[Secure-testing-commits] r26844 - data/CVE

Henri Salo fgeek-guest at moszumanska.debian.org
Wed May 7 05:01:55 UTC 2014


Author: fgeek-guest
Date: 2014-05-07 05:01:55 +0000 (Wed, 07 May 2014)
New Revision: 26844

Modified:
   data/CVE/list
Log:
CVE-2014-3242,CVE-2014-3243/python-soappy bug, NFUs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-05-07 04:55:23 UTC (rev 26843)
+++ data/CVE/list	2014-05-07 05:01:55 UTC (rev 26844)
@@ -1,14 +1,12 @@
 CVE-2014-XXXX
 	- icecast2 <unfixed>
 	NOTE: https://trac.xiph.org/changeset/19137/
-CVE-2014-3243
-	- python-soappy <unfixed>
+CVE-2014-3243 [python-soappy: XXE]
+	- python-soappy <unfixed> (bug #747280)
 	NOTE: http://www.pnigos.com/?p=260
-	TODO: check
-CVE-2014-3242
-	- python-soappy <unfixed>
+CVE-2014-3242 [python-soappy: billion laughs DoS]
+	- python-soappy <unfixed> (bug #747280)
 	NOTE: http://www.pnigos.com/?p=260
-	TODO: check
 CVE-2014-3219
 	RESERVED
 CVE-2014-3218
@@ -703,9 +701,9 @@
 CVE-2014-2883
 	RESERVED
 CVE-2014-2882 (Unspecified vulnerability in the management GUI in Citrix NetScaler ...)
-	TODO: check
+	NOT-FOR-US: Citrix Netscaler
 CVE-2014-2881 (Unspecified vulnerability in the Diffie-Hellman key agreement ...)
-	TODO: check
+	NOT-FOR-US: Citrix Netscaler
 CVE-2014-2880 (Open redirect vulnerability in Oracle Identity Manager 11g R2 SP1 ...)
 	NOT-FOR-US: Oracle Identity Manager
 CVE-2014-2879 (Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL ...)
@@ -5513,6 +5511,7 @@
 	RESERVED
 CVE-2014-0930
 	RESERVED
+	NOT-FOR-US: IBM AIX
 CVE-2014-0929
 	RESERVED
 CVE-2014-0928




More information about the Secure-testing-commits mailing list