[Secure-testing-commits] r33639 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Apr 16 16:21:17 UTC 2015


Author: carnil
Date: 2015-04-16 16:21:17 +0000 (Thu, 16 Apr 2015)
New Revision: 33639

Modified:
   data/CVE/list
Log:
Add more information for net-snmp issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-04-16 14:09:58 UTC (rev 33638)
+++ data/CVE/list	2015-04-16 16:21:17 UTC (rev 33639)
@@ -638,6 +638,8 @@
 CVE-2015-XXXX [net-snmp snmp_pdu_parse() function incompletely initializaition vulnerability]
 	- net-snmp <unfixed>
 	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/04/13/1
+	NOTE: Upstream patch: https://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/
+	NOTE: https://sourceforge.net/p/net-snmp/bugs/2615/ (currently not public)
 	TODO: check
 CVE-2015-XXXX [read-only directory traversal in Etherpad frontend tests]
 	- etherpad-lite <itp> (bug #576998)




More information about the Secure-testing-commits mailing list