[Secure-testing-commits] r28721 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Sep 11 20:57:13 UTC 2014


Author: carnil
Date: 2014-09-11 20:57:13 +0000 (Thu, 11 Sep 2014)
New Revision: 28721

Modified:
   data/CVE/list
Log:
CVE-2013-7322/oath-toolkit fixed in unstable

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-09-11 20:47:17 UTC (rev 28720)
+++ data/CVE/list	2014-09-11 20:57:13 UTC (rev 28721)
@@ -10768,10 +10768,9 @@
 CVE-2012-6636 (The Android API before 17 does not properly restrict the ...)
 	NOT-FOR-US: Android
 CVE-2013-7322 (usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly ...)
-	- oath-toolkit <unfixed> (low; bug #738515)
+	- oath-toolkit 2.4.1-1 (low; bug #738515)
 	[wheezy] - oath-toolkit <no-dsa> (Minor issue)
 	NOTE: http://lists.nongnu.org/archive/html/oath-toolkit-help/2013-12/msg00000.html
-	NOTE: fixed in 2.4.1 upstream, http://lists.nongnu.org/archive/html/oath-toolkit-help/2014-02/msg00010.html
 CVE-2014-1939 (java/android/webkit/BrowserFrame.java in Android before 4.4 uses the ...)
 	NOT-FOR-US: Android Jelly Bean
 CVE-2014-1938 [insecure use of /tmp]




More information about the Secure-testing-commits mailing list