[Secure-testing-commits] r32204 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Thu Feb 12 22:34:05 UTC 2015


Author: jmm
Date: 2015-02-12 22:34:05 +0000 (Thu, 12 Feb 2015)
New Revision: 32204

Modified:
   data/CVE/list
Log:
bugs for libarchive, byzanz, facter


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-02-12 22:24:41 UTC (rev 32203)
+++ data/CVE/list	2015-02-12 22:34:05 UTC (rev 32204)
@@ -384,7 +384,7 @@
 	NOTE: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=20e1db19db5d6b9e4e83021595eab0dc8f107bef (3.6)
 	NOTE: Also fixed in 3.2.30
 CVE-2012-XXXX [Out-of heap-based buffer write in GIF encoder]
-	- byzanz <unfixed>
+	- byzanz <unfixed> (low; bug #778261)
 	[squeeze] - byzanz <no-dsa> (Minor issue)
 	[wheezy] - byzanz <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=852481
@@ -517,7 +517,7 @@
 	TODO: check, possibly only 1.3.0-1.3.7 and 1.4.0-1.4.2
 CVE-2015-1426
 	RESERVED
-	- facter <unfixed>
+	- facter <unfixed> (bug #778265)
 CVE-2015-1493 [MDL-48980 Security: Always clean the result  from min_get_slash_argument]
 	RESERVED
 	- moodle 2.7.5+dfsg-1
@@ -1733,7 +1733,7 @@
 CVE-2015-1051 (Open redirect vulnerability in the Context UI module in the Context ...)
 	NOT-FOR-US: Drupal extension drupal7-context
 CVE-2015-XXXX [directory traversal in bsdcpio]
-	- libarchive <unfixed>
+	- libarchive <unfixed> (bug #778266)
 	NOTE: http://www.openwall.com/lists/oss-security/2015/01/16/7
 CVE-2015-1200 (Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for ...)
 	- pxz 4.999.99~beta3+git659fc9b-3 (bug #775306)




More information about the Secure-testing-commits mailing list