[Secure-testing-commits] r35422 - in data: . CVE

Guido Guenther agx at moszumanska.debian.org
Fri Jul 10 15:13:00 UTC 2015


Author: agx
Date: 2015-07-10 15:13:00 +0000 (Fri, 10 Jul 2015)
New Revision: 35422

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
policykit-1/squeeze affected by CVE-2015-3255 but not CVE-2015-3256

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-07-10 15:12:52 UTC (rev 35421)
+++ data/CVE/list	2015-07-10 15:13:00 UTC (rev 35422)
@@ -5501,7 +5501,9 @@
 	RESERVED
 	[experimental] - policykit-1 0.113-1
 	- policykit-1 <unfixed>
+	[squeeze] - policykit-1 <not-affected> (Vulnerable code to process JavaScript rules not present)
 	NOTE: https://bugs.freedesktop.org/show_bug.cgi?id=69501
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=910262#c75
 CVE-2015-3255
 	RESERVED
 	[experimental] - policykit-1 0.113-1

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2015-07-10 15:12:52 UTC (rev 35421)
+++ data/dla-needed.txt	2015-07-10 15:13:00 UTC (rev 35422)
@@ -57,6 +57,9 @@
 --
 python-django
 --
+--
+policykit-1
+--
 pound (Guido Günther)
 --
 roundup (Thorsten Alteholz)




More information about the Secure-testing-commits mailing list