[Secure-testing-commits] r32855 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Fri Mar 13 20:51:36 UTC 2015
Author: carnil
Date: 2015-03-13 20:51:36 +0000 (Fri, 13 Mar 2015)
New Revision: 32855
Modified:
data/CVE/list
Log:
Convert gnutls gitorious urls to gitlab, since gnutls project moved already
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-03-13 19:57:10 UTC (rev 32854)
+++ data/CVE/list 2015-03-13 20:51:36 UTC (rev 32855)
@@ -7490,7 +7490,7 @@
- gnutls26 <removed>
[experimental] - gnutls28 3.3.13-1
- gnutls28 3.3.8-6 (bug #779428)
- NOTE: https://gitorious.org/gnutls/gnutls/commit/6e76e9b9fa845b76b0b9a45f05f4b54a052578ff (gnutls_3_3_13)
+ NOTE: https://gitlab.com/gnutls/gnutls/commit/6e76e9b9fa845b76b0b9a45f05f4b54a052578ff (gnutls_3_3_13)
CVE-2015-0293
RESERVED
CVE-2015-0292
@@ -9223,7 +9223,7 @@
CVE-2014-8564 (The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS ...)
- gnutls28 3.3.8-4 (bug #769154)
- gnutls26 <not-affected> (Vulnerable code not present; no support for ECC)
- NOTE: https://gitorious.org/gnutls/gnutls/commit/e821e1908686657a45c1b735f6d077b7a8493e2b (3.3.x branch)
+ NOTE: https://gitlab.com/gnutls/gnutls/commit/e821e1908686657a45c1b735f6d077b7a8493e2b (3.3.x branch)
NOTE: http://www.gnutls.org/security.html#GNUTLS-SA-2014-5
NOTE: in experimental fixed in 3.3.10-1
CVE-2014-8563
@@ -10407,7 +10407,7 @@
RESERVED
- gnutls26 2.9.10-1
- gnutls28 <not-affected> (Initial version 3.0.0-1 already contained the check based on 2.9.10)
- NOTE: Fixed by: https://gitorious.org/gnutls/gnutls/commit/897cbce62c0263a498088ac3e465aa5f05f8719c
+ NOTE: Fixed by: https://gitlab.com/gnutls/gnutls/commit/897cbce62c0263a498088ac3e465aa5f05f8719c
CVE-2014-8154 (The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect ...)
- vala-0.26 0.26.1-1.1 (bug #775913)
- vala-0.16 <not-affected> (MapInfo not yet present)
@@ -26208,8 +26208,8 @@
- gnutls26 2.12.23-12
[squeeze] - gnutls26 <not-affected> (does not allow X.509 v1 certificates by default)
- gnutls28 3.2.11-1
- NOTE: https://www.gitorious.org/gnutls/gnutls/commit/b1abfe3d18
- NOTE: introduced by https://www.gitorious.org/gnutls/gnutls/commit/60ee8a0eb9975d123002b1cffbefd60a8cd5fae6
+ NOTE: https://gitlab.com/gnutls/gnutls/commit/b1abfe3d18
+ NOTE: introduced by https://gitlab.com/gnutls/gnutls/commit/60ee8a0eb9975d123002b1cffbefd60a8cd5fae6
CVE-2014-1958 [PSD Images Processing RLE Decoding Buffer Overflow Vulnerability]
RESERVED
{DSA-2898-1}
@@ -29572,7 +29572,7 @@
CVE-2009-5138 (GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag ...)
- gnutls26 2.7.12-1
- gnutls28 <not-affected> (Only affects versions before 2.7.6)
- NOTE: Only affects version prior of 2.7.6, fix: https://gitorious.org/gnutls/gnutls/commit/c8dcbedd1fdc312f5b1a70fcfbc1afe235d800cd
+ NOTE: Only affects version prior of 2.7.6, fix: https://gitlab.com/gnutls/gnutls/commit/c8dcbedd1fdc312f5b1a70fcfbc1afe235d800cd
NOTE: and the issue has different root than CVE-2014-1959
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1069301
CVE-2009-5137 (Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows ...)
@@ -38657,7 +38657,7 @@
- gnutls26 <not-affected> (only 3.1.x and 3.2.x)
- gnutls28 <not-affected> (libdane is not built)
NOTE: http://www.gnutls.org/security.html#GNUTLS-SA-2013-3
- NOTE: Upstream commit for 3.2.x: https://gitorious.org/gnutls/gnutls/commit/ed51e5e53cfbab3103d6b7b85b7ba4515e4f30c3
+ NOTE: Upstream commit for 3.2.x: https://gitlab.com/gnutls/gnutls/commit/ed51e5e53cfbab3103d6b7b85b7ba4515e4f30c3
CVE-2013-4465 (Unrestricted file upload vulnerability in the avatar upload ...)
NOT-FOR-US: Simple Machines Forum
CVE-2013-4464
More information about the Secure-testing-commits
mailing list