[Secure-testing-commits] r30566 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Dec 5 18:29:54 UTC 2014


Author: carnil
Date: 2014-12-05 18:29:53 +0000 (Fri, 05 Dec 2014)
New Revision: 30566

Modified:
   data/CVE/list
Log:
One mantis issue had a CVE split again

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-12-05 18:25:35 UTC (rev 30565)
+++ data/CVE/list	2014-12-05 18:29:53 UTC (rev 30566)
@@ -473,11 +473,14 @@
 	[squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)
 	NOTE: http://github.com/mantisbt/mantisbt/commit/05378e00
 	NOTE: http://www.mantisbt.org/bugs/view.php?id=17297
-CVE-2014-9271 [Multiple XSS]
+CVE-2014-9281 [XSS in admin panel / copy_field.php]
 	- mantis <removed>
 	[squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)
 	NOTE: http://github.com/mantisbt/mantisbt/commit/e5fc835a
 	NOTE: http://www.mantisbt.org/bugs/view.php?id=17876
+CVE-2014-9271 [XSS in file uploads]
+	- mantis <removed>
+	[squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)
 	NOTE: http://www.mantisbt.org/bugs/view.php?id=17874
 	NOTE: http://github.com/mantisbt/mantisbt/commit/9fb8cf36f
 CVE-2014-9270 [XSS in projax_api.php]




More information about the Secure-testing-commits mailing list