[Secure-testing-commits] r31793 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jan 28 18:34:15 UTC 2015


Author: carnil
Date: 2015-01-28 18:34:15 +0000 (Wed, 28 Jan 2015)
New Revision: 31793

Modified:
   data/CVE/list
Log:
Add CVE-2013-7423/glibc

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-01-28 18:31:42 UTC (rev 31792)
+++ data/CVE/list	2015-01-28 18:34:15 UTC (rev 31793)
@@ -151,6 +151,10 @@
 	NOTE: https://nodesecurity.io/advisories/marked_vbscript_injection
 	NOTE: https://github.com/chjj/marked/issues/492
 	NOTE: libv8 is not covered by security support
+CVE-2013-7423 [getaddrinfo() writes DNS queries to random file descriptors under high load]
+	- glibc <unfixed>
+	- eglibc <removed>
+	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=15946
 CVE-2013-7421 [Linux kernel crypto api unprivileged arbitrary module load]
 	RESERVED
 	- linux 3.16.7-ckt4-2




More information about the Secure-testing-commits mailing list