[Secure-testing-commits] r37660 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Nov 11 06:32:52 UTC 2015


Author: carnil
Date: 2015-11-11 06:32:52 +0000 (Wed, 11 Nov 2015)
New Revision: 37660

Modified:
   data/CVE/list
Log:
Update CVE-2015-7816/undertow

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-11-11 05:34:53 UTC (rev 37659)
+++ data/CVE/list	2015-11-11 06:32:52 UTC (rev 37660)
@@ -28581,9 +28581,7 @@
 	NOTE: https://sourceware.org/ml/libc-alpha/2014-11/msg00519.html
 	NOTE: Git commit: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=a39208bd7fb76c1b01c127b4c61f9bfd915bfe7c
 CVE-2014-7816 (Directory traversal vulnerability in JBoss Undertow 1.0.x before ...)
-	- undertow <itp> (bug #767001)
-	NOTE: When this enters the archive it should be marked straight as not-affected
-	NOTE: as the issue is only when undertow is running on Windows.
+	- undertow <not-affected> (only when running Windows)
 CVE-2014-7815 (The set_pixel_format function in ui/vnc.c in QEMU allows remote ...)
 	{DSA-3067-1 DSA-3066-1}
 	- qemu 2.1+dfsg-7




More information about the Secure-testing-commits mailing list