[Secure-testing-commits] r26821 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun May 4 20:59:54 UTC 2014


Author: carnil
Date: 2014-05-04 20:59:54 +0000 (Sun, 04 May 2014)
New Revision: 26821

Modified:
   data/CVE/list
Log:
Update note for CVE-2014-2734, should be rejected probably

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-05-04 17:22:41 UTC (rev 26820)
+++ data/CVE/list	2014-05-04 20:59:54 UTC (rev 26821)
@@ -873,8 +873,8 @@
 CVE-2014-2735 (WinSCP before 5.5.3, when FTP with TLS is used, does not verify that ...)
 	NOT-FOR-US: WinSCP
 CVE-2014-2734 (The openssl extension in Ruby 2.x does not properly maintain the state ...)
+	NOTE: considered invalid and should be rejected, see https://gist.github.com/emboss/91696b56cd227c8a0c13
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1091156#c1
-	NOTE: https://gist.github.com/gdisneyleugers/10446549
 CVE-2014-2733 (Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a ...)
 	NOT-FOR-US: Siemens SINEMA
 CVE-2014-2732 (Multiple directory traversal vulnerabilities in the integrated web ...)




More information about the Secure-testing-commits mailing list