[Secure-testing-commits] r29319 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Oct 8 09:24:46 UTC 2014


Author: carnil
Date: 2014-10-08 09:24:46 +0000 (Wed, 08 Oct 2014)
New Revision: 29319

Modified:
   data/CVE/list
Log:
CVE-2014-7206/apt does not affect squeeze, as apt-get changelog command not present

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-10-08 07:01:58 UTC (rev 29318)
+++ data/CVE/list	2014-10-08 09:24:46 UTC (rev 29319)
@@ -1334,6 +1334,7 @@
 CVE-2014-7206 [apt-get: Insecure temporary changelog handling]
 	RESERVED
 	- apt 1.0.9.2 (bug #763780)
+	[squeeze] - apt <not-affected> (apt changelog command and vulnerable code not present)
 	NOTE: mitigated by Linux kernel features in wheezy and up
 CVE-2013-7405
 	RESERVED




More information about the Secure-testing-commits mailing list