[Secure-testing-commits] r25366 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jan 25 13:26:32 UTC 2014


Author: carnil
Date: 2014-01-25 13:26:32 +0000 (Sat, 25 Jan 2014)
New Revision: 25366

Modified:
   data/CVE/list
Log:
Update information for CVE-2013-7298

By trying to use parse_url with double %% in wheezy with
cxxtools/2.1.1-1 not reproducible to produce the segfault, whereas it is
for 2.2-1, fixed by 2.2.1-1.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-01-24 22:20:54 UTC (rev 25365)
+++ data/CVE/list	2014-01-25 13:26:32 UTC (rev 25366)
@@ -539,8 +539,8 @@
 CVE-2013-7298 [cxxtools: denial of service]
 	RESERVED
 	- cxxtools 2.2.1-1 (low; bug #735880)
-	[wheezy] - cxxtools <no-dsa> (Minor issue)
-	[squeeze] - cxxtools <no-dsa> (Minor issue)
+	[wheezy] - cxxtools <not-affected> (Issue not present, introduced in v2.2)
+	[squeeze] - cxxtools <not-affected> (Issue not present, introduced in v2.2)
 CVE-2013-7296 [DoS]
 	RESERVED
 	- poppler <not-affected> (Introduced in a3cee0e7e9dd292c70fe1fa19a92e70bbc1e1b41)




More information about the Secure-testing-commits mailing list