[Secure-testing-commits] r27731 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Jul 16 07:45:30 UTC 2014


Author: jmm
Date: 2014-07-16 07:45:30 +0000 (Wed, 16 Jul 2014)
New Revision: 27731

Modified:
   data/CVE/list
Log:
Java update


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-07-16 05:08:50 UTC (rev 27730)
+++ data/CVE/list	2014-07-16 07:45:30 UTC (rev 27731)
@@ -1053,29 +1053,28 @@
 CVE-2014-4268
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4267
 	RESERVED
 CVE-2014-4266
 	RESERVED
-	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-6 <not-affected> (Only affects Java 7/8)
+	- openjdk-7 <unfixed>
 CVE-2014-4265
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-4264
 	RESERVED
+	TODO: Possibly restricted to Oracle Java, needs further investigation
 CVE-2014-4263
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4262
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4261
 	RESERVED
 CVE-2014-4260
@@ -1105,8 +1104,7 @@
 CVE-2014-4252
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4251
 	RESERVED
 CVE-2014-4250
@@ -1117,6 +1115,8 @@
 	RESERVED
 CVE-2014-4247
 	RESERVED
+	- openjdk-6 <not-affected> (JavaFX not part of OpenJDK)
+	- openjdk-7 <not-affected> (JavaFX not part of OpenJDK)
 CVE-2014-4246
 	RESERVED
 CVE-2014-4245
@@ -1124,8 +1124,7 @@
 CVE-2014-4244
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4243
 	RESERVED
 	- mysql-5.5 <unfixed>
@@ -1179,6 +1178,8 @@
 	RESERVED
 CVE-2014-4227
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-4226
 	RESERVED
 CVE-2014-4225
@@ -1187,29 +1188,30 @@
 	RESERVED
 CVE-2014-4223
 	RESERVED
+	TODO: Possibly restricted to Oracle Java, needs further investigation
 CVE-2014-4222
 	RESERVED
 CVE-2014-4221
 	RESERVED
+	TODO: Possibly restricted to Oracle Java, needs further investigation
 CVE-2014-4220
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-4219
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4218
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4217
 	RESERVED
 CVE-2014-4216
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4215
 	RESERVED
 CVE-2014-4214
@@ -1230,10 +1232,11 @@
 CVE-2014-4209
 	RESERVED
 	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-7 <unfixed>
 CVE-2014-4208
 	RESERVED
+	- openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
+	- openjdk-7 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java)
 CVE-2014-4207
 	RESERVED
 	- mysql-5.5 <unfixed>
@@ -5541,9 +5544,8 @@
 	RESERVED
 CVE-2014-2490
 	RESERVED
-	- openjdk-6 6b32-1.13.4-1
-	- openjdk-7 <undetermined>
-	TODO: check openjdk-7
+	- openjdk-6 <not-affected> (Only affects Java 7/8)
+	- openjdk-7 <unfixed>
 CVE-2014-2489
 	RESERVED
 CVE-2014-2488
@@ -5563,6 +5565,7 @@
 	TODO: check might affect only 5.6 series
 CVE-2014-2483
 	RESERVED
+	TODO: Possibly restricted to Oracle Java, needs further investigation
 CVE-2014-2482
 	RESERVED
 CVE-2014-2481




More information about the Secure-testing-commits mailing list