[Secure-testing-commits] r37999 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Nov 30 21:08:29 UTC 2015


Author: carnil
Date: 2015-11-30 21:08:29 +0000 (Mon, 30 Nov 2015)
New Revision: 37999

Modified:
   data/CVE/list
Log:
Add CVE-2015-8313/gnutls26

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-11-30 21:08:22 UTC (rev 37998)
+++ data/CVE/list	2015-11-30 21:08:29 UTC (rev 37999)
@@ -170,8 +170,11 @@
 	RESERVED
 CVE-2015-8314
 	RESERVED
-CVE-2015-8313
+CVE-2015-8313 [fail to check the first byte of the padding in CBC modes]
 	RESERVED
+	- gnutls28 <not-affected> (Vulnerable code not present)
+	- gnutls26 <removed>
+	NOTE: https://blog.hboeck.de/archives/877-A-little-POODLE-left-in-GnuTLS-old-versions.html
 CVE-2015-8312
 	RESERVED
 CVE-2015-8311




More information about the Secure-testing-commits mailing list