[Secure-testing-commits] r38311 - data/CVE

Raphaël Hertzog hertzog at moszumanska.debian.org
Tue Dec 15 09:16:36 UTC 2015


Author: hertzog
Date: 2015-12-15 09:16:36 +0000 (Tue, 15 Dec 2015)
New Revision: 38311

Modified:
   data/CVE/list
Log:
Mark CVE-2015-7545/git as not affecting squeeze

The vulnerability relies on the availability of git-remote-ext which
was not yet introduced in git 1.7.2 (it has been introduced in 1.7.4
apparently).

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-12-15 09:10:17 UTC (rev 38310)
+++ data/CVE/list	2015-12-15 09:16:36 UTC (rev 38311)
@@ -3874,6 +3874,7 @@
 CVE-2015-7545 [arbitrary code execution issues via URLs]
 	RESERVED
 	- git 1:2.6.1-1
+	[squeeze] - git <not-affected> (git 1.7.2 did not have git-remote-ext yet)
 	NOTE: http://www.openwall.com/lists/oss-security/2015/10/06/1
 CVE-2015-7747 [When changing both sample format and number of channels, data gets corrupted; if new sample format smaller than old, possible buffer overflow]
 	RESERVED




More information about the Secure-testing-commits mailing list