[Secure-testing-commits] r38193 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Dec 9 21:31:32 UTC 2015


Author: carnil
Date: 2015-12-09 21:31:32 +0000 (Wed, 09 Dec 2015)
New Revision: 38193

Modified:
   data/CVE/list
Log:
Add CVE-2015-5254/activemq, left TODO

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-12-09 21:28:13 UTC (rev 38192)
+++ data/CVE/list	2015-12-09 21:31:32 UTC (rev 38193)
@@ -9596,8 +9596,12 @@
 	NOT-FOR-US: Apache Cordova
 CVE-2015-5255 (Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before ...)
 	TODO: check
-CVE-2015-5254
+CVE-2015-5254 [Unsafe deserialization]
 	RESERVED
+	- activemq <unfixed>
+	NOTE: http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt
+	NOTE: https://issues.apache.org/jira/browse/AMQ-6013
+	TODO: check
 CVE-2015-5253 (The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before ...)
 	NOT-FOR-US: Apache CXF
 CVE-2015-5252




More information about the Secure-testing-commits mailing list