[Secure-testing-commits] r25254 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Fri Jan 17 11:51:35 UTC 2014


Author: jmm
Date: 2014-01-17 11:51:35 +0000 (Fri, 17 Jan 2014)
New Revision: 25254

Modified:
   data/CVE/list
Log:
libvirt n/a for stable/oldstable


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-01-17 10:15:45 UTC (rev 25253)
+++ data/CVE/list	2014-01-17 11:51:35 UTC (rev 25254)
@@ -115,6 +115,7 @@
 CVE-2014-1410
 	RESERVED
 CVE-2013-7294 (The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in ...)
+	NOT-FOR-US: libreswan, strongSwan not affected (pluto never supported ikev2)
 CVE-2013-7293 (The ASUS WL-330NUL router has a configuration process that relies on ...)
 	TODO: check
 CVE-2013-XXXX [DoS]
@@ -3642,6 +3643,8 @@
 CVE-2014-0028 [event registration bypasses domain:getattr ACL]
 	RESERVED
 	- libvirt <unfixed>
+	[squeeze] - libvirt <not-affected> (Introduced in 1.1.1)
+	[wheezy] - libvirt <not-affected> (Introduced in 1.1.1)
 	NOTE: https://www.redhat.com/archives/libvir-list/2014-January/msg00684.html
 	TODO: check
 CVE-2014-0027




More information about the Secure-testing-commits mailing list