[Secure-testing-commits] r28677 - data/CVE
Joey Hess
joeyh at moszumanska.debian.org
Tue Sep 9 21:14:12 UTC 2014
Author: joeyh
Date: 2014-09-09 21:14:12 +0000 (Tue, 09 Sep 2014)
New Revision: 28677
Modified:
data/CVE/list
Log:
automatic update
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2014-09-09 20:27:54 UTC (rev 28676)
+++ data/CVE/list 2014-09-09 21:14:12 UTC (rev 28677)
@@ -6140,7 +6140,7 @@
CVE-2014-3588
RESERVED
CVE-2014-3587 (Integer overflow in the cdf_read_property_info function in cdf.c in ...)
- {DSA-3008-1}
+ {DSA-3021-1 DSA-3008-1}
- php5 5.6.0+dfsg-1
NOTE: https://bugs.php.net/bug.php?id=67716
NOTE: https://github.com/php/php-src/commit/7ba1409a1aee5925180de546057ddd84ff267947
@@ -6285,7 +6285,7 @@
CVE-2014-3539
RESERVED
CVE-2014-3538 (file before 5.19 does not properly restrict the amount of data read ...)
- {DSA-3008-1}
+ {DSA-3021-1 DSA-3008-1}
- file 1:5.19-1
NOTE: fix relies on the new feature that introduced regex/<length> syntax, might be too intrusive for backporting.
- php5 5.6.0~rc4+dfsg-1
@@ -6450,7 +6450,7 @@
- netty <not-affected> (Introduced in 3.9.0)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1107983 says only affects 3.9.0 and 3.9.1
CVE-2014-3487 (The cdf_read_property_info function in file before 5.19, as used in ...)
- {DSA-2974-1 DLA-27-1}
+ {DSA-3021-1 DSA-2974-1 DLA-27-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/93e063ee374b6a75729df9e7201fb511e47e259d
@@ -6485,7 +6485,7 @@
CVE-2014-3481 (org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat ...)
- jbossas4 <not-affected> (Only builds a few libraries, not the full application server, #581226)
CVE-2014-3480 (The cdf_count_chain function in cdf.c in file before 5.19, as used in ...)
- {DSA-2974-1 DLA-27-1 DLA-0018-1}
+ {DSA-3021-1 DSA-2974-1 DLA-27-1 DLA-0018-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/40bade80cbe2af1d0b2cd0420cebd5d5905a2382
@@ -6493,7 +6493,7 @@
[squeeze] - php5 5.3.3-7+squeeze21
NOTE: http://bugs.php.net/bug.php?id=67412
CVE-2014-3479 (The cdf_check_stream_offset function in cdf.c in file before 5.19, as ...)
- {DSA-2974-1 DLA-27-1}
+ {DSA-3021-1 DSA-2974-1 DLA-27-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/36fadd29849b8087af9f4586f89dbf74ea45be67
@@ -6501,7 +6501,7 @@
[squeeze] - php5 <not-affected> (Vulnerable code was introduced later)
NOTE: https://bugs.php.net/bug.php?id=67411
CVE-2014-3478 (Buffer overflow in the mconvert function in softmagic.c in file before ...)
- {DSA-2974-1 DLA-27-1}
+ {DSA-3021-1 DSA-2974-1 DLA-27-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/27a14bc7ba285a0a5ebfdb55e54001aa11932b08
@@ -15691,7 +15691,7 @@
[wheezy] - samba <not-affected> (AD feature not present)
NOTE: AD-related packages removed from src:samba4 in 4.0.0~beta2+dfsg1-3.2+deb7u2
CVE-2014-0238 (The cdf_read_property_info function in cdf.c in the Fileinfo component ...)
- {DSA-2943-1 DLA-27-1}
+ {DSA-3021-1 DSA-2943-1 DLA-27-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/f97486ef5dc3e8735440edc4fc8808c63e1a3ef0
@@ -15699,7 +15699,7 @@
[squeeze] - php5 <no-dsa> (Minor issue, can be fixed along with a future DSA)
NOTE: https://bugs.php.net/bug.php?id=67327
CVE-2014-0237 (The cdf_unpack_summary_info function in cdf.c in the Fileinfo ...)
- {DSA-2943-1 DLA-27-1}
+ {DSA-3021-1 DSA-2943-1 DLA-27-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: https://github.com/file/file/commit/b8acc83781d5a24cc5101e525d15efe0482c280d
@@ -15813,7 +15813,7 @@
RESERVED
- foreman <itp> (bug #663101)
CVE-2014-0207 (The cdf_read_short_sector function in cdf.c in file before 5.19, as ...)
- {DSA-2974-1 DLA-27-1 DLA-0018-1}
+ {DSA-3021-1 DSA-2974-1 DLA-27-1 DLA-0018-1}
- file 1:5.19-1
[squeeze] - file 5.04-5+squeeze6
NOTE: fixed as part of https://github.com/file/file/commit/6d209c1c489457397a5763bca4b28e43aac90391#diff-0
More information about the Secure-testing-commits
mailing list