[Secure-testing-commits] r31537 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Jan 19 18:43:24 UTC 2015


Author: carnil
Date: 2015-01-19 18:43:24 +0000 (Mon, 19 Jan 2015)
New Revision: 31537

Modified:
   data/CVE/list
Log:
Add CVE-2014-8152/libxml-security-java

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-01-19 18:39:57 UTC (rev 31536)
+++ data/CVE/list	2015-01-19 18:43:24 UTC (rev 31537)
@@ -6752,8 +6752,11 @@
 	NOTE: https://git.gnome.org/browse/vala/commit/?id=3092537db65887e24a3d3e87a27caf9c5295e4f7
 CVE-2014-8153 (The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using ...)
 	- neutron <not-affected> (Affects neutron 2014.2 up to 2014.2.1)
-CVE-2014-8152
+CVE-2014-8152 [treaming XML Signature verification failure]
 	RESERVED
+	- libxml-security-java <not-affected> (streaming XML Signature support introduced in 2.0.0)
+	NOTE: http://svn.apache.org/viewvc?view=revision&revision=1634334
+	NOTE: http://santuario.apache.org/secadv.data/CVE-2014-8152.txt.asc
 CVE-2014-8151 (The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in ...)
 	- curl <not-affected> (Only relevant when building with darwinssl/Mac OS X)
 	NOTE: http://curl.haxx.se/docs/adv_20150108A.html




More information about the Secure-testing-commits mailing list