30543

Modified:
   data/CVE/list
Log:
kde-workspace unimportant


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-12-04 15:21:14 UTC (rev 30542)
+++ data/CVE/list	2014-12-04 15:23:13 UTC (rev 30543)
@@ -2327,8 +2327,10 @@
 	NOT-FOR-US: ALLPlayer
 CVE-2014-8651 [Privilege Escalation via KDE Clock KCM polkit helper]
 	RESERVED
-	- kde-workspace 4:4.11.13-2
+	- kde-workspace 4:4.11.13-2 (unimportant)
 	NOTE: https://projects.kde.org/projects/kde/kde-workspace/repository/diff?rev=54d0bfb5effff9c8cf60da890b7728cbe36a454e&rev_to=fd2aa9deed44fad6107625ad7360157fea7296f6
+        NOTE: On Debian changing the clock requires authentication, so it's not exploitable
+        NOTE: in the standard setup
 CVE-2014-8583
 	RESERVED
 	- mod-wsgi 4.2.7-1




More information about the Secure-testing-commits mailing list