[Secure-testing-commits] r28834 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Sep 16 18:39:09 UTC 2014


Author: carnil
Date: 2014-09-16 18:39:09 +0000 (Tue, 16 Sep 2014)
New Revision: 28834

Modified:
   data/CVE/list
Log:
Add note for cyassl CVEs which should be addressed in 3.2.0 upstream

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-09-16 18:06:11 UTC (rev 28833)
+++ data/CVE/list	2014-09-16 18:39:09 UTC (rev 28834)
@@ -8424,15 +8424,19 @@
 CVE-2014-2904
 	RESERVED
 	- cyassl <unfixed>
+	NOTE: according to maintainer addressed in 3.2.0 upstream
 CVE-2014-2903
 	RESERVED
 	- cyassl <unfixed>
+	NOTE: according to maintainer addressed in 3.2.0 upstream
 CVE-2014-2902
 	RESERVED
 	- cyassl <unfixed>
+	NOTE: according to maintainer addressed in 3.2.0 upstream
 CVE-2014-2901
 	RESERVED
 	- cyassl <unfixed>
+	NOTE: according to maintainer addressed in 3.2.0 upstream
 CVE-2014-2900 (wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 ...)
 	- cyassl 2.9.4+dfsg-1
 CVE-2014-2899 (wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial ...)




More information about the Secure-testing-commits mailing list