[Secure-testing-commits] r35618 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jul 22 14:26:57 UTC 2015


Author: carnil
Date: 2015-07-22 14:26:57 +0000 (Wed, 22 Jul 2015)
New Revision: 35618

Modified:
   data/CVE/list
Log:
Update entry for CVE-2015-5400/squid

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-07-22 11:25:09 UTC (rev 35617)
+++ data/CVE/list	2015-07-22 14:26:57 UTC (rev 35618)
@@ -664,13 +664,15 @@
 	NOTE: http://trac.roundcube.net/ticket/1490417
 CVE-2015-5400 [Do not blindly forward cache peer CONNECT responses]
 	RESERVED
-	- squid <not-affected> (Vulnerable code not present)
+	- squid <removed>
 	- squid3 <unfixed> (bug #793128)
 	NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13856.patch (3.5)
 	NOTE: http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13225.patch (3.4)
 	NOTE: http://www.squid-cache.org/Advisories/SQUID-2015_2.txt
 	NOTE: http://www.openwall.com/lists/oss-security/2015/07/06/8
 	NOTE: In squeeze's squid3 the code is structured differently but the bug still appears to be present.
+	NOTE: For squid 2.x all versions are affected, cf. comment by upstream in
+	NOTE: https://bugs.debian.org/793128#12
 CVE-2015-5380 (The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in ...)
 	- nodejs <not-affected> (Only affects 0.12.x)
 	NOTE: http://www.openwall.com/lists/oss-security/2015/07/05/1




More information about the Secure-testing-commits mailing list