[Secure-testing-commits] r35730 - data/CVE

Luca Bruno lucab at moszumanska.debian.org
Mon Jul 27 16:12:06 UTC 2015


Author: lucab
Date: 2015-07-27 16:12:06 +0000 (Mon, 27 Jul 2015)
New Revision: 35730

Modified:
   data/CVE/list
Log:
shibboleth-sp advisory has been updated, now tracked as CVE-2015-0851

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-07-27 15:59:00 UTC (rev 35729)
+++ data/CVE/list	2015-07-27 16:12:06 UTC (rev 35730)
@@ -4,11 +4,6 @@
 	[wheezy] - chromium-browser <end-of-life>
 	[squeeze] - chromium-browser <end-of-life>
 	NOTE: http://crbug.com/497588
-CVE-2015-XXXX [Shibboleth SP software crashes on well-formed but invalid XML]
-	- xmltooling <unfixed>
-	NOTE: http://shibboleth.net/community/advisories/secadv_20150721.txt
-	NOTE: The upstream advisory lists the wrong CVE
-	NOTE: opensaml2 will need binNMUs
 CVE-2015-5621
 	RESERVED
 CVE-2015-5620
@@ -14029,8 +14024,11 @@
 	RESERVED
 CVE-2015-0852
 	RESERVED
-CVE-2015-0851
-	RESERVED
+CVE-2015-0851 [Shibboleth SP software crashes on well-formed but invalid XML]
+	- xmltooling <unfixed>
+	NOTE: http://shibboleth.net/community/advisories/secadv_20150721.txt
+	NOTE: Initial advisory was listing the wrong CVE, updated later
+	NOTE: opensaml2 will need binNMUs
 CVE-2015-0850 (The Git plugin for FusionForge before 6.0rc4 allows remote attackers ...)
 	{DSA-3275-1}
 	- fusionforge 6.0~rc4-1




More information about the Secure-testing-commits mailing list