[Secure-testing-commits] r33492 - data/CVE

David Prévot taffit at moszumanska.debian.org
Fri Apr 10 17:01:57 UTC 2015


Author: taffit
Date: 2015-04-10 17:01:57 +0000 (Fri, 10 Apr 2015)
New Revision: 33492

Modified:
   data/CVE/list
Log:
CVE-2015-0270/zendframework assigned

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-04-10 17:01:47 UTC (rev 33491)
+++ data/CVE/list	2015-04-10 17:01:57 UTC (rev 33492)
@@ -9713,8 +9713,12 @@
 	RESERVED
 CVE-2015-0271 (The log-viewing function in the Red Hat redhat-access-plugin before ...)
 	- horizon <not-affected> (RedHat-specific plugin)
-CVE-2015-0270
+CVE-2015-0270 [Potential SQL injection in PostgreSQL Zend\Db adapter]
 	RESERVED
+	- zendframework <not-affected> (the vulnerability was introduced in the 2 series)
+	- php-zend-db <itp> (bug #780422)
+	NOTE: php-zend-db fixed in NEW (2.3.7-1)
+	NOTE: http://framework.zend.com/security/advisory/ZF2015-02
 CVE-2015-0269
 	RESERVED
 CVE-2015-0268 (The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when ...)




More information about the Secure-testing-commits mailing list