[Secure-testing-commits] r29777 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Nov 1 10:30:22 UTC 2014


Author: carnil
Date: 2014-11-01 10:30:22 +0000 (Sat, 01 Nov 2014)
New Revision: 29777

Modified:
   data/CVE/list
Log:
Add CVE-2014-7816, undertow itp'ed but not affecting Debian

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-10-31 22:28:09 UTC (rev 29776)
+++ data/CVE/list	2014-11-01 10:30:22 UTC (rev 29777)
@@ -1670,8 +1670,11 @@
 	TODO: check
 CVE-2014-7817
 	RESERVED
-CVE-2014-7816
+CVE-2014-7816 [information disclosure via directory traversal]
 	RESERVED
+	- undertow <itp> (bug #767001)
+	NOTE: When this enters the archive it should be marked straight as not-affected
+	NOTE: as the issue is only when undertow is running on Windows.
 CVE-2014-7815 [insufficient bits_per_pixel from the client sanitization]
 	RESERVED
 	- qemu <unfixed>




More information about the Secure-testing-commits mailing list