[Secure-testing-commits] r28870 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Sep 17 15:14:42 UTC 2014


Author: carnil
Date: 2014-09-17 15:14:42 +0000 (Wed, 17 Sep 2014)
New Revision: 28870

Modified:
   data/CVE/list
Log:
Update CVE-2013-1799 status, add TODO item

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-09-17 15:12:25 UTC (rev 28869)
+++ data/CVE/list	2014-09-17 15:14:42 UTC (rev 28870)
@@ -30609,8 +30609,9 @@
 CVE-2013-1800 (The crack gem 0.3.1 and earlier for Ruby does not properly restrict ...)
 	- ruby-crack 0.3.2-1
 CVE-2013-1799 (Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before ...)
-	- gnome-online-accounts 3.7.91-1
-	[wheezy] - gnome-online-accounts <not-affected> (vulnerable code introduced in a later version)
+	- gnome-online-accounts <undetermined>
+	NOTE: CVE for incomplete fix for CVE-2013-0240 in some versions
+	TODO: check if fix applied to Debian in 3.4.2-2 was incomplete
 CVE-2013-1798 (The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux ...)
 	{DSA-2668-1}
 	- linux 3.2.41-2




More information about the Secure-testing-commits mailing list