[Secure-testing-commits] r31833 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Jan 29 20:35:41 UTC 2015


Author: carnil
Date: 2015-01-29 20:35:41 +0000 (Thu, 29 Jan 2015)
New Revision: 31833

Modified:
   data/CVE/list
Log:
Add temporary item for xchat and hexchat

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-01-29 19:46:46 UTC (rev 31832)
+++ data/CVE/list	2015-01-29 20:35:41 UTC (rev 31833)
@@ -13,6 +13,12 @@
        [squeeze] - asterisk <not-affected> (Only affects 12.x and 13.x)
 	NOTE: https://issues.asterisk.org/jira/browse/ASTERISK-24666
 	NOTE: http://downloads.digium.com/pub/security/AST-2015-001.html
+CVE-2013-XXXX [don't properly verify SSL certificates]
+	- xchat <unfixed>
+	- hexchat <unfixed>
+	NOTE: https://github.com/hexchat/hexchat/issues/524
+	NOTE: https://github.com/hexchat/hexchat/commit/c9b63f7f9be01692b03fa15275135a4910a7e02d
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/01/29/23
 CVE-2013-7424 [Invalid-free when using getaddrinfo()]
 	- glibc 2.19-4
 	- eglibc 2.17-2




More information about the Secure-testing-commits mailing list