[Secure-testing-commits] r31276 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sun Jan 11 20:34:36 UTC 2015
Author: carnil
Date: 2015-01-11 20:34:36 +0000 (Sun, 11 Jan 2015)
New Revision: 31276
Modified:
data/CVE/list
Log:
Add references to pending CVE request since otherwise we lose track of what is already requested
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-01-11 20:27:51 UTC (rev 31275)
+++ data/CVE/list 2015-01-11 20:34:36 UTC (rev 31276)
@@ -1177,6 +1177,7 @@
- python-imaging <removed>
NOTE: https://github.com/python-pillow/Pillow/commit/b3e09122e527ae554eb590741bbd7611d5710e40
NOTE: http://pillow.readthedocs.org/releasenotes/2.7.0.html#png-text-chunk-size-limits
+ NOTE: CVE Request: https://marc.info/?l=oss-security&m=142055745031061&w=2
TODO: check
CVE-2014-9584 (The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the ...)
- linux <unfixed>
@@ -1187,6 +1188,7 @@
CVE-2015-XXXX [HTTP TRACE DoS]
- trafficserver <unfixed>
[wheezy] - trafficserver <not-affected> (Only affects 5.x)
+ NOTE: CVE Request: https://marc.info/?l=oss-security&m=142053376523895&w=2
NOTE: https://issues.apache.org/jira/browse/TS-3223 (fixed in 5.1.2)
NOTE: https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;a=commit;h=8b5f0345dade6b2822d9b52c8ad12e63011a5c12
NOTE: notes: https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12327089&styleName=Html&projectId=12310963
@@ -1239,11 +1241,13 @@
- libav <unfixed>
NOTE: Patch in http://www.openwall.com/lists/oss-security/2015/01/04/10 seem to apply for libav
NOTE: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=169065fbfb3da1ab776379c333aebc54bb1f1bc4
+ NOTE: CVE Request: https://marc.info/?l=oss-security&m=142034472712971&w=2
CVE-2015-XXXX [Zoo directory traversal]
- zoo <unfixed> (low; bug #774453)
[jessie] - zoo <no-dsa> (Minor issue)
[wheezy] - zoo <no-dsa> (Minor issue)
[squeeze] - zoo <no-dsa> (Minor issue)
+ NOTE: CVE Request: https://marc.info/?l=oss-security&m=142024361327375&w=2
CVE-2015-XXXX [buffer over-read]
- arc <unfixed> (low; bug #774439)
[jessie] - arc <no-dsa> (Minor issue)
More information about the Secure-testing-commits
mailing list