[Secure-testing-commits] r33663 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Fri Apr 17 20:48:48 UTC 2015
Author: carnil
Date: 2015-04-17 20:48:48 +0000 (Fri, 17 Apr 2015)
New Revision: 33663
Modified:
data/CVE/list
Log:
CVE-2015-3330 assigned for php5
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-04-17 20:46:16 UTC (rev 33662)
+++ data/CVE/list 2015-04-17 20:48:48 UTC (rev 33663)
@@ -5,12 +5,13 @@
NOTE: https://groups.google.com/forum/#!topic/linux.kernel/HnegnbXk0Vs
NOTE: Proposed fixes: http://www.spinics.net/lists/linux-containers/msg30786.html
NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/04/17/4
-CVE-2015-XXXX [PHP potential remote code execution with apache 2.4 apache2handler]
+CVE-2015-3330 [PHP potential remote code execution with apache 2.4 apache2handler]
- php5 <unfixed>
NOTE: https://bugs.php.net/bug.php?id=69218
NOTE: https://bugs.php.net/bug.php?id=68486
NOTE: Fixed by: http://git.php.net/?p=php-src.git;a=commit;h=809610f5ea38a83b284e1125d1fff129bdd615e7
- NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/04/17/3
+ NOTE: http://www.openwall.com/lists/oss-security/2015/04/17/3
+ NOTE: For details on scope of the CVE assignment: http://www.openwall.com/lists/oss-security/2015/04/17/7
CVE-2015-3319 (Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly ...)
TODO: check
CVE-2015-3318
More information about the Secure-testing-commits
mailing list