[Secure-testing-commits] r33359 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Fri Apr 3 12:43:33 UTC 2015


Author: jmm
Date: 2015-04-03 12:43:32 +0000 (Fri, 03 Apr 2015)
New Revision: 33359

Modified:
   data/CVE/list
Log:
linux n/a
php no-dsa


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-04-03 12:34:27 UTC (rev 33358)
+++ data/CVE/list	2015-04-03 12:43:32 UTC (rev 33359)
@@ -6060,10 +6060,9 @@
 	NOTE: https://bugzilla.novell.com/show_bug.cgi?id=901643
 CVE-2015-0777
 	RESERVED
-	- linux <undetermined>
-	- linux-2.6 <removed>
+	- linux <not-affected> (Addon Xen usbback patch not present)
+	- linux-2.6 <not-affected> (Addon Xen usbback patch not present)
 	NOTE: https://bugzilla.novell.com/show_bug.cgi?id=917830
-	TODO: verify, only SuSE?
 CVE-2015-0776
 	RESERVED
 CVE-2015-0775
@@ -12183,6 +12182,8 @@
 	NOTE: netcf needs to use.
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1172176#c3
 	NOTE: https://www.redhat.com/archives/augeas-devel/2014-December/msg00000.html
+	NOTE: The affected code is only in drv_redhat.c and drv_suse.c, maybe
+	NOTE: Debian isn't affected after all, need further investigation
 CVE-2014-8118 (Integer overflow in RPM 4.12 and earlier allows remote attackers to ...)
 	{DSA-3129-1 DLA-140-1}
 	- rpm 4.11.3-1.1 (bug #773101)
@@ -35010,6 +35011,7 @@
 	RESERVED
 CVE-2013-6501 (The default soap.wsdl_cache_dir setting in (1) php.ini-production and ...)
 	- php5 <unfixed>
+	[jessie] - php5 <no-dsa> (Minor issue, can be fixed in a future DSA)
 	[wheezy] - php5 <no-dsa> (Minor issue, can be fixed in a future DSA)
 CVE-2013-6500
 	REJECTED




More information about the Secure-testing-commits mailing list