[Secure-testing-commits] r34916 - data/CVE

Guido Guenther agx at moszumanska.debian.org
Fri Jun 12 16:27:16 UTC 2015


Author: agx
Date: 2015-06-12 16:27:16 +0000 (Fri, 12 Jun 2015)
New Revision: 34916

Modified:
   data/CVE/list
Log:
Mark CVE-2015-1788/openssl as not affected in squeeze

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-06-12 15:46:23 UTC (rev 34915)
+++ data/CVE/list	2015-06-12 16:27:16 UTC (rev 34916)
@@ -7316,6 +7316,7 @@
 CVE-2015-1788 [Malformed ECParameters causes infinite loop]
 	RESERVED
 	- openssl 1.0.2b-1
+	[squeeze] - openssl <not-affected> (Vulnerable code got introduced post 1.0.0)
 	NOTE: http://openssl.org/news/secadv_20150611.txt
 CVE-2015-1787 (The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL ...)
 	- openssl <not-affected> (Vulnerable version never in unstable)




More information about the Secure-testing-commits mailing list