[Secure-testing-commits] r26328 - data/CVE

Michael Gilbert mgilbert at moszumanska.debian.org
Fri Mar 28 23:02:15 UTC 2014


Author: mgilbert
Date: 2014-03-28 23:02:15 +0000 (Fri, 28 Mar 2014)
New Revision: 26328

Modified:
   data/CVE/list
Log:
systemd issue is unimportant

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-03-28 22:43:49 UTC (rev 26327)
+++ data/CVE/list	2014-03-28 23:02:15 UTC (rev 26328)
@@ -13568,9 +13568,10 @@
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=859104
 	NOTE: http://cgit.freedesktop.org/systemd/systemd/commit/?id=1dfa7e79a60de680086b1d93fcc3629b463f58bd
 CVE-2013-4392 (systemd, when updating file permissions, allows local users to change ...)
-	- systemd <unfixed> (low; bug #725357)
+	- systemd <unfixed> (unimportant; bug #725357)
 	[wheezy] - systemd <not-affected> (/etc/tmpfiles.d not supported in Wheezy)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=859060
+	NOTE: only relevant to systems running systemd along with selinux
 CVE-2013-4391 (Integer overflow in the valid_user_field function in ...)
 	{DSA-2777-1}
 	- systemd 204-5 (bug #725357)
@@ -14138,7 +14139,7 @@
 	- libmodplug 1:0.8.8.4-4 (bug #719462)
 CVE-2013-4232 (Use-after-free vulnerability in the t2p_readwrite_pdf_image function ...)
 	{DSA-2744-1}
-	- tiff 4.0.3-2 (bug #719303)
+	- tiff 4.0.3-2 (low; bug #719303)
 	- tiff3 <not-affected> (The tiff3 source package doesn't build the TIFF tools)
 CVE-2013-4231 (Multiple buffer overflows in libtiff before 4.0.3 allow remote ...)
 	{DSA-2744-1}




More information about the Secure-testing-commits mailing list