[Secure-testing-commits] r35530 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Fri Jul 17 14:35:49 UTC 2015
Author: carnil
Date: 2015-07-17 14:35:49 +0000 (Fri, 17 Jul 2015)
New Revision: 35530
Modified:
data/CVE/list
Log:
One CVE assigned for squid, one pending
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-07-17 13:27:39 UTC (rev 35529)
+++ data/CVE/list 2015-07-17 14:35:49 UTC (rev 35530)
@@ -285,8 +285,6 @@
RESERVED
CVE-2015-5401
RESERVED
-CVE-2015-5400
- RESERVED
CVE-2015-5399
RESERVED
CVE-2015-5398
@@ -424,14 +422,14 @@
NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13849.patch
NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/07/06/8
NOTE: Only affects custom builds with --enable-ssl (disabled for license purposes in Debian)
-CVE-2015-XXXX [Do not blindly forward cache peer CONNECT responses]
+CVE-2015-5400 [Do not blindly forward cache peer CONNECT responses]
- squid <removed>
- squid3 <unfixed>
[squeeze] - squid <not-affected> (Vulnerable code not present)
NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13856.patch (3.5)
NOTE: http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13225.patch (3.4)
NOTE: http://www.squid-cache.org/Advisories/SQUID-2015_2.txt
- NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/07/06/8
+ NOTE: http://www.openwall.com/lists/oss-security/2015/07/06/8
NOTE: In squeeze's squid3 the code is structured differently but the bug still appears to be present.
TODO: check
CVE-2015-5380 (The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in ...)
More information about the Secure-testing-commits
mailing list