[Secure-testing-commits] r25214 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Jan 15 08:13:20 UTC 2014


Author: jmm
Date: 2014-01-15 08:13:20 +0000 (Wed, 15 Jan 2014)
New Revision: 25214

Modified:
   data/CVE/list
Log:
new openjdk issues


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-01-15 06:54:33 UTC (rev 25213)
+++ data/CVE/list	2014-01-15 08:13:20 UTC (rev 25214)
@@ -1949,6 +1949,8 @@
 	RESERVED
 CVE-2014-0428
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0427
 	RESERVED
 CVE-2014-0426
@@ -1957,10 +1959,16 @@
 	RESERVED
 CVE-2014-0424
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0423
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0422
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0421
 	RESERVED
 CVE-2014-0420
@@ -1969,12 +1977,20 @@
 	RESERVED
 CVE-2014-0418
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0417
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0416
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0415
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0414
 	RESERVED
 CVE-2014-0413
@@ -1983,12 +1999,18 @@
 	RESERVED
 CVE-2014-0411
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0410
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0409
 	RESERVED
 CVE-2014-0408
 	RESERVED
+	- openjdk-6 <not-affected> (Specific to MacOS X)
+	- openjdk-7 <not-affected> (Specific to MacOS X)
 CVE-2014-0407
 	RESERVED
 CVE-2014-0406
@@ -1999,6 +2021,8 @@
 	RESERVED
 CVE-2014-0403
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0402
 	RESERVED
 CVE-2014-0401
@@ -2031,16 +2055,22 @@
 	RESERVED
 CVE-2014-0387
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0386
 	RESERVED
 CVE-2014-0385
 	RESERVED
+	- openjdk-6 <not-affected> (Specific to MacOS X)
+	- openjdk-7 <not-affected> (Specific to MacOS X)
 CVE-2014-0384
 	RESERVED
 CVE-2014-0383
 	RESERVED
 CVE-2014-0382
 	RESERVED
+	- openjdk-6 <not-affected> (JavaFX not part of OpenJDK)
+	- openjdk-7 <not-affected> (JavaFX not part of OpenJDK)
 CVE-2014-0381
 	RESERVED
 CVE-2014-0380
@@ -2053,12 +2083,18 @@
 	RESERVED
 CVE-2014-0376
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0375
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-0374
 	RESERVED
 CVE-2014-0373
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0372
 	RESERVED
 CVE-2014-0371
@@ -2069,6 +2105,8 @@
 	RESERVED
 CVE-2014-0368
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2014-0367
 	RESERVED
 CVE-2014-0366
@@ -4674,6 +4712,7 @@
 	- pywbem <unfixed> (bug #732594)
 CVE-2013-6443
 	RESERVED
+	NOT-FOR-US: RedHat CloudForms Management Engine
 CVE-2013-6442
 	RESERVED
 CVE-2013-6441 [lxc: sshd template allow privilege escalation on host]
@@ -5940,40 +5979,63 @@
 	NOT-FOR-US: Tenable SecurityCenter
 CVE-2013-5910
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2013-5909
 	RESERVED
 CVE-2013-5908
 	RESERVED
 CVE-2013-5907
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
+	TODO: Might affect ICU
 CVE-2013-5906
 	RESERVED
+	- openjdk-6 <not-affected> (Installation performed differently for Linux distros)
+	- openjdk-7 <not-affected> (Installation performed differently for Linux distros)
 CVE-2013-5905
 	RESERVED
+	- openjdk-6 <not-affected> (Installation performed differently for Linux distros)
+	- openjdk-7 <not-affected> (Installation performed differently for Linux distros)
 CVE-2013-5904
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5903
 	REJECTED
 CVE-2013-5902
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5901
 	RESERVED
 CVE-2013-5900
 	RESERVED
 CVE-2013-5899
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5898
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5897
 	RESERVED
 CVE-2013-5896
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2013-5895
 	RESERVED
+	- openjdk-6 <not-affected> (JavaFX not part of OpenJDK)
+	- openjdk-7 <not-affected> (JavaFX not part of OpenJDK)
 CVE-2013-5894
 	RESERVED
 CVE-2013-5893
 	RESERVED
+	- openjdk-6 <not-affected> (Only affects OpenJDK 7)
+	- openjdk-7 <unfixed>
 CVE-2013-5892
 	RESERVED
 CVE-2013-5891
@@ -5982,16 +6044,24 @@
 	RESERVED
 CVE-2013-5889
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5888
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5887
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2013-5886
 	RESERVED
 CVE-2013-5885
 	RESERVED
 CVE-2013-5884
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2013-5883
 	RESERVED
 CVE-2013-5882
@@ -6004,6 +6074,8 @@
 	RESERVED
 CVE-2013-5878
 	RESERVED
+	- openjdk-6 <unfixed>
+	- openjdk-7 <unfixed>
 CVE-2013-5877
 	RESERVED
 CVE-2013-5876
@@ -6020,6 +6092,8 @@
 	RESERVED
 CVE-2013-5870
 	RESERVED
+	- openjdk-6 <not-affected> (JavaFX not part of OpenJDK)
+	- openjdk-7 <not-affected> (JavaFX not part of OpenJDK)
 CVE-2013-5869
 	RESERVED
 CVE-2013-5868




More information about the Secure-testing-commits mailing list