[Secure-testing-commits] r32084 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Feb 8 09:30:22 UTC 2015


Author: carnil
Date: 2015-02-08 09:30:22 +0000 (Sun, 08 Feb 2015)
New Revision: 32084

Modified:
   data/CVE/list
Log:
Add CVE-2-13-4235/shadow

Information in https://bugzilla.redhat.com/show_bug.cgi?id=884658 does
not contain information of the fix.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-02-08 09:30:11 UTC (rev 32083)
+++ data/CVE/list	2015-02-08 09:30:22 UTC (rev 32084)
@@ -37080,8 +37080,10 @@
 CVE-2013-4236 (VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged ...)
 	NOT-FOR-US: Red Hat vdms
 	NOTE: for incomplete fix for CVE-2013-0167
-CVE-2013-4235
+CVE-2013-4235 [TOCTOU race conditions by copying and removing directory trees]
 	RESERVED
+	- shadow <unfixed>
+	TODO: check
 CVE-2013-4234 (Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) ...)
 	{DSA-2751-1}
 	- libmodplug 1:0.8.8.4-4 (bug #719462)




More information about the Secure-testing-commits mailing list