[Secure-testing-commits] r35057 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jun 20 09:24:09 UTC 2015


Author: carnil
Date: 2015-06-20 09:24:07 +0000 (Sat, 20 Jun 2015)
New Revision: 35057

Modified:
   data/CVE/list
Log:
Update information for policykit issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-06-20 09:16:10 UTC (rev 35056)
+++ data/CVE/list	2015-06-20 09:24:07 UTC (rev 35057)
@@ -3810,9 +3810,10 @@
 	- policykit-1 <unfixed> (bug #787932)
 	[jessie] - policykit-1 <no-dsa> (Minor issue)
 	[wheezy] - policykit-1 <no-dsa> (Minor issue)
-	[squeeze] - policykit-1 <no-dsa> (Minor issue)
+	[squeeze] - policykit-1 <not-affected> (Vulnerable code introduced later)
 	NOTE: http://lists.freedesktop.org/archives/polkit-devel/2015-May/000420.html
 	NOTE: Patch: http://cgit.freedesktop.org/polkit/commit/?id=48e646918efb2bf0b3b505747655726d7869f31c
+	NOTE: Introduced by: http://cgit.freedesktop.org/polkit/commit/?id=6eeb077bc90c9c7783360a526b2f04645b1b0848
 CVE-2015-3217 [PCRE Library Call Stack Overflow Vulnerability in match()]
 	RESERVED
 	- pcre3 <unfixed> (bug #787641)




More information about the Secure-testing-commits mailing list