[Secure-testing-commits] r31837 - data/CVE

Ben Hutchings benh at moszumanska.debian.org
Fri Jan 30 00:02:46 UTC 2015


Author: benh
Date: 2015-01-30 00:02:46 +0000 (Fri, 30 Jan 2015)
New Revision: 31837

Modified:
   data/CVE/list
Log:
Add details for CVE-2013-7423

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-01-29 21:55:18 UTC (rev 31836)
+++ data/CVE/list	2015-01-30 00:02:46 UTC (rev 31837)
@@ -311,9 +311,12 @@
 	NOTE: libv8 is not covered by security support
 CVE-2013-7423 [getaddrinfo() writes DNS queries to random file descriptors under high load]
 	RESERVED
-	- glibc <unfixed>
+	- glibc 2.19-1 (bug #722075)
 	- eglibc <removed>
-	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=15946
+	[wheezy] - eglibc <unfixed>
+	[squeeze] - eglibc <unfixed>
+	NOTE: Upstream report: https://sourceware.org/bugzilla/show_bug.cgi?id=15946
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/01/28/16
 CVE-2013-7421 [Linux kernel crypto api unprivileged arbitrary module load]
 	RESERVED
 	- linux 3.16.7-ckt4-2




More information about the Secure-testing-commits mailing list