[Secure-testing-commits] r28951 - data/CVE

Raphaël Hertzog hertzog at moszumanska.debian.org
Mon Sep 22 09:45:48 UTC 2014


Author: hertzog
Date: 2014-09-22 09:45:48 +0000 (Mon, 22 Sep 2014)
New Revision: 28951

Modified:
   data/CVE/list
Log:
Update infos for CVE-2014-6610/asterisk

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-09-22 09:26:19 UTC (rev 28950)
+++ data/CVE/list	2014-09-22 09:45:48 UTC (rev 28951)
@@ -10,8 +10,11 @@
 	[wheezy] - twisted <not-affected> (Only affects 14.0 series)
 	[squeeze] - twisted <not-affected> (Only affects 14.0 series)
 CVE-2014-6610 [Remote crash when handling out of call message in certain dialplan configurations]
-	- asterisk <unfixed> (bug #762164)
+	- asterisk 1:11.12.1~dfsg-1 (medium; bug #762164)
+	[squeeze] - asterix <not-affected>
 	NOTE: http://downloads.asterisk.org/pub/security/AST-2014-010.html
+	NOTE: http://downloads.asterisk.org/pub/security/AST-2014-010-11.diff applies on 1:1.8.13.1~dfsg1-3+deb7u3
+	NOTE: Squeeze version doesn't have res/res_fax_spandsp.c with the problem.
 CVE-2014-6607
 	NOT-FOR-US: M/Monit
 CVE-2014-6601




More information about the Secure-testing-commits mailing list